Senior Incident Response Analyst, MDR
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 15h ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 9d ago
The date the source published, not the day we noticed it (2026-09-22). Last seen at its source just now.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
Canada
The description states no restriction of its own. This is the source's own tag.
Pay
$131k–219k/yr
Read out of the job description by us, not from a structured field. Shown in the posting's own currency and period; we never convert.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
lever employer's own board first seen 15h ago · last seen just now
The listing
Role Summary
Sophos is seeking a highly skilled Senior Incident Response Analyst to support Managed Detection and Response (MDR) customers within the Critical Incident Response Team (CIRT).
As a Senior Incident Response Analyst 2, you will lead complex and high-impact incident response engagements, operating across Responder, Advisor, and Commander roles as required. You are trusted to provide advanced technical leadership, shape investigative strategy, guide containment decisions, and ensure high-quality customer outcomes during critical security incidents.
What You Will Do
- Lead complex investigations involving advanced adversaries, multi-vector intrusions, or cross-environment compromise
- Serve as the primary Incident Advisor or delegated Commander for high-severity engagements
- Direct and coordinate investigative, forensic, and containment activities across multiple analysts
- Define engagement strategy, investigative priorities, and containment approaches based on risk and impact
- Validate and synthesize technical findings into clear, actionable guidance for customers and internal stakeholders
- Provide technical mentorship and oversight to IR and SOC analysts
- Collaborate closely with SOC, Threat Intelligence, and Detection Engineering teams to validate detections and close visibility gaps
- Lead or contribute to post-incident reviews, driving improvements to playbooks, tools, and response workflows
- Maintain accurate time and activity tracking to support operational visibility and capacity planning
What You Will Bring
- 5+ years of experience in incident response, MDR, or cyber security investigations, including leadership of complex incidents
- Advanced expertise in endpoint and network forensics, log analysis, and adversary tradecraft
- Strong understanding of enterprise network architecture and IT infrastructure
- Proven ability to lead investigations, validate findings, and design effective containment strategies
- Experience communicating technical findings to customers, including senior and executive stakeholders
- Demonstrated mentorship and leadership across incident response teams
- Ability to operate effectively under high-pressure, time-sensitive conditions
- Willingness to work some weekends and holidays as part of a rotation
- Advanced incident response or forensic certifications (GCFA, GCED, GCIH, OSCP, or equivalent)
- Experience acting as Incident Advisor or Commander during critical engagements
- Publications, presentations, or recognized contributions within the cybersecurity field
- Experience influencing detection strategy, tooling improvements, or service design
- Strong customer-facing presence with experience briefing executives during incidents
Essential:
Desired: