Senior Incident Response Engineer
SophosIndiaPermanent1w ago
Job description
About the role
Sophos is looking for a seasoned professional to join its Incident Response unit. This group handles cyberattacks for organizations around the world using standard forensic methods and Sophos products, drawing on the expertise of Sophos X-Ops. You will direct investigations for customers who have suffered a security breach, guiding a team of consultants and managing client communications. You will also be responsible for determining the origin of the incident and checking if any information was taken.
Key facts
What you'll do
- Lead incident response projects for customers who have experienced a severe cyberattack and significant data breach.
- Manage a dedicated team of junior consultants during active threat investigations and comprehensive remediation phases.
- Conduct direct calls with clients to discuss ongoing security events and provide immediate tactical guidance.
- Send detailed written updates to customers via email regularly to keep them fully informed.
- Set the priorities for each investigation and assign specific tasks to individual team members promptly.
- Ensure the team and the customer take proper steps to stop the active threat immediately.
- Perform a deep root cause analysis to find out exactly how the breach initially started.
- Identify if any sensitive data was stolen, provided the necessary forensic evidence exists to prove it.
- Create an executive summary report at the end of every single engagement cycle for stakeholders.
- Map the timeline of key events to the MITRE ATT&CK framework accurately and thoroughly throughout.
- Provide detailed remediation guidance to help organizations recover and strengthen their overall security defenses quickly.
- Translate complex technical findings into clear language that executive-level stakeholders can easily understand and act on.
Requirements
- Possess extensive experience leading incident response efforts in a professional services environment consistently and effectively.
- Demonstrate a deep understanding of various cybersecurity threats and effective mitigation strategies used today widely.
- Communicate complex technical information to non-technical executive stakeholders in a clear and concise written manner.
- Have a strong background in forensic analysis and cybersecurity investigation methodologies and related technical tools.
- Show proven ability to manage and mentor a team of incident responders effectively across all shifts.
- Maintain composure and make sound decisions during high-pressure security crisis situations without any hesitation or delay.
- Understand the mechanics of modern cyberattacks and adversary tactics, techniques, and procedures thoroughly and completely.
- Hold a relevant degree or equivalent practical experience in the cybersecurity field as a requirement.
- Be comfortable working rotating on-call shifts to support global customer needs around the clock reliably.
- Exhibit strong written and verbal communication skills across diverse technical and business audiences with clarity.
Nice to have
- Familiarity with Sophos specific products like XDR and endpoint protection platforms is highly helpful for success.
- Experience working within a managed detection and response service delivery model is always advantageous to have.
- Knowledge of identity threat detection and response technologies and their practical implementations matters greatly in this role.
- Previous exposure to next-generation SIEM platforms and advanced log analysis techniques is very beneficial for the team.
- Understanding of cloud security principles and email security infrastructure configurations adds significant value to the investigations.
Skills & tools
- Proficiency in industry-standard forensic tools and various investigation software applications is absolutely essential for this role.
- Expertise with endpoint detection and response technologies and related security platforms required for daily operations.
- Strong analytical skills for interpreting complex network and system logs efficiently and accurately during investigations.
- Ability to use automation scripts to accelerate investigation workflows and reduce manual effort significantly over time.
- Working knowledge of the MITRE ATT&CK framework and precise mapping methodologies is vital for proper documentation.
- Experience with cloud-based security monitoring and alerting systems to detect anomalies quickly and respond appropriately.
- Familiarity with network traffic analysis tools and intrusion detection system configurations is useful for deeper analysis.
- Knowledge of endpoint, network, email, and cloud security platforms is beneficial for comprehensive threat hunting.
Practical notes
- This role is based in India and requires regular on-site presence at the local office daily without exception.
- Candidates must be able to work full-time hours as part of the permanent staff team consistently.
- The position involves frequent communication with international customers across different time zones throughout the day and night.
- Applicants should expect to participate in ongoing training on the latest threat landscapes and emerging vulnerabilities continuously.
- Travel may be required occasionally to client sites or regional offices to support critical incidents and deployments.