Threat Analyst 3
SophosCanadaPermanent1w ago
Machine LearningAISecurityAnalystSolutionsPlatformAutomationremotecurated-jd
Job description
Threat Analyst 3 at Sophos.
About the role
Join our Managed Threat Response team to provide proactive security monitoring and incident defense for global clients. You will work alongside incident responders, threat hunters, and ethical hackers to identify, investigate, and neutralize cyber threats using our proprietary platform.
Key facts
What you'll do
- Analyze security logs and events using Sophos tools to detect malicious activity.
- Communicate technical findings to both executive and technical customer stakeholders.
- Manage customer interactions and requests through to final issue resolution.
- Provide actionable recommendations to clients to reduce their security risk.
- Research emerging exploits, vulnerabilities, and Indicators of Compromise to improve detection capabilities.
- Coordinate with internal security and response teams to address active threats.
Requirements
- Minimum 4+ years of experience in a Security Operations Center or IT security team.
- Experience with threat hunting and endpoint or network security monitoring.
- Proficiency in administering Windows Server and workstations, plus experience with either Linux or Apple operating systems.
- Understanding of incident response procedures and the Mitre ATT&CK framework.
- Knowledge of adversary tactics, including persistence, obfuscation, and defense evasion.
- Foundational understanding of network traffic analysis, including TCP/IP, routing, and protocols.
- Ability to analyze Windows event logs.
- Availability to work outside standard business hours, including weekends and holidays, to support our 24/7/365 service.
- Shift: 8AM to 5PM EST.
Nice to have
- Proficiency in SQL query construction.
- Experience with OSQuery.
- Background in enterprise SIEM management.
- Scripting and programming skills, specifically in PowerShell.
Skills & tools
- Windows OS administration
- Linux or Apple OS administration
- Network traffic analysis
- Incident response
- Threat hunting
- Mitre ATT&CK framework
Practical notes
- Applicants must possess legal authorization to work in Canada without employer sponsorship.
- Sophos operates as a remote-first organization.
- Comprehensive benefits package included.
- Personal data provided during the application process is retained for 12 months per our privacy policy.