Defeat Cyberattacks
Principal Incident Response Engineer
Location
Canada
Posted
37 days ago
Salary
$161K - $268K / year
Seniority
Lead
Job Description
Principal Incident Response Engineer
Sophos
• Conduct comprehensive reviews of incident response plans, identifying gaps and developing tailored strategies to strengthen organizational preparedness. • Design and deliver customized incident response playbooks to address specific threats and operational needs. • Facilitate training sessions on incident response fundamentals to build customer capabilities. • Lead workshops, tabletop exercises, drills, and functional simulations to evaluate and improve readiness. • Provide strategic guidance to customers on integrating readiness into broader security programs. • Serve as a subject matter expert in digital forensics and incident response (DFIR). • Lead large-scale, complex investigations involving host, network, and cloud artifacts to determine the nature, scope, and root cause of cyber incidents. • Guide containment, remediation, and recovery efforts to secure environments post-incident. • Maintain a professional, calming, and authoritative presence during high-pressure incidents. • Brief senior leadership and technical teams on findings, risks, and recommendations.
Job Requirements
- Comprehensive experience in both readiness and incident response.
- Strong analytical and problem-solving skills.
- Ability to lead and mentor cross-functional teams.
- Excellent communication skills, including executive briefings.
- Proven ability to manage high-stakes engagements.
- Experience with forensic tools and techniques (e.g., EDR, log analysis, malware analysis).
- Familiarity with enterprise environments including Windows, Linux, Azure, AWS, and M365.
- Strong understanding of attacker Tactics, Techniques, and Procedures (TTPs) and modern detection and response strategies.
- Willingness to travel up to 20%, including on short notice, to support on-site customer engagements.
- 12–15 years of experience in cybersecurity or related fields, with a focus on incident response and readiness.
- Demonstrated ability to lead high-profile incidents and readiness initiatives.
Benefits
- Sophos operates a remote-first working model, making remote work the primary option for most employees.
- Employee-led diversity and inclusion networks that build community and provide education and advocacy.
- Annual charity and fundraising initiatives and volunteer days for employees to support local communities.
- Global employee sustainability initiatives to reduce our environmental footprint.
- Global fitness and trivia competitions to keep our bodies and minds sharp.
- Global wellbeing days for employees to relax and recharge.
- Monthly wellbeing webinars and training to support employee health and wellbeing.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Responsible for the implementation, administration and continuous improvement of the security solutions identified in the organization’s security program to ensure adequate protection of information assets. • Responsible for day-to-day security operations including supporting and maintaining a wide range of information security products. • Work jointly with other cyber security team members to coordinate, facilitate and effectively implement and maintain compliance of the organization’s security policies and procedures. • Administer security posture, identify and remediate vulnerabilities, perform threat modeling, implement threat protection, and respond to security incident escalations. • Investigate, respond, and hunt for threats using Microsoft Azure Sentinel, Azure Defender, Microsoft 365 Defender, and third-party security products. • Implement and manage secure systems to ensure confidentiality, integrity, availability, safety, privacy and recovery of digital assets. • Implement, manage and support secure network solutions to protect against threats. • Monitor security advisory groups and ensure necessary updates, patches and preventive measures are in place.
Offensive Security Engineer
TryHackMeTryHackMe is an online, cloud-based, cyber security training platform used by individuals and academics alike.
• Work directly with the AI agent system, run it against targets, understand where it performs well and where it falls short, and provide structured feedback to improve coverage and accuracy • Validate, reproduce, and escalate findings, writing clear and reliable proof-of-concepts that demonstrate real-world exploitability • Coordinate disclosures across OSS projects and bug bounty platforms, managing timelines and communication effectively • Contribute to public security research and technical content that is relevant and valuable to the security community • Research emerging vulnerability classes and attack techniques, and translate those insights into improvements in how the system tests • Build and maintain custom tooling where needed, including automation scripts, payload lists, and testing harnesses tailored to specific targets
Grid Automation Operational Technology (OT) Cybersecurity and Networking Specialist
HitachiHitachi Social Innovation is POWERING GOOD
Title: Grid Automation Operational Technology (OT) Cybersecurity and Networking Specialist Hybrid locations Raleigh, North Carolina, United States time type Full time Job Description: Job ID: R0127741 Company Name: HITACHI ENERGY USA INC Profession (Job Category): IT, Telecom & Internet Job Schedule: Full time Remote: No Job Description: The overall responsibility of the OT Cyber and Networking Specialist is providing cyber, networking and product technical support for our regional team, system integrators and utility customers using Hitachi Energy Automation and Communications solutions and products. Pre- and post-sales customer engagement supporting the regional Hitachi Energy teams in customer product system validation, technical evaluations and solution demonstrations. Apply knowledge of cybersecurity and complex communication networking using utility OT communication infrastructure practices and theories in determining equipment configuration and performance. Prepare solutions for customer demonstration, evaluation and diagnostics in OT applications including Substation Automation, Distribution Automation utilizing Wired (Ethernet/MPLS) and Wireless Broadband (Cellular/LTE and Mesh) communications networks. Regional customer engagement, communicating with and responding to customer support requests and inquires including site installation issues requiring service and support. JOB DUTIES: Key Responsibilities could include but are not limited to: - Debug, resolve and reproduce the most important issues for our customers. - Interface with other developers, quality team, and product management members to improve overall customer experience. - Assess, inspect and trouble-shoot devices, prototypes and test equipment as necessary. - Provide regional customer service and support remote and onsite when required to perform equipment assessment, application triage and software and hardware field upgrades. - Create, prepare, build, test and modify equipment used for application diagnostics and demonstration. Preparing equipment, devices and other equipment working from drawings and specifications. - Participate in industry events, trade shows, technical conferences and standardization. - Assist in the implementation and maintenance of cybersecurity measures for Grid Automation OT products and solutions. - Monitor and analyze network traffic to identify potential security threats. - Collaborate with the Grid Automation team to develop and deploy security protocols. - Participate in cybersecurity incident response and recovery efforts. - Stay updated on the latest cybersecurity trends and technologies. - Configure/manage network devices to ensure optimal performance and security. - Network and architecture design to support secure and efficient communication. - Troubleshoot network-related issues and provide solutions to enhance network stability. COMPLEXITY OF TASKS: - Requires knowledge and experience of utility communications infrastructure, Information Technology and Operation Technology automation and control systems, maintenance, and operation practices. - Must be able to work under the direction of the regional technical sales and application teams to prepare/configure devices and applications, quality assurance testing to validate application performance. - Requires problem solving and diagnostic experience for device/solution application issues recommending corrective action. - Assist regional team in executing customer demonstrations and pilots. - Self-starter and able to perform duties with minimal guidance. - Excellent analysis and problem-solving skills. - Team-player attitude. Equal Employment Opportunity (EEO)-Females/Minorities/Protected Veterans/Individuals with Disabilities Protected veterans and qualified individuals with a disability may request a reasonable accommodation if you are unable or limited in your ability to use or access the Hitachi Energy career site as a result of your disability. You may request reasonable accommodations by completing a general inquiry form on our website. Please include your contact information and specific details about your required accommodation to support you during the job application process. This is solely for job seekers with disabilities requiring accessibility assistance or an accommodation in the job application process. Messages left for other purposes will not receive a response.
• Play a key role in looking after the vulnerability management process at Glia • Collaborate with other teams on the implementation of new security policies and procedures • Manage, test and categorize incoming information on security incidents (internal, reported, or industry-wide) • Perform regular vulnerability scans and security control reviews to ensure a continuously strong security posture • Participate in security reviews and risk assessments of AI tools used across the company • Assist Compliance in ongoing compliance activities and monitoring efforts across different regulations (GDPR, SOC 2, HIPAA, PCI-DSS, CCPA, etc.)




