Sophos logo
SophosPosted 4 weeks ago

Senior Incident Response Consultant, Rapid Response

On-siteOxford, England, United Kingdom

Full TimeSenior LevelLarge

Job Summary

Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat. Provide guidance on best practices following an incident and lead daily update calls to deliver forensic findings. Direct forensic investigations, identify priorities, and delegate tasks to analysts while conducting multiple Rapid Response incidents concurrently. Determine TTPs identified by analysts and add them to the threat intel platform. Write clear and concise Executive Summary style reports in a timely manner, including timelines mapped to the MITRE ATT&CK framework. Responsible for basic to moderate complexity projects contributing to the development of the Sophos Rapid Response service. Provide daily handover notes to teams in different time zones or when incident responsibility is being transferred.

Required Qualifications

  • 5+ years of experience leading incident response investigations involving ransomware
  • Experience leading BEC investigations
  • Proven track record of successful neutralization and remediation of ransomware threats
  • Excellent understanding of the Incident Response process
  • Excellent understanding of cyber risks and able to qualify them to customers
  • Excellent oral communication skills
  • Strong written communication skills
  • Ability to manage time effectively
  • Able to delegate and prioritize tasks across multiple incidents
  • Able to excel under stressful circumstances
  • Occasionally willing to begin work early and/or stay late when warranted for customer engagements
  • Strong grasp of the MITRE ATT&CK framework
  • Enjoy mentoring and assisting in the development of junior analysts
  • A team-player attitude with a willingness to share knowledge
  • Ability to work some weekends and holidays
  • Post-secondary education in Cybersecurity, comparable

Desired Qualifications

  • Continuously learning and staying informed of the changing threat landscape
  • Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar)
  • Experience with SIEM technology (e.g. Splunk, ELK, etc.)
  • Willingness to work occasional overtime during peak times or holidays
  • Experience writing SQL queries
  • Experience writing PowerShell, Python, or Bash scripts

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce