Threat Analyst 1 in Oxford

Threat Analyst 1 in Oxford

Oxford Full-Time 28800 - 43200 ÂŁ / year (est.) Home office possible
Go Premium
Sophos Group

At a Glance

  • Tasks: Monitor and respond to cyber threats, ensuring customer environments stay secure.
  • Company: Join Sophos, a leader in cybersecurity innovation and protection.
  • Benefits: Remote-first work model, diverse culture, and wellness initiatives.
  • Why this job: Make a real impact in the fight against cybercrime with cutting-edge technology.
  • Qualifications: 1+ years in cybersecurity, familiarity with security tools, and a passion for learning.
  • Other info: Dynamic team environment with opportunities for growth and development.

The predicted salary is between 28800 - 43200 ÂŁ per year.

About Us

Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure‑play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. In addition to MDR and other services, Sophos’ complete portfolio includes industry‑leading endpoint, network, email, and cloud security that interoperate and adapt to defend through the Sophos Central platform. Secureworks provides the innovative, market‑leading Taegis XDR/MDR, identity threat detection and response (ITDR), next‑gen SIEM capabilities, managed risk, and a comprehensive set of advisory services. Sophos sells all these solutions through reseller partners, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) worldwide, defending more than 600,000 organizations worldwide from phishing, ransomware, data theft, other everyday and state‑sponsored cybercrimes. The solutions are powered by historical and real‑time threat intelligence from Sophos X‑Ops and the newly added Counter Threat Unit (CTU). Sophos is headquartered in Oxford, U.K.

Role Summary

As a Threat Analyst - Tier I on our Managed Detection and Response (MDR) team, you will provide best‑in‑class monitoring, detection, and response services to proactively defend customer environments before attacks prevail. You will work alongside and contribute to a team of cyber threat hunters, incident response analysts, engineers, and ethical hackers by using enterprise log analysis and endpoint collection systems to facilitate investigations, identification, and neutralization of cyber threats.

What You Will Do

  • Monitor, investigate, and respond to alerts generated by the Sophos security stack (including EDR/XDR capabilities)
  • Perform end‑to‑end analysis on suspicious activity to assess scope, impact, and risk
  • Identify and respond to cyber threats across customer environments using approved playbooks and tooling
  • Accurately document findings, investigative steps, and outcomes in the MDR case management platform
  • Conduct threat hunting to identify potential threats throughout the MDR customer base
  • Investigate phishing emails, suspicious binaries, and behavioral anomalies
  • Support detection tuning by identifying recurring false positives and suggesting improvements
  • Stay informed on threat actor behaviors, MITRE ATT&CK techniques, and Sophos threat research updates
  • Proactively research emerging IOCs, active exploits, and vulnerabilities to stay ahead of evolving threats
  • Contribute to internal knowledge bases, documentation, and continuous improvement initiatives
  • Participate in shift rotations and ensure timely, detailed handovers between global teams
  • Provide detection and response support for active security incidents
  • Manage case workflows: create cases, track progress, and follow up with clients until resolution
  • Engage with clients via email, phone, and tickets as part of case handling
  • Assist with developing and refining Security Operations processes, playbooks, and tooling feedback

What You Will Bring

  • 1+ years of experience working in a Security Operations Center (SOC) or cybersecurity‑focused IT role
  • Familiarity with endpoint and network security tools, including EDR, IDS/IPS, and malware prevention/monitoring solutions
  • Working knowledge of Windows operating systems (both workstation and server), with additional experience in Linux (Ubuntu, Debian, RedHat) or macOS environments
  • Ability to interpret and analyze Windows event logs and other telemetry data
  • Understanding of core network concepts including TCP/IP, protocols, routing, and traffic analysis
  • Practical experience investigating alerts and performing basic response actions in a real‑time environment
  • Exposure to threat hunting methodologies and an understanding of attacker behavior and patterns
  • Exposure to incidents involving active threats and taking active response measures to contain the threat
  • Foundational understanding of adversary tactics and techniques (e.g., persistence, privilege escalation, lateral movement, obfuscation), especially as defined in frameworks like MITRE ATT&CK
  • Familiarity with common incident response workflows and security operations processes
  • Strong analytical thinking and troubleshooting skills, with attention to detail in investigations and case documentation
  • Excellent communication skills, with the ability to clearly explain findings to both technical and non‑technical audiences
  • Customer‑first mindset with professionalism and a focus on service excellence
  • Must thrive within a team environment as well as on an individual basis
  • Natural curiosity and willingness to learn in a fast‑paced, ever‑changing threat landscape
  • A passion for cybersecurity, continuous improvement, and staying current on threat trends
  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity or related field, or equivalent practical experience
  • Willingness to work from 0630 to 1500 JST, with the flexibility to adjust to business requirements
  • Willingness to participate in rotating weekend and holiday coverage (our MDR service is 24x7x365)

Desirable

  • Familiarity with the MITRE ATT&CK framework and its application in detection and response
  • Experience working with SIEM platforms and managing enterprise security telemetry
  • Ability to write and interpret SQL queries for data analysis and investigation
  • Experience with OSQuery and scripting skills, particularly in PowerShell
  • Relevant and practical cybersecurity certifications (e.g., GSEC, GCIA, GCIH, PEN‑200, Security Blue Team L1, TCM Academy SOC L1, or similar)

Ready to Join Us?

At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back – we encourage you to apply.

What’s Great About Sophos?

  • Sophos operates a remote‑first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship.
  • Our people – we innovate and create, all of which are accompanied by a great sense of fun and team spirit
  • Employee‑led diversity and inclusion networks that build community and provide education and advocacy
  • Annual charity and fundraising initiatives and volunteer days for employees to support local communities
  • Global employee sustainability initiatives to reduce our environmental footprint
  • Global fitness and trivia competitions to keep our bodies and minds sharp
  • Global wellbeing days for employees to relax and recharge
  • Monthly wellbeing webinars and training to support employee health and wellbeing

Our Commitment To You

We’re proud of the diverse and inclusive environment we have at Sophos, and we’re committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know.

Data Protection

If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos’ data protection practices, please consult our Privacy Policy.

Threat Analyst 1 in Oxford employer: Sophos Group

At Sophos, we pride ourselves on being a remote-first employer that fosters a vibrant and inclusive work culture, where innovation thrives alongside a strong sense of community. Our commitment to employee wellbeing is evident through initiatives like global fitness competitions, wellbeing days, and diverse employee-led networks, all designed to support personal and professional growth. Join us in Oxford, U.K., where your unique skills will contribute to our mission of defending against cyber threats while enjoying a collaborative and supportive environment.
Sophos Group

Contact Detail:

Sophos Group Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Threat Analyst 1 in Oxford

✨Tip Number 1

Network, network, network! Reach out to folks in the cybersecurity field, especially those at Sophos. Attend industry events or webinars and don’t be shy about introducing yourself. You never know who might have a lead on your dream job!

✨Tip Number 2

Get your hands dirty with practical experience. Whether it’s through internships, labs, or personal projects, show us you can handle real-world threats. The more you can demonstrate your skills, the better your chances of landing that Threat Analyst role.

✨Tip Number 3

Prepare for interviews by brushing up on your knowledge of the MITRE ATT&CK framework and common incident response workflows. We want to see that you’re not just familiar with the theory but can apply it in practice. Practice explaining your thought process clearly!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows us you’re genuinely interested in joining the Sophos team. So, what are you waiting for? Get that application in!

We think you need these skills to ace Threat Analyst 1 in Oxford

Monitoring and Detection
Incident Response
Threat Hunting
Cyber Threat Analysis
EDR/XDR Capabilities
Windows and Linux Operating Systems
Network Security Tools
TCP/IP and Network Concepts
MITRE ATT&CK Framework
SQL Query Writing
Analytical Thinking
Attention to Detail
Communication Skills
Customer Service Orientation
Team Collaboration

Some tips for your application 🫡

Tailor Your CV: Make sure your CV reflects the skills and experiences that match the Threat Analyst role. Highlight any relevant experience in Security Operations or cybersecurity-focused IT roles, and don’t forget to mention your familiarity with tools like EDR and IDS/IPS.

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about cybersecurity and how your unique experiences can contribute to our team at Sophos. Keep it concise but engaging!

Showcase Your Analytical Skills: In your application, emphasise your analytical thinking and troubleshooting skills. Mention specific examples where you've successfully investigated alerts or responded to incidents, as this will resonate well with us.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!

How to prepare for a job interview at Sophos Group

✨Know Your Cybersecurity Basics

Make sure you brush up on your knowledge of core network concepts and the MITRE ATT&CK framework. Being able to discuss these topics confidently will show that you understand the fundamentals of threat analysis and can apply them in real-world scenarios.

✨Familiarise Yourself with Sophos Tools

Since you'll be working with the Sophos security stack, it’s a good idea to get acquainted with their EDR/XDR capabilities and other tools mentioned in the job description. This will not only help you answer technical questions but also demonstrate your proactive approach to learning.

✨Prepare for Scenario-Based Questions

Expect to face scenario-based questions where you might need to explain how you would handle specific cyber threats or incidents. Practising these types of questions can help you articulate your thought process and decision-making skills effectively.

✨Show Your Passion for Continuous Learning

Cybersecurity is always evolving, so express your enthusiasm for staying updated on the latest trends and threats. Mention any relevant courses, certifications, or personal projects that showcase your commitment to continuous improvement in this field.

Threat Analyst 1 in Oxford
Sophos Group
Location: Oxford
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>