Senior Incident Response Engineer
See all open roles at cyberoam →
Likely real
- 121 open roles at this company in 30 days (mass-hiring blitz)
- no salary disclosed (correlates with ghost postings)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
What you will do
Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat
Provide guidance to customers on best practices following an incident
Lead daily update calls for customers to deliver forensic findings
Deliver concise email updates to customers between update calls
Direct the forensic investigations, identify priorities, and delegate tasks to analysts
Conduct multiple Rapid Response incidents concurrently
Determine TTPs identified by analysts and add them to the threat intel platform
Write clear and concise Executive Summary style reports in a timely manner
Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service
Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead
This role will involve working from Friday to Tuesday (Wednesday & Thursday would be off).
It will involve working in fixed Morning Shift (6am to 3pm IST).
What you will bring
5+ years of experience leading incident response investigations involving ransomware
Experience leading BEC investigations
Continuously learning and staying informed of the changing threat landscape
Proven track record of successful neutralization and remediation of ransomware threats
Excellent understanding of the Incident Response process
Excellent understanding of cyber risks and able to qualify them to customers
Excellent oral communication skills
Strong written communication skills
Ability to manage time effectively
Able to delegate and prioritize tasks across multiple incidents
Able to excel under stressful circumstances
Occasionally willing to begin work early and/or stay late when warranted for customer engagements
Strong grasp of the MITRE ATT&CK framework
Enjoy mentoring and assisting in the development of junior analysts
A team-player attitude with a willingness to share knowledge
Ability to work on weekends and holidays
Post-secondary education in Cybersecurity, comparable
Desirable
Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar)
Experience with SIEM technology (e.g. Splunk, ELK, etc.)
Willingness to work occasional overtime during peak times or holidays
Experience writing SQL queries
Experience writing PowerShell, Python, or Bash scripts
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot