Threat Analyst 3
Job description
About the role
Join our Managed Threat Response team to provide proactive security monitoring and incident defense for global clients. You will work alongside incident responders, threat hunters, and ethical hackers to identify, investigate, and neutralize cyber threats using our proprietary platform. In this capacity, you will own the full lifecycle of threat detection and remediation for assigned customer environments, ensuring that complex security incidents are resolved efficiently and effectively. This role requires a high level of autonomy and judgment as you analyze sophisticated threats and translate technical risk into clear, actionable guidance for customers. You will be a key contributor to enhancing the security posture of organizations by leveraging advanced monitoring techniques and deep expertise in endpoint and network defenses. Success in this position means building trusted relationships with clients by delivering consistent, accurate, and timely security insights.
Key facts
What you'll do
- Analyze security logs and events using Sophos tools to detect malicious activity across endpoints and networks.
- Conduct proactive threat hunting exercises to uncover stealthy adversaries and potential security breaches before they escalate.
- Investigate complex security incidents by correlating data from multiple sources to determine root cause and scope.
- Communicate technical findings to both executive and technical customer stakeholders in a clear and concise manner.
- Manage customer interactions and requests through to final issue resolution, ensuring alignment with service level expectations.
- Provide actionable recommendations to clients to reduce their security risk and improve their overall resilience.
- Research emerging exploits, vulnerabilities, and Indicators of Compromise to enhance detection capabilities and protect customer environments.
- Coordinate with internal security and response teams to address active threats and support escalations as needed.
- Maintain detailed documentation of investigations, findings, and remediation steps for audit and knowledge-sharing purposes.
- Collaborate with product and engineering teams to provide feedback that influences future improvements to Sophos solutions.
- Monitor threat landscapes and adversary behaviors to adjust detection rules and improve monitoring effectiveness.
- Support the development and refinement of playbooks and standard operating procedures for common threat scenarios.
- Validate the effectiveness of security controls through testing and verification activities.
- Assist in the creation of threat intelligence reports that highlight trends and insights relevant to managed customers.
- Ensure all activities are conducted in compliance with internal policies and customer contractual obligations.
Requirements
- Minimum 4+ years of experience in a Security Operations Center or IT security team in a professional capacity.
- Demonstrated experience with threat hunting and continuous monitoring of endpoint or network security events.
- Proficiency in administering Windows Server and workstations, with additional experience in either Linux or Apple operating systems.
- Solid understanding of incident response lifecycles and established frameworks such as Mitre ATT&CK to guide investigations.
- In-depth knowledge of common adversary tactics, including persistence mechanisms, obfuscation methods, and defense evasion techniques.
- Foundational understanding of network traffic analysis, including core protocols, TCP/IP concepts, and routing behaviors.
- Proven ability to analyze Windows event logs to identify anomalies, indicators of compromise, and patterns of suspicious behavior.
- Availability to work outside standard business hours, including weekends and holidays, to support Sophos 24/7/365 service operations.
- Willingness to adhere to a defined shift schedule of 8AM to 5PM EST for consistent coverage and team coordination.
- Strong written and verbal communication skills to articulate technical issues to diverse audiences.
- Capability to work independently and as part of a distributed security operations team in a remote-first environment.
- Commitment to maintaining confidentiality and handling sensitive security data with the utmost professionalism.
- Legal authorization to work in Canada without the need for employer sponsorship or work permits.
- Willingness to continuously learn and adapt to new threats, tools, and technologies in the cybersecurity space.
Nice to have
- Proficiency in constructing SQL queries to extract and analyze security data from databases and log repositories.
- Hands-on experience with OSQuery for querying and monitoring endpoint configurations and states.
- Background in managing enterprise SIEM platforms and correlating data across multiple security tools.
- Scripting and programming skills, particularly using PowerShell to automate repetitive tasks and enhance efficiency.
- Familiarity with security orchestration, automation, and response concepts to streamline incident handling.
- Experience in a customer-facing or advisory security role that requires translating technical concepts for business stakeholders.
- Understanding of cloud security architectures and how they intersect with endpoint protection strategies.
- Participation in cybersecurity communities, conferences, or training initiatives to stay current on industry trends.
Practical notes
- Applicants must possess legal authorization to work in Canada without employer sponsorship.
- Sophos operates as a remote-first organization, allowing flexibility in work location within the country.
- A comprehensive benefits package is included to support overall well-being and professional growth.
- Personal data submitted during the application process will be retained for 12 months in accordance with the company privacy policy.
- This position operates on a permanent, full-time basis with standard expectations for availability during shift hours.
- The role requires consistent participation in on-call rotations as determined by team requirements and incident severity.
- All hiring decisions are contingent upon successful completion of any required assessments or background checks.