Senior Incident Response Consultant, Rapid Response

Sophos
Romania
Workplace: RemoteFull timeFunction: CybersecurityExperience: 5+ yearsSkills: ["Communication","Delegation","Prioritization","Time management","Mentoring","Ability to work under pressure"]

Lead customer incident response engagements for ransomware and BEC events, running customer calls, directing forensic investigations, and coordinating multiple incidents at once. Determine investigation priorities, delegate tasks across analysts, and provide timely email updates and executive summaries. Produce root-cause analysis and reports mapped to the MITRE ATT&CK framework, while contributing to the growth and development of junior analysts within the Rapid Response service.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sophos
Sophos
4 days ago

Senior Incident Response Consultant, Rapid Response

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Lead customer incident response engagements for ransomware and BEC events, running customer calls, directing forensic investigations, and coordinating multiple incidents at once. Determine investigation priorities, delegate tasks across analysts, and provide timely email updates and executive summaries. Produce root-cause analysis and reports mapped to the MITRE ATT&CK framework, while contributing to the growth and development of junior analysts within the Rapid Response service.
Location: Romania
Workplace: Remote
Employment Type: Full time · Permanent
Job Function: Cybersecurity
Seniority: Manager level

Key Responsibilities

  • •Spearhead incident response engagements for customers after cybersecurity attacks, including leading customer-facing calls.
  • •Direct forensic investigations: identify priorities, delegate tasks to analysts, and run multiple Rapid Response incidents concurrently.
  • •Determine tactics, techniques, and procedures (TTPs) identified by analysts and add them to the threat intel platform.
  • •Provide timely written updates (including executive summary-style reports) and deliver daily update calls with forensic findings.
  • •Ensure appropriate actions are taken by both the team and customer, and perform thorough root cause analysis (including assessing data exfiltration when evidence is available).

Key Requirements

  • •5+ years leading incident response investigations involving ransomware.
  • •Experience leading BEC investigations.
  • •Strong understanding of the incident response process and cyber risks, with ability to qualify risks to customers.
  • •Strong grasp of the MITRE ATT&CK framework and ability to produce executive summary-style reports.
  • •Post-secondary education in cybersecurity (or comparable), plus desirable experience such as SIEM tools (e.g., Splunk/ELK), SQL, and scripting (PowerShell/Python/Bash).
Experience:5+ yearsRansomwareBECIncident responseManaged detection and response (MDR)SIEM
Education:
Skills:CommunicationDelegationPrioritizationTime managementMentoringAbility to work under pressure
Certifications:CISSPGCFA
Tech Stack:MITRE ATT&CKSIEMSplunkELKSQLPowerShellPythonBashThreat intel platform

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Sophos
Provides enterprise cybersecurity software and services including endpoint protection, network security, cloud security, encryption, and managed threat response to protect organizations from advanced threats and ransomware.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 500M to 1B
Growth: Established Company
Valuation: Unicorn (USD 1B+)
Funding: Private Equity Backed
Headquarters: Abingdon, United Kingdom
Founded: 1985
WebsiteLinkedIn