See all jobs on JobTailor
Search thousands of fresh jobs every day.
- Fresh listings
- Fast filters
- No subscription required

Senior Incident Response Consultant
SophosSenior Incident Response Consultant leading DFIR engagements, forensic investigations, and threat neutralization. Protecting global organizations through Sophos’s AI-driven cybersecurity platform and expert services.
Core Competencies
Role fitUse this summary to align your resume positioning with the role.
Demonstrates extensive experience in leading incident response investigations, particularly in ransomware and network breaches, while effectively managing multiple incidents and coordinating with various stakeholders. Proficient in digital forensic analysis across cloud platforms and adept at producing detailed reports aligned with the MITRE ATT&CK framework.
ATS Keywords
Tailor your resumeTip: use these terms in your resume and cover letter to boost ATS matches.
Tech Stack
Tools & technologiesAbout the role
Key responsibilities & impact- Lead kickoff calls with customers to understand their situation and identify initial response actions to contain threats
- Advise customers on post-incident best practices
- Lead daily customer update calls and deliver forensic findings
- Deliver concise email updates between calls
- Direct forensic investigations, identify priorities, and delegate tasks to analysts
- Conduct multiple incidents concurrently
- Determine analyst-identified TTPs and add them to the threat intelligence platform
- Write timely Executive Summary-style reports
- Contribute to basic to moderate complexity projects developing the Sophos DFIR service
- Provide daily handover notes to teams in different time zones or when transferring incident responsibility
- Lead incident response engagements and teams for customers experiencing cybersecurity attacks
- Coordinate with legal counsel and cyber insurance carriers as needed
- Ensure appropriate actions neutralize threats
- Conduct root cause analysis, including determining whether data exfiltration occurred
- Produce reports with key-event timelines mapped to the MITRE ATT&CK framework and remediation guidance
Requirements
What you’ll need- 10+ years of experience leading incident response investigations involving ransomware, network breaches, malicious insiders, and web applications and database services
- Experience leading BEC investigations
- In-depth digital forensic analysis of AWS, Microsoft Azure, and GCP data
- Continuously learning and staying informed of the changing threat landscape
- Proven track record of neutralization and remediation of ransomware threats
- Excellent understanding of the Incident Response process and cyber risks
- Excellent oral and strong written communication skills
- Ability to manage time effectively
- Ability to delegate and prioritize tasks across multiple incidents
- Ability to excel under stressful circumstances
- Willingness to begin work early and/or stay late when warranted
- Strong grasp of the MITRE ATT&CK framework
- Mentoring and knowledge-sharing ability
- Ability to work some weekends and holidays
- Cybersecurity certifications such as CISSP, GCFA, or similar are an asset
- Experience with SIEM technology such as Splunk or ELK is desirable
- Willingness to work occasional overtime during peak times or holidays is desirable
- Experience writing SQL queries is desirable
- Experience writing PowerShell, Python, or Bash scripts is desirable
Benefits
Comp & perks- Bonus eligibility
- Comprehensive benefits package
- Remote-first working model
- Employee-led diversity and inclusion networks
- Annual charity and fundraising initiatives
- Volunteer days
- Global employee sustainability initiatives
- Global fitness and trivia competitions
- Global wellbeing days
- Monthly wellbeing webinars and training