Threat Analyst 2 (Romania - shift schedule)

Sophos
Romania
Workplace: RemoteFull timeFunction: Administration & Executive AssistanceExperience: 2+ yearsEducation: bachelorsSkills: ["Analytical thinking","Troubleshooting","Communication","Customer-first","Teamwork"]

Provide best-in-class monitoring, detection, and response for customer environments as a Tier II Threat Analyst on the MDR team. Investigate and respond to alerts from the Sophos security stack (EDR/XDR), perform threat hunting, analyze telemetry and event logs, and manage MDR case workflows from triage through resolution. Mentor Tier I analysts on escalated cases, tune detections by reducing false positives, and support active incidents using approved playbooks and tooling.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sophos
Sophos
2 months ago

Threat Analyst 2 (Romania - shift schedule)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live

Job Summary

Provide best-in-class monitoring, detection, and response for customer environments as a Tier II Threat Analyst on the MDR team. Investigate and respond to alerts from the Sophos security stack (EDR/XDR), perform threat hunting, analyze telemetry and event logs, and manage MDR case workflows from triage through resolution. Mentor Tier I analysts on escalated cases, tune detections by reducing false positives, and support active incidents using approved playbooks and tooling.
Location: Romania
Workplace: Remote
Employment Type: Full time · Permanent
Job Function: Administration & Executive Assistance
Seniority: Mid level

Key Responsibilities

  • •Monitor, investigate, and respond to alerts from the Sophos security stack (including EDR/XDR capabilities).
  • •Perform end-to-end analysis of suspicious activity to assess scope, impact, and risk and identify threats across customer environments using approved playbooks.
  • •Conduct threat hunting across the MDR customer base and investigate phishing emails, suspicious binaries, and behavioral anomalies.
  • •Document findings and investigative steps in the MDR case management platform and manage case workflows through client resolution.
  • •Participate in shift rotations with timely, detailed handovers and provide detection/response support for active security incidents while mentoring Tier I analysts on escalations.

Key Requirements

  • •2+ years of hands-on experience in a SOC, MDR environment, or cybersecurity-focused IT role.
  • •Proficient with endpoint and network security tools (e.g., EDR, IDS/IPS) to validate and triage complex alerts.
  • •Working knowledge of Windows, with additional experience in Linux (Ubuntu, Debian, RedHat) or macOS.
  • •Ability to interpret Windows event logs and analyze telemetry data.
  • •Bachelor’s degree in IT/CS/Cybersecurity or equivalent practical experience; able to communicate in English.
Experience:2+ yearsCybersecuritySOCMDR
Education:Bachelor's in Information Technology, Computer Science, Cybersecurity or related field
Skills:Analytical thinkingTroubleshootingCommunicationCustomer-firstTeamwork
Certifications:GSECGCIAGCIHPEN-200Security Blue Team L1TCM Academy SOC L1
Languages:English
Tech Stack:EDRXDRIDS/IPSMalware detection platformsWindowsLinuxUbuntuDebianRedHatMacOSTCP/IPSIEMSQLOSQueryPowerShellMITRE ATT&CKMDR case management platformTelemetryEvent logsPhishing

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Sophos
Provides enterprise cybersecurity software and services including endpoint protection, network security, cloud security, encryption, and managed threat response to protect organizations from advanced threats and ransomware.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 500M to 1B
Growth: Established Company
Valuation: Unicorn (USD 1B+)
Funding: Private Equity Backed
Headquarters: Abingdon, United Kingdom
Founded: 1985
WebsiteLinkedIn