Incident Response Engineer 2

Sophos
United Kingdom
Workplace: RemoteFull timeFunction: Solutions Engineering & Sales EngineeringSkills: ["Written communication","Verbal communication","Incident documentation","Mentoring","Working under pressure"]

Serve as an Incident Responder for Sophos MDR customers in the Critical Incident Response Team (CIRT), performing advanced investigative and forensic analysis during active cyber incidents. Correlate alerts and telemetry to determine scope and root cause, validate indicators of compromise, and execute containment actions as directed by Incident Advisors. Maintain high-quality engagement documentation and support customer updates, while mentoring junior analysts and contributing to incident reviews.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sophos
Sophos
23 hours ago

Incident Response Engineer 2

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Serve as an Incident Responder for Sophos MDR customers in the Critical Incident Response Team (CIRT), performing advanced investigative and forensic analysis during active cyber incidents. Correlate alerts and telemetry to determine scope and root cause, validate indicators of compromise, and execute containment actions as directed by Incident Advisors. Maintain high-quality engagement documentation and support customer updates, while mentoring junior analysts and contributing to incident reviews.
Location: United Kingdom
Workplace: Remote
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Perform advanced investigative and forensic analysis across endpoints, network logs, and cloud telemetry
  • •Execute containment and response actions to neutralize active threats as directed by Incident Advisors or Senior Analysts
  • •Validate indicators of compromise (IOCs) and correlate alerts, artifacts, and telemetry to determine scope and root cause
  • •Maintain clear engagement documentation, including trailheads, timelines, and playbooks, for customer updates and post-incident reports
  • •Mentor junior IR and SOC analysts and participate in shift handovers, debriefs, and post-incident reviews

Pay and Benefits

Perks:Remote Work

Key Requirements

  • •2+ years of experience in incident response, MDR, SOC, or security operations roles
  • •Strong technical understanding of endpoint forensics, log analysis, and common attack techniques
  • •Experience investigating malware, credential theft, ransomware, or similar threats
  • •Ability to correlate alerts and telemetry to determine incident scope and root cause
  • •Strong written and verbal communication for documenting findings and contributing to customer updates
Experience:MDRSOCIncident responseSOC operationsSecurity operations
Skills:Written communicationVerbal communicationIncident documentationMentoringWorking under pressure
Certifications:GCIHGCEDCompTIA Security+
Tech Stack:EDRSIEMOSQuerySQLKQLMITRE ATT&CKEndpoint forensicsLog analysis

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Sophos
Provides enterprise cybersecurity software and services including endpoint protection, network security, cloud security, encryption, and managed threat response to protect organizations from advanced threats and ransomware.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 500M to 1B
Growth: Established Company
Valuation: Unicorn (USD 1B+)
Funding: Private Equity Backed
Headquarters: Abingdon, United Kingdom
Founded: 1985
WebsiteLinkedIn