- Independently detect, investigate and respond to cyber threats across Sophos and its products, while engineering the detections, automations, reusable skills and agentic workflows that scale Internal Detection and Response
- The role combines incident response judgement with security engineering and the safe, measurable and observable use of AI
- Own complex investigations across the incident lifecycle, from triage and evidence collection through containment, recovery and lessons learned
- Act as a trusted front door for security issues, coordinating response across IDR, engineering, product and business teams
- Perform DFIR and endpoint forensics, including log, network and packet analysis, malware analysis and firewall investigation where applicable
- Write and improve detections, playbooks, orchestrations and preventions using evidence from incidents and threat hunting
- Build production-quality automation that removes repetitive work, improves consistency and enables analysts to operate at a higher layer
- Design model-agnostic, reusable skills and workflows that run across approved AI and agent platforms rather than depending on one model
- Use Claude, Codex, Copilot and future approved tooling to accelerate investigations, coding, testing, documentation and detection engineering
- Contribute through GitHub: create branches, raise and review pull requests, write tests, respond to feedback and support controlled deployment
- Instrument agentic workflows with logs, traces, metrics, evaluation results and failure signals so behaviour and outcomes are observable
- Apply safe harness design, least privilege, scoped tool access, approval gates, evidence validation, rollback and human review for consequential actions
- Communicate incidents, risks, decisions and technical outcomes clearly to engineering and leadership audiences
Benefits
- We encourage teams to get together in person periodically to help facilitate teamwork
- Remote-first working model & hybrid options
- Flexible start and end times for many roles
- Leadership development program
- Access to LinkedIn Learning
- Global internal coaching program (Coach Match)
- Periodic Sophos wellness days off for all Sophos to help employees relax and recharge
- Global wellbeing program, which offers a range of wellbeing resources, including Sophos Wellbeing Webinars, Stress Management Toolkits, and Developing Resilience Courses
- Free Employee Assistance Program (EAP) for confidential advice and counseling on a wide range of work and personal issues
- Free annual subscription to the Calm app
- Paid parental leave, caregiver leave & bereavement/compassion leave available
- We host some unforgettable social experiences for our global teams including our music festival SOPH-Fest, go-karting, Sophmudder, and incredible holiday parties!
- Our annual global fitness challenge, SOPH-Fit, sees thousands of employees taking part in our virtual global race around the world
- Each quarter, we celebrate our exceptional global team by running the Sophos Values Awards, which recognizes and rewards employees who embody the Sophos values and who we are as a company
- Health care benefits available worldwide
- Understanding of agent architecture, tool use, skill-based design, model portability and AI or automation safety controls
- Hands-on familiarity with Claude, Codex or comparable coding agents, including context design, task decomposition and validation of generated output
- Ability to design and write evals for agentic workflows and skills, covering task success, output quality, safety, regressions and common failure modes
- Clear written and verbal communication, sound opsec judgement and the ability to work effectively in a globally coordinated environment
- Practical capability in DFIR, endpoint and firewall forensics, threat hunting, detection engineering and analysis of unstructured telemetry
- Ability to write reliable automation in Python or a comparable language, work with APIs and query data using SQL
- Working knowledge of Git and GitHub engineering practices, including pull requests, code review, testing and CI/CD concepts
- Ability to design observability for automated work and use telemetry to troubleshoot, measure quality and improve reliability
- Strong enterprise incident response experience across endpoint, identity, cloud, network and product-focused investigations
- At Sophos, we believe in the power of diverse perspectives to fuel innovation.
Research shows that candidates sometimes hesitate to apply if they don’t check every box in a job description.
We challenge that notion.
Your unique experiences and skills might be exactly what we need to enhance our team.