sophos - Senior Incident Response Consultant, Rapid Response
Requirements
• Continuously learning and staying informed of the changing threat landscape • Proven track record of successful neutralization and remediation of ransomware threats • Excellent understanding of the Incident Response process • Excellent understanding of cyber risks and able to qualify them to customers • Ability to manage time effectively • Able to delegate and prioritize tasks across multiple incidents • Able to excel under stressful circumstances • Occasionally willing to begin work early and/or stay late when warranted for customer engagements • Strong grasp of the MITRE ATT&CK framework • Enjoy mentoring and assisting in the development of junior analysts • A team-player attitude with a willingness to share knowledge • Ability to work some weekends and holidays • Post-secondary education in Cybersecurity, comparable • Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar) • Experience with SIEM technology (e.g. Splunk, ELK, etc.) • Willingness to work occasional overtime during peak times or holidays • Experience writing PowerShell, Python, or Bash scripts • Ready to Join Us?
Responsibilities
• The working week for this role will be Fri, Sat, Sun and Monday working with Tues, Wed and Thursdays off • Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat • Provide guidance to customers on best practices following an incident • Lead daily update calls for customers to deliver forensic findings • Deliver concise email updates to customers between update calls • Direct the forensic investigations, identify priorities, and delegate tasks to analysts • Conduct multiple Rapid Response incidents concurrently • Determine TTPs identified by analysts and add them to the threat intel platform • Write clear and concise Executive Summary style reports in a timely manner • Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service • Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead • 5+ years of experience leading incident response investigations involving ransomware
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT