Senior Incident Response Lead — Remote

Sophos

Canada

On-site

CAD 131,000 - 219,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Sophos seeks an experienced Senior Incident Response Consultant to join our DFIR team in a remote-first, largely Canada-based role. You will lead incident response engagements, coordinate with customers and stakeholders, and deliver clear executive summaries with MITRE ATT&CK alignment.

You will manage multiple incidents, mentor junior analysts, and help drive the development of the Sophos DFIR service through practical, high‑impact investigations and remediation guidance.

Qualifications

  • Experience leading incident response investigations (ransomware, breaches, threats).
  • Experience with cloud forensics (AWS, Azure, GCP).
  • Strong written and verbal communication; able to mentor analysts.

Responsibilities

  • Lead incident response engagements with customers.
  • Coordinate with legal and cyber insurance as needed.
  • Produce executive summary reports with MITRE ATT&CK mapping.
  • Direct forensic investigations and prioritize tasks across incidents.
  • Provide regular written updates between calls.

Skills

Incident response leadership
Digital forensics
Team leadership
MITRE ATT&CK
Threat intel
Communication

Education

Bachelor's degree in CS/Security

Tools

Splunk
ELK
SQL
PowerShell
Python
Bash

Job description

Sophos seeks an experienced Senior Incident Response Consultant to join our DFIR team in a remote-first, largely Canada-based role. You will lead incident response engagements, coordinate with customers and stakeholders, and deliver clear executive summaries with MITRE ATT&CK alignment.

You will manage multiple incidents, mentor junior analysts, and help drive the development of the Sophos DFIR service through practical, high‑impact investigations and remediation guidance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Analyst - MDR & Threat Hunting Lead
Senior Threat Analyst - MDR & Threat Hunting Lead

Sophos Group • Canada

On-site
CAD 86,000 - 143,000
Bonus eligibility
Comprehensive benefits package
Remote-first culture
Incident Response Consultant - Remote, Up to 30% Travel
Incident Response Consultant - Remote, Up to 30% Travel

Forensic Focus Limited • Quebec

Hybrid
CAD 70,000 - 110,000
Incident Response Senior Consultant
Incident Response Senior Consultant

Forensic Focus Limited • Canada

On-site
CAD 120,000 - 180,000
Senior Incident Response Consultant — Travel-Ready
Senior Incident Response Consultant — Travel-Ready

Forensic Focus Limited • Canada

On-site
CAD 120,000 - 180,000
Lead Forward-Deployed Detection & Response Consultant
Lead Forward-Deployed Detection & Response Consultant

Google • Ottawa

On-site
CAD 140,000 - 190,000
Global Incident Response Lead, Cyber Defense
Global Incident Response Lead, Cyber Defense

CyberClan • Canada

On-site
CAD 100,000 - 130,000
Senior Cyber Security Analyst Incident Response Lead
Senior Cyber Security Analyst Incident Response Lead

QuadReal Property Group • Vancouver

On-site
CAD 125,000 - 173,000
Health & dental
Pension plan
Paid time off
+1
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Senior AI-Driven Forward-Deployed Detection & Response Lead
Senior AI-Driven Forward-Deployed Detection & Response Lead

Google Inc. • Ottawa

On-site
CAD 166,000 - 170,000
Equity
Bonus target
Benefits package
Threat Analyst 3
Threat Analyst 3

Sophos Group • Canada

On-site
CAD 74,000 - 123,000