Senior Incident Response Consultant, Rapid Response
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 46d ago
The date the source published, not the day we noticed it (2026-07-31). Last seen at its source 1h ago.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
United Kingdom
The description states no restriction of its own. This is the source's own tag.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
lever employer's own board first seen 26d ago · last seen 1h ago
The listing
Role Summary
Sophos is seeking an experienced and motivated Senior Incident Response Consultant to join our Incident Response (IR) service. The Sophos IR team is an elite group of incident responders that are engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents.
As a Senior Incident Response Consultant on the Sophos IR team, you will be responsible for spearheading incident response engagements for customers who have experienced a cybersecurity attack. In this role, you will lead a team of Incident Response Consultants, running customer-facing calls, providing detailed written updates via email, and determining the priorities of the investigation, delegating tasks accordingly to your team.
In this role, you will be accountable for ensuring that the appropriate actions have been taken by both your team and the customer to effectively neutralize the threat. Additionally, you will be tasked with conducting a thorough root cause analysis to determine the origin of the incident, including identifying whether any data exfiltration occurred, provided the necessary evidence is available.
At the culmination of each engagement, you will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident and provide remediation guidance.
The ideal candidate for this role will possess extensive experience leading incident response efforts, a deep understanding of cybersecurity threats and mitigation strategies, and the ability to communicate complex technical information to executive-level stakeholders in a clear and concise manner.
What You Will Do
- The working week for this role will be Fri, Sat, Sun and Monday working with Tues, Wed and Thursdays off
- Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat
- Provide guidance to customers on best practices following an incident
- Lead daily update calls for customers to deliver forensic findings
- Deliver concise email updates to customers between update calls
- Direct the forensic investigations, identify priorities, and delegate tasks to analysts
- Conduct multiple Rapid Response incidents concurrently
- Determine TTPs identified by analysts and add them to the threat intel platform
- Write clear and concise Executive Summary style reports in a timely manner
- Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service
- Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead
What You Will Bring
- 5+ years of experience leading incident response investigations involving ransomware
- Experience leading BEC investigations
- Continuously learning and staying informed of the changing threat landscape
- Proven track record of successful neutralization and remediation of ransomware threats
- Excellent understanding of the Incident Response process
- Excellent understanding of cyber risks and able to qualify them to customers
- Excellent oral communication skills
- Strong written communication skills
- Ability to manage time effectively
- Able to delegate and prioritize tasks across multiple incidents
- Able to excel under stressful circumstances
- Occasionally willing to begin work early and/or stay late when warranted for customer engagements
- Strong grasp of the MITRE ATT&CK framework
- Enjoy mentoring and assisting in the development of junior analysts
- A team-player attitude with a willingness to share knowledge
- Ability to work some weekends and holidays
- Post-secondary education in Cybersecurity, comparable
- Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar)
- Experience with SIEM technology (e.g. Splunk, ELK, etc.)
- Willingness to work occasional overtime during peak times or holidays
- Experience writing SQL queries
- Experience writing PowerShell, Python, or Bash scripts
Desirable: