Threat Analyst

Sophos

Ottawa

Hybrid

CAD 70,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remote-first culture
Hybrid options
Flexible start times
Wellbeing program
EAP & counseling

Job summary

Sophos is seeking a Threat Analyst 1 for its Managed Threat Response (MDR) team. You will monitor, detect, and respond to cyber threats across customer environments, working with threat hunters, IR analysts, and engineers to prevent attacks and minimize risk.

You will analyze logs, investigate security events, and clearly document findings for technical and executive audiences, helping customers resolve issues and improve defenses. This role involves 24x7 awareness and collaboration across teams.

Qualifications

  • Minimum 2+ years in a SOC or computer security team in an IT environment.
  • Experience with SIEM data management and endpoint monitoring.
  • Proficiency with OSQuery and scripting (PowerShell).
  • Knowledge of MITRE ATT&CK framework and threat hunting practices.

Responsibilities

  • Monitor, detect and respond to threats on customer environments.
  • Investigate and analyze logs and security events using Sophos tooling.
  • Communicate findings to technical and executive stakeholders and drive resolution.
  • Collaborate with security engineers, threat hunters and IR teams to operationalize detections.
  • Research emerging IOCs and tactics to improve protection for customers.
  • Engage with customers to provide recommendations to reduce risk and prevention.

Skills

SQL query construction
MITRE ATT&CK
SOC experience
Troubleshooting
Powershell
OSQuery
Windows/Linux
Threat hunting
Network traffic analysis

Tools

OSQuery
SIEM

Job description

  • As a Threat Analyst 1 on our Managed Threat Response (MDR) team, you will provide best-in-class monitoring, detection, and response services to proactively defend customer environments before attacks prevail
  • You will work alongside and contribute to a team of cyber threat hunters, incident response analysts, engineers, and ethical hackers by using enterprise, log analysis and endpoint collection systems to facilitate investigations, identification, and neutralization of cyber threats. Shift: 8-5pm ET
  • Investigate and analyze logs and security-related events via Sophos tooling
  • Identify and respond to cyber threats occurring within customer environments
  • Communicate and document findings to various customer audiences including technical and executive teams
  • Follow up with customers through to issue resolution and drive continuous improvement by providing detailed recommendations to minimize risk in customer environments
  • Acknowledge and satisfy inbound customer requests and interact with customers through various mediums
  • Collaborate and assist with core security and threat response teams
  • Actively research emerging Indicators of Compromise/Attack, exploits and vulnerabilities with the intent of operationalizing findings to better protect our customers
Benefits
  • We encourage teams to get together in person periodically to help facilitate teamwork
  • Remote-first working model & hybrid options
  • Flexible start and end times for many roles
  • Leadership development program
  • Access to LinkedIn Learning
  • Global internal coaching program (Coach Match)
  • Periodic Sophos wellness days off for all Sophos to help employees relax and recharge
  • Global wellbeing program, which offers a range of wellbeing resources, including Sophos Wellbeing Webinars, Stress Management Toolkits, and Developing Resilience Courses
  • Free Employee Assistance Program (EAP) for confidential advice and counseling on a wide range of work and personal issues
  • Free annual subscription to the Calm app
  • Paid parental leave, caregiver leave & bereavement/compassion leave available
  • We host some unforgettable social experiences for our global teams including our music festival SOPH-Fest, go-karting, Sophmudder, and incredible holiday parties!
  • Our annual global fitness challenge, SOPH-Fit, sees thousands of employees taking part in our virtual global race around the world
  • Each quarter, we celebrate our exceptional global team by running the Sophos Values Awards, which recognizes and rewards employees who embody the Sophos values and who we are as a company
  • Health care benefits available worldwide
A plus if you have:
  • Experience with SQL query construction
  • Knowledge of Mitre ATT&CK framework
  • Passion for all things related to information technology and cybersecurity
  • Minimum 2+ years of experience working in a SOC environment or computer security team in an IT environment
  • Excellent troubleshooting and analytical skills, with proven ability to think outside the box
  • Willingness to work outside of standard business hours, including weekends and holidays – our MDR service is 24x7x365
  • Innovative mindset and driven to contribute to a team providing a best-in-class cybersecurity service
  • Customer service-oriented with strong written and verbal communication skills
  • Experience with OSQuery
  • Programming and scripting skills - proficient knowledge of Powershell
  • Basic understanding of Windows event log analysis
  • Knowledge of incident response procedures
  • Experience with enterprise information security data management - SIEM experience
  • Must thrive within a team environment as well as on an individual basis
  • Natural curiosity and ability to learn new skills quickly
  • Experience with threat hunting
  • Knowledge of common adversary tactics and techniques, e.g., obfuscation, persistence, defense evasion, etc
  • Experience administering and supporting Windows OS (both workstations and server) and one of the following: Apple or Linux-based operating systems (e.g., XP, Windows 7, 2003, 2008, OS X)
  • Experience with endpoint and network security monitoring
  • Basic understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc

Research shows that candidates sometimes hesitate to apply if they don’t check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don’t let a checklist hold you back – we encourage you to apply

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Analyst
Senior Threat Analyst

Sophos • Canada

On-site
CAD 86,000 - 143,000
Remote-first culture
Flexible work options
Remote Senior Incident Response Consultant 2
Remote Senior Incident Response Consultant 2

Bilinguallink • New Westminster

Remote
CAD 131,000 - 219,000
Remote-first policy
Remote Senior Threat Researcher Behavioral Protection
Remote Senior Threat Researcher Behavioral Protection

Bilinguallink • Sault Ste. Marie

Remote
CAD 129,000 - 215,000
Remote Manager, Cyber Risk Advisor - Managed Risk
Remote Manager, Cyber Risk Advisor - Managed Risk

Bilinguallink • Niagara Falls

Remote
CAD 110,000 - 183,000
Bonus eligibility
Comprehensive benefits package
Product Manager 2 - SecOps
Product Manager 2 - SecOps

Sophos • Canada

On-site
CAD 110,000 - 184,000
Remote-first working model
Employee-led diversity networks
Annual charity initiatives
+4
Remote Compliance Enablement Technical Program Manager
Remote Compliance Enablement Technical Program Manager

Bilinguallink • Calgary

Remote
CAD 90,000 - 150,000
Remote-first work model
Wellbeing programs
Volunteer days
Security Operations Analyst
Security Operations Analyst

F12.net • Surrey

On-site
CAD 70,000 - 100,000
Cybersecurity Analyst - Tier 2
Cybersecurity Analyst - Tier 2

Vanderlande • Vancouver

On-site
CAD 90,000 - 130,000
Senior MDR Analyst
Senior MDR Analyst

Blackpoint Cyber • Canada

On-site
CAD 80,000 - 110,000
Remote Senior Cybersecurity Analyst - Threat Detection
Remote Senior Cybersecurity Analyst - Threat Detection

Placements24 • Kimberley

Hybrid
CAD 90,000 - 130,000
Remote work flexibility
Continuous learning in cybersecurity
Competitive compensation package
+1