Incident Response Consultant 3

Sophos

United States

On-site

USD 120,000 - 200,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

A leading cybersecurity company is seeking an experienced Incident Response Consultant 3 to join their elite IR team. The role involves investigating and neutralizing cyber threats, conducting forensic analysis, and leading response efforts across various customer networks. This position offers a competitive salary and opportunities for continuous learning in a dynamic environment.

Qualifications

  • 3+ years of experience in Incident Response or related roles.
  • Strong understanding of Windows logs and forensic artifacts.
  • Familiarity with the MITRE ATT&CK framework.

Responsibilities

  • Perform in-depth forensic analysis of systems.
  • Investigate customer networks for suspicious activity.
  • Lead incident response efforts and document findings.

Skills

Incident Response
Forensic Analysis
Cybersecurity
Communication
Teamwork

Education

Post-secondary education in Cybersecurity or equivalent

Tools

Splunk
ELK
XDR
SQL
PowerShell
Python
Bash

Job description

Get AI-powered advice on this job and more exclusive features.

Sophos is seeking an experienced and motivated Incident Response Consultant 3 to join our Incident Response (IR) service. The Sophos IR team is an elite group of incident responders engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents.

As an Incident Response Consultant 3 on the Sophos IR team, you will collaborate with a dedicated group of experts to neutralize critical security incidents for customers of varying sizes and industries. You will be responsible for investigating at-scale across customer networks and conducting forensic analysis using industry-standard tools to identify indicators of compromise and tactics, techniques, and procedures used by threat actors. Reporting to the Team Lead, Incident Response, you will lead assigned incident response engagements, delegate tasks to other consultants, and document and communicate findings to our customers.

Role Summary

Sophos is seeking an experienced and motivated Incident Response Consultant 3 to join our Incident Response (IR) service. The IR team is an elite group of responders engaged worldwide to handle cyber threats, providing investigations, response, remediation, and root cause analysis using forensic tools and Sophos technologies.

In this role, you will work with a team of experts to handle critical security incidents, investigate networks, perform forensic analysis, and identify threat indicators. You will lead incident response efforts, delegate tasks, and ensure thorough documentation and communication of findings.

What You Will Do

  • Perform in-depth forensic analysis of systems
  • Acquire full disk and triage images of Windows, Mac, and Linux systems
  • Investigate customer networks for suspicious activity
  • Leverage tools such as XDR for large-scale threat hunts
  • Identify systems of interest related to investigations
  • Maintain detailed documentation of findings
  • Document IOCs and contribute to threat intelligence
  • Collect sample files from customer devices
  • Conduct OSINT searches
  • Log work hours accurately
  • Complete training and development programs as directed

What You Will Bring

  • 3+ years of experience in Incident Response or related roles
  • Strong understanding of Windows logs and forensic artifacts
  • Knowledge of hypervisors and virtualization
  • Experience in disk image acquisition
  • Familiarity with the MITRE ATT&CK framework
  • Experience with open-source forensic utilities
  • Passion for cybersecurity and digital forensics
  • Desire for continuous learning
  • Strong communication skills
  • Team-player attitude
  • Willingness to work weekends and holidays
  • Experience leading BEC investigations
  • Post-secondary education in Cybersecurity or equivalent
  • Certifications like CompTIA CySA+, GCFE, GCIH are a plus
  • Experience with SIEM tools like Splunk, ELK is a plus
  • Ability to write SQL queries and scripts (PowerShell, Python, Bash) is a plus

In the U.S., the salary ranges from $120,000 to $200,000, with additional bonuses and benefits. Compensation depends on skills, experience, location, and certifications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Engineer
Senior Incident Response Engineer

Sophos • United States

On-site
USD 150,000 - 190,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000
Senior Incident Response Lead
Senior Incident Response Lead

Sophos • United States

On-site
USD 150,000 - 190,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000
Incident Response Lead
Incident Response Lead

ECS Corporate Services • Washington

Hybrid
USD 140,000 - 150,000