Responsibilities
- As a Threat Analyst - Tier II on our Managed Detection and Response (MDR) team, you will provide best-in-class monitoring, detection, and response services to proactively defend customer environments before attacks prevail
- You will work alongside and contribute to a team of cyber threat hunters, incident response analysts, engineers, and ethical hackers by using enterprise, log analysis and endpoint collection systems to facilitate investigations, identification, and neutralization of cyber threats
- Investigate and analyze logs and security-related events via Sophos tooling
- Handle escalations from Tier I Threat Analysts - guide / advise on investigation handling
- Onboard and train new Threat Analysts
- Create cases, track and follow up with clients through threat neutralization
- Communicate and document findings to various customer audiences including technical and executive teams
- Follow up with customers through to issue resolution and drive continuous improvement by providing detailed recommendations to minimize risk in customer environments
- Acknowledge and satisfy inbound customer requests and interact with customers through various mediums (Email, Phone, Ticket)
- Collaborate and assist with core security and threat response teams
- Actively research emerging Indicators of Compromise/Attack, exploits and vulnerabilities
- Conduct threat hunting to identify potential threats throughout the MDR customer base
- Participate in Security Operations process improvement and creation
- Obtain metrics for reporting on threat trends, intelligence analysis and situational awareness
Qualifications
- Must thrive within a team environment as well as on an individual basis
- Administrate and support Windows OS (workstations and server) and one of the following: Apple or Linux-based operating systems (RedHat, Debian, Ubuntu, OS X)
- 2+ years of experience working in a SOC environment or computer security team in an IT environment
- Passion for all things related to information technology and cybersecurity
- Innovative mindset and driven to contribute to a team providing a best-in-class cybersecurity service
- Willingness to work outside of standard business days including weekends and holidays β our MDR service is 24x7x365 (Hours are standard business hours)
- Knowledge of common adversary tactics and techniques, e.g., obfuscation, persistence, defense evasion, etc
- Experience with threat hunting
- Working knowledge of incident response procedures
- Endpoint and network security experience required; IDS, IPS, EDR, ATP, Malware defenses and monitoring experience
- Bachelors in Information Technology, Computer Science or a related field; or relevant commensurate work experience
- Natural curiosity and ability to learn new skills quickly
- Excellent troubleshooting and analytical skills, with proven ability to think outside the box
- Customer service-oriented with strong written and verbal communication skills
- Fundamental understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc
- Strong understanding of Windows event log analysis
- Experience with enterprise information security data management - SIEM
- Experience with OSQuery programming and scripting skills - proficient knowledge of PowerShell
- Advanced Cyber Security certifications
- Experience with SQL query construction
- Knowledge of MITRE ATT&CK framework
Benefits
- We encourage teams to get together in person periodically to help facilitate teamwork
- Remote-first working model & hybrid options
- Flexible start and end times for many roles
- Leadership development program
- Access to LinkedIn Learning
- Global internal coaching program (Coach Match)
- Periodic Sophos wellness days off for all Sophos to help employees relax and recharge
- Global wellbeing program, which offers a range of wellbeing resources, including Sophos Wellbeing Webinars, Stress Management Toolkits, and Developing Resilience Courses
- Free Employee Assistance Program (EAP) for confidential advice and counseling on a wide range of work and personal issues
- Free annual subscription to the Calm app
- Paid parental leave, caregiver leave & bereavement/compassion leave available
- We host some unforgettable social experiences for our global teams including our music festival SOPH-Fest, go-karting, Sophmudder, and incredible holiday parties!
- Our annual global fitness challenge, SOPH-Fit, sees thousands of employees taking part in our virtual global race around the world
- Each quarter, we celebrate our exceptional global team by running the Sophos Values Awards, which recognizes and rewards employees who embody the Sophos values and who we are as a company
- Health care benefits available worldwide