Overview
About Us
Full job description
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.
Maintain supervision over operational tasks and provide day-to-day oversight for threat analysts Oversee analysts in their investigation and response Activities when security incidents arise to determine possible root cause and resolution Effectively communicate information to stakeholders of all levels Demonstrate experience in network and host-based intrusion analysis, incident response processes and procedures, digital forensics and/or handling malware Acting as a lead throughout incident scenarios and provide subject matter expertise in cybersecurity incident response· Successfully executing incident handling procedures as well as direct response to cyber security incidents Maintaining current knowledge and recognition of attacker tools, tactics, and procedures to produce indicators of compromise (IOCs) that can be utilized during active and future investigations Assessing cyber threat intelligence/open source intelligence and operationalizing that information Demonstrating real-world, hands-on experience dealing with sophisticated malware and dynamic cyber threat actors Identifying current and emerging threats and application of such research
5+ years of experience within a cybersecurity environment; experience in a leadership role is preferred Bachelor's in information technology, Computer Science, or a related field; or relevant, commensurate work experience Experience in a security operations center, or similar environment, and identifying indications of compromise or attack and responding to incidents Endpoint and network security experience required; IDS, IPS, EDR, ATP, Malware defenses and monitoring experience Threat hunting experience preferred Knowledge of common adversary tactics and techniques, e.g., obfuscation, persistence, defense evasion, etc. Knowledge of Mitre ATT&CK framework preferred Working knowledge of incident response procedures Experience with SQL query construction preferred Experience with OSQuery is a plus Experience administering and supporting Windows OS (both workstations and server) and one of the following: Apple or Linux-based operating systems (e.g. XP, Windows 7, 2003, 2008, OS X) Fundamental understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
JobOpportunity.info helps you discover and organize source listings. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Sophos (lever) →