Defeat Cyberattacks
Senior Incident Response Analyst 1, MDR
Location
United Kingdom
Posted
61 days ago
Salary
0
Seniority
Senior
Job Description
Senior Incident Response Analyst 1, MDR
Sophos
About Us Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure-play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. In addition to MDR and other services, Sophos’ complete portfolio includes industry-leading endpoint, network, email, and cloud security that interoperate and adapt to defend through the Sophos Central platform. Secureworks provides the innovative, market-leading Taegis XDR/MDR, identity threat detection and response (ITDR), next-gen SIEM capabilities, managed risk, and a comprehensive set of advisory services. Sophos sells all these solutions through reseller partners, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) worldwide, defending more than 600,000 organizations worldwide from phishing, ransomware, data theft, other every day and state-sponsored cybercrimes. The solutions are powered by historical and real-time threat intelligence from Sophos X-Ops and the newly added Counter Threat Unit (CTU). Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com. Role Summary Sophos is seeking an experienced and motivated Senior Incident Response Analyst to support Managed Detection and Response (MDR) customers and managed service providers (MSPs) within the Critical Incident Response Unit (CIRU). As a Senior Incident Response Analyst, you will lead the investigative execution of active cyber incidents, working directly with customers and MSPs to investigate, contain, and support remediation efforts. Utilizing Sophos technologies, you will work with both large and small organizations across multiple countries and levels of technical maturity. This is a fast-paced role that requires the ability to make quick context-based decisions to disrupt adversary activity. What You Will Do - Utilize Sophos technologies to investigate, contain, and respond to cyber incidents - Mentor incident response analysts and MDR operations analysts by providing technical guidance, review, and escalation support - Perform advanced incident response analysis to identify initial access, persistence, and lateral movement to contain and remediate threats - Support MDR customers and MSPs by conducting phone calls and joining meetings to discuss cyber incidents, while often providing priority recommendations to contain, neutralize, and remediate - Conduct analysis of cyber incidents for malware, ransomware, and other common attack types - Maintain accurate and detailed documentation for analysis performed during cyber incidents - Work closely with internal SophosLabs, Detection Engineering, and Threat Hunting teams to continuously expand and improve detection logic - Work closely with Sophos MDR Operations teams in providing response, remediation guidance, and excellent customer service - Where appropriate, contribute to Sophos blogs, social media, and other sources on adversary tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and other investigative findings - Evaluate new technologies and processes to improve the overall incident response capability - Assist in creating accurate and detailed technical incident reports as a post-incident deliverable for MDR customers and MSPs What You Will Bring Essential: - 4+ years experience conducting cyber security investigations in a methodical manner and investigating threats or 2+ years experience performing incident response engagements - Understanding of network architecture and IT infrastructure - Experience creating technical documentation and technical reports for customers - Ability to work under high-pressure situations, when response time matters, to disrupt adversary activity - Network and endpoint (macOS, Linux, Windows) investigation experience; IDS, IPS, EDR, and basic malware analysis - Understanding of at least one of the following: OSQuery, SQL, and KQL - Experience applying frameworks such as MITRE Attack and Cyber Kill Chain - Ability to work some weekends and holidays - Knowledge of Windows and Linux command and script interpreters Desired: - Advanced cyber security certifications (GCFE/GCFA, CompTIA CySA+, OSCP, etc.) - Experience calling customers and providing excellent customer service - Publications, either written or acknowledged, within the cyber security field Ready to Join Us? At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back – we encourage you to apply. What's Great About Sophos? · Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship. · Our people – we innovate and create, all of which are accompanied by a great sense of fun and team spirit · Employee-led diversity and inclusion networks that build community and provide education and advocacy · Annual charity and fundraising initiatives and volunteer days for employees to support local communities · Global employee sustainability initiatives to reduce our environmental footprint · Global fitness and trivia competitions to keep our bodies and minds sharp · Global wellbeing days for employees to relax and recharge · Monthly wellbeing webinars and training to support employee health and wellbeing Our Commitment To You We’re proud of the diverse and inclusive environment we have at Sophos, and we’re committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos’ data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered | Sophos
Related Guides
Related Categories
Related Job Pages
More Incident Response Analyst Jobs
A company built to serve you. It's your career, Shelter it! Catastrophe Response Team- Traveling Storm Adjuster $23.82-$29.54 minimum starting pay Job Level: Individual Contributor Shelter maintains broad salary ranges for its roles in order to account for variations in geographic location, education, training, skills, relevant work experience, business needs and market demands. Please remember that this is the minimum starting base pay only and does not consider other components that make up the total rewards package for the position. This is a position where the adjuster works from home, living in and servicing the Jonesboro, AR area. Some travel will be required to assist in our regional area as needs arise. Home office equipment and company vehicle provided. What You Will Be Doing: The Catastrophe Response Team Adjuster will investigate, analyze, evaluate, and settle insurance claims involving auto damage losses. Specialize in adjusting property claims requiring physical inspection and requires extensive travel to a variety of geographic locations. Determine value of a claim and negotiates settlements. Involved in handling of complex property losses requiring expertise in fraud detection and prevention. Due to the duties and responsibilities of this position, a Credit Bureau Report, Motor Vehicle Report, and Criminal Background Check may be ordered on final candidates. What We're Looking For: - Requires excellent analytical, organizational, and decision-making skills. - Superior skills in investigation, organization, negotiation, communication, documentation, and customer service are required. - Must be physically able to travel long distances and lift/move/climb ladders. - Must be able to work outside in all temperatures and inspect property physically and visually. - Must be able to travel overnight as job requires. - Ability to maintain schedules and deadlines and work well with others. - Must possess a valid driver's license supported by a good driving history. - Requires minimal supervision and ability to work independently. - Ability to perform the essential functions of the position, with or without reasonable accommodation. Shelter's uncompromising commitment to excellence doesn't stop with our customers. We recognize our employees are what make us a premier organization in the insurance industry. Shelter Employees enjoy such benefits as: - Health, Dental, Voluntary Vision and Prescription Drug Insurance - Savings and Profit Sharing 401(k) - Paid Time Off for Sick and Personal Leave, Vacation and Holidays - Vitality Wellness Program - "Dress for Your Day" Dress Code - Flexible Scheduling - And much more! #IND1# If interested, please apply by: 04/28/2026
A company built to serve you. It's your career, Shelter it! Catastrophe Response Team- Traveling Storm Adjuster $23.82-$29.54 minimum starting pay Job Level: Individual Contributor Shelter maintains broad salary ranges for its roles in order to account for variations in geographic location, education, training, skills, relevant work experience, business needs and market demands. Please remember that this is the minimum starting base pay only and does not consider other components that make up the total rewards package for the position. This is a position where the adjuster works from home, living in and servicing the Edwardsville, IL area. Some travel will be required to assist in our regional area as needs arise. Home office equipment and company vehicle provided. What You Will Be Doing: The Catastrophe Response Team Adjuster will investigate, analyze, evaluate, and settle insurance claims involving auto damage losses. Specialize in adjusting property claims requiring physical inspection and requires extensive travel to a variety of geographic locations. Determine value of a claim and negotiates settlements. Involved in handling of complex property losses requiring expertise in fraud detection and prevention. Due to the duties and responsibilities of this position, a Credit Bureau Report, Motor Vehicle Report, and Criminal Background Check may be ordered on final candidates. What We're Looking For: - Requires excellent analytical, organizational, and decision-making skills. - Superior skills in investigation, organization, negotiation, communication, documentation, and customer service are required. - Must be physically able to travel long distances and lift/move/climb ladders. - Must be able to work outside in all temperatures and inspect property physically and visually. - Must be able to travel overnight as job requires. - Ability to maintain schedules and deadlines and work well with others. - Must possess a valid driver's license supported by a good driving history. - Requires minimal supervision and ability to work independently. - Ability to perform the essential functions of the position, with or without reasonable accommodation. Shelter's uncompromising commitment to excellence doesn't stop with our customers. We recognize our employees are what make us a premier organization in the insurance industry. Shelter Employees enjoy such benefits as: - Health, Dental, Voluntary Vision and Prescription Drug Insurance - Savings and Profit Sharing 401(k) - Paid Time Off for Sick and Personal Leave, Vacation and Holidays - Vitality Wellness Program - "Dress for Your Day" Dress Code - Flexible Scheduling - And much more! #IND1# If interested, please apply by: 04/28/2026
DFIR Analyst
InfiosAt Infios, we're not just looking for employees; we're looking for partners in innovation, growth, and purpose. Meeting you where you are to create the future you need is at the core of who we are and what we do. We believe the future is better when supply chains work better. We are an equal-opportunity employer and committed to inclusion in the workplace. At Infios, we believe that inclusion is a fundamental cornerstone of our success. We are committed to creating a safe and welcoming environment where every individual’s unique experiences and perspectives are valued. All qualified applicants will receive consideration for employment without regard to race, color, ethnicity, national origin, sex, sexual orientation, gender identity, marital status, pregnancy, religion, age, disability, veteran status, genetic information, or any other characteristic protected by law. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this role. If you require assistance or accommodation due to a disability during the recruiting process, please let us know at jobs@infios.com. Disclaimer: This job advertisement is not designed to cover a comprehensive listing of all duties or responsibilities that are required for this job. Please note that any salary information is a general guideline only. Applications must be submitted via our career site.
• Continuously monitor, triage, and respond to P1–P4 cybersecurity events • Lead major investigations and serve as the Incident Handler/Commander • Act as a central coordinator for cybersecurity events • Collaborate closely with internal business units
Department Name: IT Service Delivery Work Shift: Night Job Category: Information Technology Estimated Pay Range: $40.91 - $68.19 / hour Banner Health is committed to pay equity and transparency. The posted compensation range is a reasonable estimate that extends from the lowest to the highest pay Banner Health in good faith believes it might pay for this particular job, based on the circumstances at the time of posting. This range is based on possible base salaries and does not include the value of our total rewards package. Actual pay determined at offer will be based on years of relevant work experience, education, certifications, skills, and geographic location, along with a review of current employees in similar roles to ensure pay equity is achieved and maintained. Banner Health was named to Fortune’s Most Innovative Companies in America 2025 list for the third consecutive year and named to Newsweek's list of Most Trustworthy Companies in America for the second year in a row. We’re proud to be recognized for our commitment to the latest health care advancements and excellent patient care. The Banner Health Critical Response team steps in when our most critical IT services are disrupted—mobilizing quickly to restore stability, safeguard patient care, and support the teams who depend on technology every minute of the day. As a Major Incident Commander, you will be the operational engine behind our major incident response: monitoring for impact, keeping timelines and documentation crisp and accurate, ensuring process adherence, and helping teams stay aligned under pressure. When incidents are not active, you’ll support operational readiness—so when the next high-severity event hits, we respond faster and smarter. You’ll work under the guidance of the Major Incident Commanders. This role requires variable shifts plus responding to 24x7 critical alerts via mobile device or other connected platform. The schedule for this role is Monday-Friday, 10:00PM - 6:30AM AZ Time. This can be a remote position if you live in the following states ONLY: Al, AK, AR, FL, GA, ID, IN, IA, KS, KY, LA, MD,MI, MN, MS, MO, NH, NM, NY, NC, ND, OH, OK, OR, PA, SC, TN, TX, UT, VA, WA, WI AZ CA CO NE NV WY. No other states will be consider. Your pay and benefits (Total Rewards) are important components of your Journey at Banner Health. Banner Health offers a variety of benefit plans to help you and your family. We provide health and financial security options, so you can focus on being the best at what you do and enjoying your life. Within Banner Health Corporate, you will have the opportunity to apply your unique experience and expertise in support of a nationally-recognized healthcare leader. We offer stimulating and rewarding careers in a wide array of disciplines. Whether your background is in Human Resources, Finance, Information Technology, Legal, Managed Care Programs or Public Relations, you'll find many options for contributing to our award-winning patient care. POSITION SUMMARY This position is an expert providing advanced leadership during the highest‑impact incidents and drives continuous improvement of the Major Incident Management practice. This role shapes strategy, mentors the team, and partners closely with leadership across the organization. Working variable shifts and responding to 24x7 critical alerts on a mobile device or other connected platform for service disruptions is required for this role. CORE FUNCTIONS 1. Leads coordination of complex or high-impact major incident bridge calls and communication channels. Provides guidance to Coordinators and supports Major Incident Commanders during critical events. 2. Reviews incident records, timelines, and activity logs for quality, accuracy, and audit readiness. Identifies opportunities for improvement. 3. Oversees and refines outage notifications and status updates. Ensures messaging is clear, audience-appropriate, and aligned with business and clinical impact. 4. Evaluates monitoring and alerting performance across systems. Drives improvements to alerting strategy, routing, and response workflows. 5. Collaborates closely with Problem Management to improve RCA quality, identify systemic issues, and recommend preventive or corrective actions to reduce repeat incidents. 6. Analyzes and interprets major incident SLAs and KPIs. Recommends process, tooling, or operational changes to improve performance and reliability. 7. Leads updates to playbooks, escalation paths, and communication templates based on post-incident reviews, exercises, and operational experience. 8. Maintains deep knowledge of enterprise platforms, incident response processes, stakeholders, and downtime procedures. Serves as a subject matter expert and mentor. 9. Exercises incident command authority during active major incidents, including determining severity, directing escalation paths, managing risk tradeoffs, and determining when incidents are stabilized or resolved. MINIMUM QUALIFICATIONS Experience and education as normally obtained through an Associate’s degree and 2+ years of relevant experience in IT operations, service desk, NOC, or incident management. Proven experience in leading high-severity, enterprise-impacting incidents. Experience developing or improving incident management processes, playbooks, or workflows. Advanced facilitation and communication skills, including executive-level communications. Strong analytical skills with the ability to identify systemic issues and operational risk. Ability to coach and mentor other coordinators. Ability and willingness to work variable shifts and respond to 24x7 critical alerts via mobile device or other connected platforms for service disruptions. PREFERRED QUALIFICATIONS Bachelor’s degree in Information Systems, Computer Science, Healthcare Informatics, Healthcare Administration, Business Administration, or a related field preferred. ITIL Intermediate/Managing Professional certification or equivalent experience. Experience partnering with senior IT leaders, vendors, or business stakeholders during critical incidents. Experience designing or leading tabletop exercises or simulations. Experience influencing tooling, alerting, or workflow optimization. Additional related education and/or experience preferred. EEO Statement: EEO/Disabled/Veterans Our organization supports a drug-free work environment. Privacy Policy: Privacy Policy


