Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Sophos

Senior Incident Response Consultant

Sophos

Senior Incident Response Consultant leading DFIR engagements, forensic investigations, and threat neutralization. Protecting global organizations through Sophos’s AI-driven cybersecurity platform and expert services.

Posted 9/9/2026full-timeRemote • 🇨🇦 CanadaSenior💰 CA$131,000 - CA$219,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in leading incident response investigations, particularly in ransomware and network breaches, while effectively managing multiple incidents and coordinating with various stakeholders. Proficient in digital forensic analysis across cloud platforms and adept at producing detailed reports aligned with the MITRE ATT&CK framework.

Highest-signal resume keywords
Incident Response LeadershipDigital Forensic AnalysisMITRE ATT&CK FrameworkCybersecurity CertificationsSIEM Technology Experience

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Digital Forensic AnalysisIncident Response ProcessSQL Query WritingPowerShell ScriptingPython ScriptingBash ScriptingRansomware NeutralizationRoot Cause AnalysisThreat Intelligence Platform ManagementBEC Investigation
Soft Skills
Strong Written CommunicationOral Communication SkillsTime ManagementDelegation and PrioritizationAbility to Excel Under Stress
Tools & Technologies
AWSMicrosoft AzureGCPSplunkELK
Certifications & Qualifications
CISSPGCFA
Industry Keywords
CybersecurityIncident ResponseThreat LandscapeData ExfiltrationForensic Investigations

Tech Stack

Tools & technologies
AWSAzureCyber SecurityGoogle Cloud PlatformPythonSplunkSQL

About the role

Key responsibilities & impact
  • Lead kickoff calls with customers to understand their situation and identify initial response actions to contain threats
  • Advise customers on post-incident best practices
  • Lead daily customer update calls and deliver forensic findings
  • Deliver concise email updates between calls
  • Direct forensic investigations, identify priorities, and delegate tasks to analysts
  • Conduct multiple incidents concurrently
  • Determine analyst-identified TTPs and add them to the threat intelligence platform
  • Write timely Executive Summary-style reports
  • Contribute to basic to moderate complexity projects developing the Sophos DFIR service
  • Provide daily handover notes to teams in different time zones or when transferring incident responsibility
  • Lead incident response engagements and teams for customers experiencing cybersecurity attacks
  • Coordinate with legal counsel and cyber insurance carriers as needed
  • Ensure appropriate actions neutralize threats
  • Conduct root cause analysis, including determining whether data exfiltration occurred
  • Produce reports with key-event timelines mapped to the MITRE ATT&CK framework and remediation guidance

Requirements

What you’ll need
  • 10+ years of experience leading incident response investigations involving ransomware, network breaches, malicious insiders, and web applications and database services
  • Experience leading BEC investigations
  • In-depth digital forensic analysis of AWS, Microsoft Azure, and GCP data
  • Continuously learning and staying informed of the changing threat landscape
  • Proven track record of neutralization and remediation of ransomware threats
  • Excellent understanding of the Incident Response process and cyber risks
  • Excellent oral and strong written communication skills
  • Ability to manage time effectively
  • Ability to delegate and prioritize tasks across multiple incidents
  • Ability to excel under stressful circumstances
  • Willingness to begin work early and/or stay late when warranted
  • Strong grasp of the MITRE ATT&CK framework
  • Mentoring and knowledge-sharing ability
  • Ability to work some weekends and holidays
  • Cybersecurity certifications such as CISSP, GCFA, or similar are an asset
  • Experience with SIEM technology such as Splunk or ELK is desirable
  • Willingness to work occasional overtime during peak times or holidays is desirable
  • Experience writing SQL queries is desirable
  • Experience writing PowerShell, Python, or Bash scripts is desirable

Benefits

Comp & perks
  • Bonus eligibility
  • Comprehensive benefits package
  • Remote-first working model
  • Employee-led diversity and inclusion networks
  • Annual charity and fundraising initiatives
  • Volunteer days
  • Global employee sustainability initiatives
  • Global fitness and trivia competitions
  • Global wellbeing days
  • Monthly wellbeing webinars and training