Senior Manager, Incident Response
Job description
About the role
You will spearhead the expansion of Sophos Advisory Services by orchestrating cross-functional collaboration between Sophos teams and Incident Response/Readiness consultants. This role owns the end to end lifecycle of consulting engagements, balancing proactive capability building with reactive incident and breach response. You will mentor team members on service delivery excellence and advanced consulting techniques while directly partnering with customers to resolve complex blockers. The position requires a deep familiarity with threat actor tactics, techniques, and procedures to effectively counter evolving threats. You will be responsible for ensuring operational excellence and continuous improvement across incident response workflows. The role demands a strong commitment to billable work, with a minimum threshold of 15% engagement time dedicated to client billable activities. You will serve as a key liaison between technical consultants and client stakeholders to drive successful outcomes.
Key facts
What you'll do
Conduct comprehensive assessments of client incident response capabilities and maturity levels to identify gaps and opportunities.
Develop, manage, and operate scalable incident response capabilities that align with Sophos and industry best practices.
Lead complex incident response and breach response engagements, providing strategic direction and hands on guidance throughout the lifecycle.
Design and deliver specialized training, exercises, and workshops to enhance the readiness and proficiency of internal teams.
Perform threat hunting activities to proactively identify advanced threats and reduce dwell time within client environments.
Champion the implementation of preventative measures that strengthen infrastructure and data security postures.
Collaborate closely with IR team leaders and incident responders to ensure consistent and high quality service delivery.
Provide expert mentorship to consultants on advisory services, focusing on both technical depth and commercial acumen.
Interface directly with customers to understand business objectives and overcome critical blockers impacting security operations.
Maintain current knowledge of threat actor strategies, techniques, and procedures to effectively defend against sophisticated adversaries.
Oversee the on call program, ensuring adequate primary and support coverage for incident response operations.
Drive continuous improvement initiatives to enhance the efficiency and effectiveness of advisory service offerings.
Ensure all consulting engagements meet contractual obligations and adhere to defined scope and quality standards.
Act as a subject matter expert in incident readiness, contributing to the development of reusable frameworks and playbooks.
Requirements
Candidates must possess hands on experience in developing, managing, and operating incident response capabilities within a professional services environment.
You must have a proven track record of conducting training, exercises, and workshops for technical and non technical audiences.
Demonstrate fluency in the tactics, techniques, and procedures commonly used by threat actors to compromise organizations.
You must have a deep understanding of the drivers and constraints organizations face when attempting to secure their infrastructure and data.
The ability to operate effectively under pressure is essential, as you will be required to provide primary and support on call duties.
You must be willing to engage directly with customers to resolve complex issues and unblock critical security operations.
A commitment to billable work is required, with a minimum of 15% of your time allocated to client engagements.
You must be able to work collaboratively with cross functional teams including IR management, team leads, and consultants.
Practical notes
The role is based in Japan and requires the ability to work within the local time zone and cultural context. Travel may be required to meet client needs across various locations. Candidates must be eligible to work in Japan without sponsorship for this position. Visas are the responsibility of the successful candidate if relocation is necessary. There are no explicit deadlines published for this role, and the engagement is structured as a permanent position. Working hours are aligned with standard business expectations, with additional availability required for on call rotations. This position demands a high degree of autonomy and ownership over advisory services engagements. Successful candidates will contribute to the strategic growth of Sophos Advisory Services in the Japanese market. The focus remains on delivering measurable value to clients through expert incident response leadership and execution.