Senior Incident Response Consultant

Posted 2 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior Incident Response Consultant leading DFIR engagements, forensic investigations, and threat neutralization. Protecting global organizations through Sophos’s AI-driven cybersecurity platform and expert services.

Responsibilities

  • Lead kickoff calls with customers to understand their situation and identify initial response actions to contain threats
  • Advise customers on post-incident best practices
  • Lead daily customer update calls and deliver forensic findings
  • Deliver concise email updates between calls
  • Direct forensic investigations, identify priorities, and delegate tasks to analysts
  • Conduct multiple incidents concurrently
  • Determine analyst-identified TTPs and add them to the threat intelligence platform
  • Write timely Executive Summary-style reports
  • Contribute to basic to moderate complexity projects developing the Sophos DFIR service
  • Provide daily handover notes to teams in different time zones or when transferring incident responsibility
  • Lead incident response engagements and teams for customers experiencing cybersecurity attacks
  • Coordinate with legal counsel and cyber insurance carriers as needed
  • Ensure appropriate actions neutralize threats
  • Conduct root cause analysis, including determining whether data exfiltration occurred
  • Produce reports with key-event timelines mapped to the MITRE ATT&CK framework and remediation guidance

Requirements

  • 10+ years of experience leading incident response investigations involving ransomware, network breaches, malicious insiders, and web applications and database services
  • Experience leading BEC investigations
  • In-depth digital forensic analysis of AWS, Microsoft Azure, and GCP data
  • Continuously learning and staying informed of the changing threat landscape
  • Proven track record of neutralization and remediation of ransomware threats
  • Excellent understanding of the Incident Response process and cyber risks
  • Excellent oral and strong written communication skills
  • Ability to manage time effectively
  • Ability to delegate and prioritize tasks across multiple incidents
  • Ability to excel under stressful circumstances
  • Willingness to begin work early and/or stay late when warranted
  • Strong grasp of the MITRE ATT&CK framework
  • Mentoring and knowledge-sharing ability
  • Ability to work some weekends and holidays
  • Cybersecurity certifications such as CISSP, GCFA, or similar are an asset
  • Experience with SIEM technology such as Splunk or ELK is desirable
  • Willingness to work occasional overtime during peak times or holidays is desirable
  • Experience writing SQL queries is desirable
  • Experience writing PowerShell, Python, or Bash scripts is desirable

Benefits

  • Bonus eligibility
  • Comprehensive benefits package
  • Remote-first working model
  • Employee-led diversity and inclusion networks
  • Annual charity and fundraising initiatives
  • Volunteer days
  • Global employee sustainability initiatives
  • Global fitness and trivia competitions
  • Global wellbeing days
  • Monthly wellbeing webinars and training

Job title

Job type

Full Time

Experience level

Senior

Salary

CA$131,000 - CA$219,000 per year

Degree requirement

No Education Requirement

Tech skills

AWSAzureCyber SecurityGoogle Cloud PlatformPythonSplunkSQL

Location requirements

RemoteCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.