Senior Incident Response Engineer

Sophos
India
Workplace: RemoteFull timeFunction: Solutions Engineering & Sales EngineeringExperience: 5+ yearsSkills: ["Communication","Time management","Prioritization","Delegation","Stress tolerance","Mentoring","Teamwork","Continuous learning","Knowledge sharing"]

Lead customer-facing incident response engagements, running investigations to neutralize cyber threats and providing timely forensic updates. Coordinate kickoff calls, delegate tasks across incident teams, and support multiple rapid response incidents concurrently. Conduct thorough root cause analysis (including potential data exfiltration), map findings to MITRE ATT&CK, and deliver executive summary-style reports with remediation guidance. Mentor junior analysts and continuously improve threat response effectiveness.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sophos
Sophos
2 days ago

Senior Incident Response Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Lead customer-facing incident response engagements, running investigations to neutralize cyber threats and providing timely forensic updates. Coordinate kickoff calls, delegate tasks across incident teams, and support multiple rapid response incidents concurrently. Conduct thorough root cause analysis (including potential data exfiltration), map findings to MITRE ATT&CK, and deliver executive summary-style reports with remediation guidance. Mentor junior analysts and continuously improve threat response effectiveness.
Location: India
Workplace: Remote
Employment Type: Full time · Permanent
Job Function: Solutions Engineering & Sales Engineering
Seniority: Sr. Manager level

Key Responsibilities

  • •Lead customer kickoff calls to understand situations and identify initial response actions.
  • •Direct forensic investigations by setting priorities and delegating tasks to analysts.
  • •Conduct root cause analysis to determine incident origin and identify whether data exfiltration occurred.
  • •Provide daily update calls and deliver concise email updates and executive summary-style reports mapped to MITRE ATT&CK.
  • •Support multiple rapid response incidents concurrently, including creating daily handover notes across time zones and shifting incident responsibility.

Key Requirements

  • •5+ years of experience leading incident response investigations, including ransomware and BEC investigations.
  • •Strong understanding of the incident response process and cyber risks, including qualifying risks to customers.
  • •Proven track record of successfully neutralizing and remediating ransomware threats.
  • •Strong communication skills (oral and written) and the ability to manage time effectively across multiple incidents.
  • •Comfort working under stress, prioritizing/delegating tasks, and being available to work weekends and holidays when needed.
Experience:5+ yearsRansomwareIncident responseForensicsThreat intelligenceRapid responseSIEM
Education:
Skills:CommunicationTime managementPrioritizationDelegationStress toleranceMentoringTeamworkContinuous learningKnowledge sharing
Certifications:CISSPGCFA
Tech Stack:MITRE ATT&CKSIEMSplunkELKSQLPowerShellPythonBash

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Sophos
Provides enterprise cybersecurity software and services including endpoint protection, network security, cloud security, encryption, and managed threat response to protect organizations from advanced threats and ransomware.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 500M to 1B
Growth: Established Company
Valuation: Unicorn (USD 1B+)
Funding: Private Equity Backed
Headquarters: Abingdon, United Kingdom
Founded: 1985
WebsiteLinkedIn