Senior Threat Analyst 1
4 weeks ago
OverviewSophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure-play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. In addition to MDR and other services, Sophos’ portfolio includes industry-leading endpoint, network, email, and cloud security that interoperate and adapt to defend through the Sophos Central platform. Secureworks provides the Taegis XDR/MDR, ITDR, next-gen SIEM capabilities, managed risk, and advisory services. Sophos sells these solutions through reseller partners, MSPs and MSSPs worldwide, defending more than 600,000 organizations from phishing, ransomware, data theft, and other cybercrimes. The solutions are powered by historical and real-time threat intelligence from Sophos X-Ops and CTU. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.Role SummaryAs a Threat Analyst on our Managed Detection and Response (MDR) team, you will provide best-in-class monitoring, detection, and response services to proactively defend customer environments before attacks prevail. You will work alongside and contribute to a team of cyber threat hunters, incident response analysts, engineers, and ethical hackers by using enterprise, log analysis and endpoint collection systems to facilitate investigations, identification, and neutralization of cyber threats.ShiftMonday to Friday, from 2 pm to 10:30 pm EasternWhat You Will DoMonitor, investigate, and respond to alerts generated by the Sophos security stack (including EDR/XDR capabilities)Lead and mentor Tier I Analysts through escalated cases, ensuring thorough and accurate investigation practicesPerform end-to-end analysis on suspicious activity to assess scope, impact, and riskIdentify and respond to cyber threats across customer environments using approved playbooks and toolingAccurately document findings, investigative steps, and outcomes in the MDR case management platformConduct threat hunting to identify potential threats throughout the MDR customer baseInvestigate phishing emails, suspicious binaries, and behavioral anomaliesSupport detection tuning by identifying recurring false positives and suggesting improvementsStay informed on threat actor behaviors, MITRE ATT&CK techniques, and Sophos threat research updatesProactively research emerging IOCs, active exploits, and vulnerabilities to stay ahead of evolving threatsContribute to internal knowledge bases, documentation, and continuous improvement initiativesParticipate in shift rotations and ensure timely, detailed handovers between global teamsProvide detection and response support for active security incidentsManage case workflows: create cases, track progress, and follow up with clients until resolutionEngage with clients via chat, phone, and tickets as part of case handlingAssist with developing and refining Security Operations processes, playbooks, and tooling feedbackWhat You Will Bring5+ years of experience working in a SOC environment or computer security team in an IT environmentEndpoint and network security experience required; IDS, IPS, EDR, ATP, Malware defenses and monitoring experienceThreat hunting experience preferredKnowledge of common adversary tactics and techniques, e.g., obfuscation, persistence, defense evasionKnowledge of Mitre ATT&CK framework preferredWorking knowledge of incident response proceduresExperience with SQL query construction preferredExperience with OSQuery is a plusExperience administering and supporting Windows OS (workstations and servers) and one of Apple or Linux-based operating systemsFundamental understanding of network traffic analysis including TCP/IP, routing, switching, protocolsStrong understanding of Windows event log analysisExperience with enterprise information security data management - SIEM experience a plusProgramming and scripting skills - proficient knowledge of PowerShell is a plusExcellent troubleshooting and analytical thinking skillsStrong documentation and communication skillsAdvanced Cyber Security certifications preferred but not requiredExcellent customer service skillsPassion for information technology and information securityNatural curiosity and ability to learn quicklyAbility to think outside the box; innovative mindsetWillingness to participate in shift work including nights and holidaysCompensation and Benefits (Canada)In Canada, the base salary for this role ranges from $86,000 to $143,000. In addition to base salary, we offer bonus eligibility and a comprehensive benefits package. A candidate’s specific pay within this range depends on factors such as job-related skills, location, experience, education, certifications, and business needs.What’s Great About Sophos· Sophos operates a remote-first working model; some roles may require hybrid work. Applicants must have legal authorization to work in the posted jurisdiction without employer sponsorship.· Our people – we innovate and have fun; diverse perspectives are valued· Employee-led diversity and inclusion networks, charitable initiatives, and volunteer days· Global sustainability efforts, wellness days, and ongoing wellbeing programs· Global fitness and trivia competitions· Global wellbeing webinars and trainingOur Commitment To YouWe’re committed to equality of opportunity and a diverse, inclusive environment. All applicants will be treated fairly and in accordance with the law regardless of gender, sex, gender identity, race, religion or belief, color, age, veteran status, disability, pregnancy, maternity or sexual orientation. If any recruitment adjustments are needed, please let us know.Data ProtectionIf you share your CV or personal details, Sophos will hold them for 12 months in accordance with our Privacy Policy and may contact you regarding this or other opportunities. To delete or update your details, follow the steps in the Privacy Policy. #J-18808-Ljbffr
-
Cyber Threat Analyst
4 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Chainlink Labs Full timeJoin to apply for the Cyber Threat Analyst role at Chainlink LabsAbout Us Chainlink Labs is one of the primary contributing developers of Chainlink, the industry-standard oracle platform bringing the capital markets onchain and powering the majority of decentralized finance. The Chainlink stack provides the essential data, interoperability, compliance, and...
-
MDR Threat Analyst — Remote, 12PM–9PM EST
4 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Sophos Group Full timeAn established industry player in cybersecurity is seeking a dedicated Threat Analyst to join their Managed Detection and Response team. In this role, you will leverage your expertise to monitor, detect, and respond to cyber threats, ensuring the safety of customer environments. Collaborate with a team of skilled professionals, including cyber threat hunters...
-
Senior Security/Threat Analyst
7 days ago
Toronto, London, Winnipeg, Canada Hire Values Full time $120,000 - $180,000 per yearJob DescriptionWe are seeking a senior security/threat analyst with expertise in threat modeling who has the ability to create security pattern templates. 6-month contract.Main Activities:• Develop security patterns templates.• Develop Security Patterns for application and infrastructure.• Review the developed security pattern with stakeholders and get...
-
MDR Threat Hunter
3 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Sophos Full timeA cybersecurity leader is seeking a Threat Analyst to join their Managed Detection and Response team in Canada. The successful candidate will monitor and respond to cyber threats, conduct investigations, and lead a team of analysts. Ideal applicants will have over 5 years of experience in SOC environments and strong skills in endpoint and network security. A...
-
Threat Intelligence Lead
7 days ago
Edmonton, Toronto, Montreal, Calgary, Vancouver, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Surrey, Victoria, London, Halton Hills, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Canonical Full timeJoin to apply for the Threat Intelligence Lead role at Canonical3 months ago Be among the first 25 applicantsJoin to apply for the Threat Intelligence Lead role at CanonicalThe Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of...
-
Threat Intelligence Lead
7 days ago
Hamilton, Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Surrey, Victoria, London, Halton Hills, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Canonical Full timeJoin to apply for the Threat Intelligence Lead role at CanonicalContinue with Google Continue with Google3 months ago Be among the first 25 applicantsJoin to apply for the Threat Intelligence Lead role at CanonicalThe Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, including understanding of which cyber threat actors...
-
SENIOR CYBERSECURITY ANALYST
2 weeks ago
Regina, Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Surrey, Victoria, London, Halton Hills, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Sumeru Solutions Full timeKey Responsibilities Lead threat monitoring and detection across SIEM and endpoint-protection platforms. Conduct deep-dive investigations into complex security incidents. Manage containment and remediation processes; provide root-cause analysis. Develop and refine SOC playbooks detection rules and escalation procedures. Mentor junior analysts and ensure...
-
Threat Intelligence Lead
7 days ago
Vancouver, Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Surrey, Victoria, London, Halton Hills, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern, Canada Canonical Full timeJoin to apply for the Threat Intelligence Lead role at CanonicalContinue with Google Continue with Google3 months ago Be among the first 25 applicantsJoin to apply for the Threat Intelligence Lead role at CanonicalThe Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, including understanding of which cyber threat actors...
-
Threat Modeling Analyst
7 days ago
Montreal, Ottawa, Toronto, Canada nugget.ai Full timeLocation: Toronto (hybrid->3 times per week)Employment Type: ContractAbout the Role: The Threat Modeling Analyst is responsible for identifying threats and vulnerabilities across company systems and communicating the issues with the appropriate team – infrastructure, IT, risk, DLP, or any affected members.Responsibilities:Work cross-functionally with other...
-
Remote Senior IT Security Risk
2 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Surrey, Victoria, London, Halton Hills, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Maplesoft Group, an SEB Company Full timeA prominent technology consulting firm is seeking a Remote Senior IT Security Threat and Risk Assessment Analyst to support their Federal Government client. The ideal candidate should have over 10 years of experience in IT security, with a strong focus on cloud security assessments and ITSG-33 compliance. This role entails conducting risk assessments,...