Remote Incident Responder II — MDR & Forensics Expert

Lever, Inc.

Oxford

Hybrid

GBP 60,000 - 90,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote-first working model

Job summary

Sophos is seeking an intermediate-level Incident Response Analyst to support its MDR customers within the Critical Incident Response Team. You will perform advanced investigative, forensic, and containment activities during active cyber incidents, mentoring junior analysts and producing customer-facing findings.

You will operate with moderate autonomy, serve as the technical backbone of engagements, and contribute to post-incident reviews while maintaining thorough documentation and timelines.

Qualifications

  • 2+ years of incident response, MDR, SOC, or security operations experience.
  • Solid understanding of endpoint forensics and log analysis.
  • Experience investigating malware, credential theft, ransomware, or similar threats.
  • Ability to correlate alerts and telemetry to determine incident scope and root cause.
  • Strong written and verbal communication for documenting findings and updates.
  • Experience mentoring or guiding junior analysts.
  • Ability to work in high-pressure, time-sensitive incident environments.
  • Willingness to work some weekends and holidays as part of a rotation.

Responsibilities

  • Perform advanced investigative and forensic analysis across endpoints, network logs, and cloud telemetry.
  • Execute containment and response actions to neutralize active threats as directed by senior staff.
  • Validate IOCs and correlate alerts to determine scope and root cause.
  • Maintain engagement documentation, timelines, and playbooks.
  • Mentor junior IR and SOC analysts to ensure quality and consistency.
  • Prepare technical findings for customer updates and post-incident reports.
  • Identify detection or response gaps observed during investigations.
  • Participate in shift handovers, debriefs, and post-incident reviews.

Skills

Incident response
MDR/SOC
Security operations
Endpoint forensics
Log analysis
Attack techniques
Malware investigation
Credential theft
Ransomware
Communication
Mentoring
High-pressure environments

Tools

EDR
SIEM
Forensic tools
OSQuery
SQL
KQL

Job description

Sophos is seeking an intermediate-level Incident Response Analyst to support its MDR customers within the Critical Incident Response Team. You will perform advanced investigative, forensic, and containment activities during active cyber incidents, mentoring junior analysts and producing customer-facing findings.

You will operate with moderate autonomy, serve as the technical backbone of engagements, and contribute to post-incident reviews while maintaining thorough documentation and timelines.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

MDR Threat Analyst I: Threat Detection & Response
MDR Threat Analyst I: Threat Detection & Response

Sophos Group • Oxford

Remote
GBP 42,000 - 65,000
Remote Threat Analyst II - MDR Security Operations
Remote Threat Analyst II - MDR Security Operations

Lever, Inc. • Oxford

Hybrid
GBP 45,000 - 65,000
Incident Response Engineer 2
Incident Response Engineer 2

Lever, Inc. • Oxford

On-site
GBP 60,000 - 90,000
Remote-first working model
Senior Incident Response Consultant 2
Senior Incident Response Consultant 2

Sophos • Oxford

On-site
CAD 131,000 - 219,000
Senior Incident Response Lead - Remote Rapid Response
Senior Incident Response Lead - Remote Rapid Response

Sophos • United Kingdom

On-site
GBP 90,000 - 120,000
Senior Threat Analyst – Remote MDR Leader
Senior Threat Analyst – Remote MDR Leader

Sophos • Oxford

Hybrid
CAD 86,000 - 143,000
Remote-first culture
Flexible work options
Senior Incident Response Lead — Rapid Response (Ransomware)
Senior Incident Response Lead — Rapid Response (Ransomware)

Sophos Group • Oxford

Hybrid
GBP 90,000 - 125,000
Threat Analyst 2
Threat Analyst 2

Lever, Inc. • Oxford

On-site
GBP 45,000 - 65,000
Remote Intrusion Analyst: Threat Hunting & Detection
Remote Intrusion Analyst: Threat Hunting & Detection

Berenice Photography • United Kingdom

Remote
GBP 58,000 - 90,000
Senior Incident Response Consultant, Rapid Response
Senior Incident Response Consultant, Rapid Response

Sophos Group • Oxford

On-site
GBP 90,000 - 125,000