Role Summary
Sophos is seeking a highly skilled Senior Incident Response Analyst to support Managed Detection and Response (MDR) customers within the Critical Incident Response Team (CIRT).
As a Senior Incident Response Analyst 2, you will lead complex and high-impact incident response engagements, operating across Responder, Advisor, and Commander roles as required. You are trusted to provide advanced technical leadership, shape investigative strategy, guide containment decisions, and ensure high-quality customer outcomes during critical security incidents.
What You Will Do
- Lead complex investigations involving advanced adversaries, multi-vector intrusions, or cross-environment compromise
- Serve as the primary Incident Advisor or delegated Commander for high-severity engagements
- Direct and coordinate investigative, forensic, and containment activities across multiple analysts
- Define engagement strategy, investigative priorities, and containment approaches based on risk and impact
- Validate and synthesize technical findings into clear, actionable guidance for customers and internal stakeholders
- Provide technical mentorship and oversight to IR and SOC analysts
- Collaborate closely with SOC, Threat Intelligence, and Detection Engineering teams to validate detections and close visibility gaps
- Lead or contribute to post-incident reviews, driving improvements to playbooks, tools, and response workflows
- Maintain accurate time and activity tracking to support operational visibility and capacity planning
What You Will Bring
Essential:
- 5+ years of experience in incident response, MDR, or cyber security investigations, including leadership of complex incidents
- Advanced expertise in endpoint and network forensics, log analysis, and adversary tradecraft
- Strong understanding of enterprise network architecture and IT infrastructure
- Proven ability to lead investigations, validate findings, and design effective containment strategies
- Experience communicating technical findings to customers, including senior and executive stakeholders
- Demonstrated mentorship and leadership across incident response teams
- Ability to operate effectively under high-pressure, time-sensitive conditions
- Willingness to work some weekends and holidays as part of a rotation
Desired:
- Advanced incident response or forensic certifications (GCFA, GCED, GCIH, OSCP, or equivalent)
- Experience acting as Incident Advisor or Commander during critical engagements
- Publications, presentations, or recognized contributions within the cybersecurity field
- Experience influen