Incident Response Analyst 2: MDR & Forensic Investigator

Sophos

United States

Remote

USD 85,000 - 120,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Remote-first
Flexible schedule

Job summary

Sophos is seeking an intermediate-level Incident Response Analyst to support its MDR customers within the Critical Incident Response Team (CIRT). The role involves advanced investigative and containment activities, operating with moderate autonomy, and mentoring junior analysts to ensure quality and consistency.

We operate a remote-first model; some roles may require a hybrid approach. Applicants must have legal authorization to work in the posting jurisdiction without sponsorship.

Qualifications

  • 2+ years in incident response, MDR, SOC, or security operations roles.
  • Strong knowledge of endpoint forensics, log analysis, and attack techniques.
  • Experience investigating malware, credential theft, ransomware, or similar threats.

Responsibilities

  • Perform advanced investigative and forensic analysis across endpoints, network logs, and cloud telemetry.
  • Execute containment and response actions to neutralize active threats as directed by senior staff.
  • Validate indicators of compromise (IOCs) and determine scope and root cause.

Skills

2+ years IR
Endpoint forensics
Malware analysis
Incident scope & root cause
Documentation & reporting

Education

GCIH / GCED / Security+
Bachelor's in CS/IS or equivalent

Tools

EDR
SIEM
Forensic tools
OSQuery
SQL / KQL

Job description

Sophos is seeking an intermediate-level Incident Response Analyst to support its MDR customers within the Critical Incident Response Team (CIRT). The role involves advanced investigative and containment activities, operating with moderate autonomy, and mentoring junior analysts to ensure quality and consistency.

We operate a remote-first model; some roles may require a hybrid approach. Applicants must have legal authorization to work in the posting jurisdiction without sponsorship.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Analyst II - MDR Cyber Defense Expert
Threat Analyst II - MDR Cyber Defense Expert

sophos • United States

Remote
USD 110,000 - 140,000
Remote-first
Senior MDR Threat Analyst – Detection & Response
Senior MDR Threat Analyst – Detection & Response

Sophos • United States

On-site
USD 70,000 - 100,000
Incident Response Engineer 2
Incident Response Engineer 2

Sophos • United States

Remote
USD 85,000 - 120,000
Remote-first
Flexible schedule
Senior Threat Analyst & MDR Team Lead
Senior Threat Analyst & MDR Team Lead

Sophos • United States

Remote
USD 120,000 - 170,000
Threat Analyst I — 24/7 Remote MDR Defender
Threat Analyst I — 24/7 Remote MDR Defender

Sophos • United States

Remote
USD 70,000 - 110,000
Remote-first
Senior Threat Analyst — MDR Leader & Threat Hunter
Senior Threat Analyst — MDR Leader & Threat Hunter

Sophos • United States

Remote
USD 61,000 - 101,000
Remote‑first working model
Diversity and inclusion networks
Volunteer days and community programs
+1
CSIRT Analyst - MDR, DFIR & Threat Hunting
CSIRT Analyst - MDR, DFIR & Threat Hunting

Computer Task • Buffalo (NY)

On-site
USD 80,000 - 120,000
MDR Incident Response Engineer — SOC Analyst
MDR Incident Response Engineer — SOC Analyst

Infinite Computer Solutions • Campus (IL)

On-site
USD 95,000 - 130,000
Remote SOC Analyst: MDR/XDR Threat Defender
Remote SOC Analyst: MDR/XDR Threat Defender

viLogics • Ebensburg

Remote
USD 70,000 - 90,000
MDR Analyst: Incident Response & AI-Driven Triage
MDR Analyst: Incident Response & AI-Driven Triage

Acronis • United States

Remote
USD 85,000 - 120,000