Full-Time

Senior Incident Response Analyst 2

Posted on 5/24/2025

Sophos

Sophos

1,001-5,000 employees

Provides cybersecurity solutions for businesses

Compensation Overview

CA$131k - CA$219k/yr

+ Bonus

Remote in Canada

Remote

This position involves up to 60% travel for on-site services.

Category
🔒IT & Security (1)
Required Skills
Microsoft Azure
AWS
Requirements
  • Must have 7+ years of Incident Response with a focus on incident response readiness, preparedness, or IR program development
  • Must have 5+ years years building or managing IR capabilities across departments, including IR plans, playbooks, readiness assessments, and simulation exercises
  • Deep knowledge of incident response frameworks (e.g., NIST 800-61, MITRE ATT&CK, Cyber Kill Chain) and how to operationalize them in a preparedness context
  • Experience designing and facilitating tabletop exercises, purple teaming, or scenario-based simulations
  • Strong understanding of threat intelligence integration and detection strategy alignment
  • Proven ability to mentor analysts and elevate organizational response maturity
  • Skilled at documenting and improving IR procedures, runbooks, and escalation paths
  • Excellent written and verbal communication skills, including executive briefings and post-exercise reports
  • Ability to manage multiple readiness initiatives and influence cross-functional teams
  • Experience with SOAR platforms, playbook automation, and detection rule tuning
  • Familiarity with cloud security and forensics (AWS, Azure, hybrid environments)
Responsibilities
  • Serve as subject matter expert in incident response capability development and improvement
  • Manage consulting workload, client requirements, and internal projects and tasking as assigned
  • Design and deliver incident response exercises to test client incident response plans; oversee the delivery of exercises by other consultants
  • Develop detailed incident response plans and playbooks based on client needs
  • Contribute to the continual improvement of services that we deliver to clients and the processes that the team utilizes to deliver them
  • Provide objective, actionable, and complete guidance that enables and improves our customers’ incident management capabilities
  • Conduct assessments of client readiness to respond to incidents, including designing and delivering incident response exercises to test client incident response capabilities; review the assessments of other consultants
  • Support complex incident response; review analysis and conclusions of other consultants
  • Document findings, develop recommendations and present both orally and in written reports
  • Promote Sophos by participating in external speaking engagements, writing whitepapers and blogposts, and ensuring identification of opportunities for additional support to be provided to clients
  • Mentor junior staff
Desired Qualifications
  • Preferred certifications such as GCFA, GCFE, GCIH, CISSP, or similar
  • Experience in business continuity, disaster recovery, or cyber resilience programs
  • Willingness to support after-hours exercises or response readiness testing if needed

Sophos provides cybersecurity solutions to protect businesses from digital threats like malware, ransomware, and phishing attacks. Their products include endpoint protection for individual devices, network security for entire systems, and mobile security for smartphones and tablets. A key feature is Sophos Central, a cloud-based management console that allows users to oversee all security measures from one platform, making it easier to manage and respond to threats. Additionally, Sophos offers Managed Detection and Response (MDR) services, where experts monitor and address security incidents for clients who may not have in-house capabilities. Unlike many competitors, Sophos focuses on an integrated approach to security, combining various services and products under a subscription model, which provides a consistent revenue stream. The company's goal is to enhance the security posture of organizations of all sizes, ensuring they are well-protected against evolving cyber threats.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$4.7B

Headquarters

Abingdon, United Kingdom

Founded

1985

Simplify Jobs

Simplify's Take

What believers are saying

  • MSP Elevate program enhances cybersecurity offerings for service providers, boosting market penetration.
  • Sophos' partnership with EHW Technology to Gold status expands collaborative opportunities.
  • Rising ransomware attacks increase demand for Sophos' Managed Detection and Response services.

What critics are saying

  • Rising ransomware payments pose a financial burden on companies.
  • Sophos' reliance on vulnerable knowledge-based authentication methods is a security risk.
  • Data theft risks in smart cars challenge Sophos' ability to secure personal data.

What makes Sophos unique

  • Sophos Central offers a unified platform for managing diverse security solutions.
  • Sophos' MDR services provide expert monitoring and response to security incidents.
  • Sophos Firewall is recognized as the #1 Overall Firewall Solution by G2 users.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Disability Insurance

Remote Work Options

Wellness Program

Mental Health Support

Company News

Louisville Geek
Jul 10th, 2025
Faster Threat Containment: Optimizing Sophos MDR with Microsoft 365 Response Actions

When Sophos released Microsoft 365 Response Actions, Louisville Geek, Llc jumped at the opportunity to enhance its clients' protection.

Sophos
Jul 3rd, 2025
Sophos Firewall Recognized as the #1 Overall Firewall Solution by G2 Users

G2, a major technology user review platform, has just released their Summer 2025 Reports, where Sophos Firewall was rated the #1 Firewall in the Overall Firewall Grid.

EHW
Jun 18th, 2025
EHW Partners with Sophos

EHW Technology is excited to announce that EHW has officially upgraded its partnership with Sophos from Silver to Gold Partner status, further strengthening its commitment to delivering exceptional cybersecurity services.

National Original Alliance
Jun 13th, 2025
Ransomware Gangs Exploit Unpatched SimpleHelp Flaws to Target Victims with Double Extortion

Final month, Sophos revealed {that a} Managed Service Supplier's SimpleHelp deployed was accessed by the menace actor utilizing these flaws, after which leveraged it to pivot to different downstream clients.

Securities.io
May 22nd, 2025
Ransom Approved: 5 Public Companies That Paid Off Cyber Attackers

An increasing number of organizations are experiencing a ransomware attack. According to Sophos, 59% of organizations experienced one in 2024 and the majority of them (70%) resulted in data encryption.Not just the number of ransomware attacks, but the payment amount has also been rising. The median ransomware payment was less than $200k in 2023, which surged 650% to $1.5 million in about a year, as per IBM data.These attacks are projected to cost $275 billion in global damages annually by 2031. So, what are ransomware attacks?Ransomware is a type of malware, malicious software designed to block an organization’s access to its system or encrypt its data.To do this, attackers infect a system with a virus, which they use to send phishing emails that may contain a malicious link or steal an employee’s login credentials to gain unauthorized access to the enterprise network.In exchange for decryption keys or restoring access to the system, cybercriminals demand ransom money from the victims. Organizations are put in a difficult situation where paying the ransom seems like the simplest and cost-effective way to get their access back.Some ransomware variants have added functionality like data theft, which gives yet another incentive to pay the ransom. But in some high-profile cases, paying the ransom could actually be the least damaging option, despite the risks.Companies That Paid Ransom to Protect Their CustomersWhile agreeing to the demands of the attackers and paying ransom is not the ideal way to deal with cybercrimes, as not only does it not guarantee the safe return of stolen data or restoration of the entity's operations, but it also encourages further cyber attacks, sometimes there’s no other choice to protect the business and customers.With that, now let’s take a look at some of the most high-profile cybercrime cases where the companies paid the ransom and all that occurred afterwards.One of the largest insurance companies in the US, CNA Finance Corp., became the victim of a ransomware attack in March 2021

INACTIVE