Manager, Incident Response

Sophos
India
Workplace: RemoteFull timeFunction: Solutions Engineering & Sales EngineeringExperience: 7+ yearsSkills: ["People leadership","Coaching","Performance management","Analytical thinking","Communication"]

Lead Sophos’ Critical Incident Response Team (CIRT) for MDR customers, combining people leadership with senior incident response. Own day-to-day incident response operations across multiple squads, ensure operational readiness and incident command, and provide clear technical and customer communications through high-severity engagements. Establish quality standards, use operational metrics for continuous improvement, and partner across Threat Intelligence, SOC, Detection Engineering, Product, and more to close response and detection gaps.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sophos
Sophos
2 days ago

Manager, Incident Response

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Lead Sophos’ Critical Incident Response Team (CIRT) for MDR customers, combining people leadership with senior incident response. Own day-to-day incident response operations across multiple squads, ensure operational readiness and incident command, and provide clear technical and customer communications through high-severity engagements. Establish quality standards, use operational metrics for continuous improvement, and partner across Threat Intelligence, SOC, Detection Engineering, Product, and more to close response and detection gaps.
Location: India
Workplace: Remote
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Manager level

Key Responsibilities

  • •Lead and develop squads of analysts across CIRT, setting clear expectations, providing coaching and feedback, supporting career development, and building an inclusive team culture.
  • •Own day-to-day CIRT operations across multiple squads, ensuring staffing, coverage, workload balancing, prioritization, and service-level performance for concurrent customer engagements.
  • •Provide senior technical leadership and act as Incident Commander for complex or high-severity engagements, coordinating investigation, containment, eradication, recovery, and customer communications through resolution.
  • •Establish and maintain operational and investigative quality standards so teams follow approved processes and playbooks and documentation is complete and accurate.
  • •Drive continuous improvement using engagement, quality, response-time, capacity, and customer-outcome metrics; maintain operational readiness (training, exercises, tooling needs, and playbook updates).

Pay and Benefits

Perks:Remote Work

Key Requirements

  • •7+ years of cybersecurity operations, incident response, or digital forensics experience, including at least 2 years leading people or operational functions.
  • •Experience managing incident response operations across multiple concurrent engagements, including staffing, prioritization, and service-level expectations.
  • •Strong technical background across endpoint, network, and cloud security, with ability to investigate IOCs and direct containment, eradication, and remediation.
  • •Experience serving as Incident Commander or a senior escalation point during high-pressure incidents with risk-based decision-making and clear stakeholder communication.
  • •Proven people leadership (coaching, performance management, career development, hiring/onboarding) and experience using operational metrics and quality reviews to drive improvements.
Experience:7+ yearsCybersecurityIncident responseManaged detection and response (MDR)Security operationsDigital forensics
Education:
Skills:People leadershipCoachingPerformance managementAnalytical thinkingCommunication
Certifications:GCFEGCFAGCIHCISSP
Tech Stack:MITRE ATT&CKSIEMEDROSQuerySQLPowerShellKQLCyLRVelociraptor

Company Brief

Sophos
Provides enterprise cybersecurity software and services including endpoint protection, network security, cloud security, encryption, and managed threat response to protect organizations from advanced threats and ransomware.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 500M to 1B
Growth: Established Company
Valuation: Unicorn (USD 1B+)
Funding: Private Equity Backed
Headquarters: Abingdon, United Kingdom
Founded: 1985
WebsiteLinkedIn