hirly

Sophos

Senior Incident Response Consultant 2

Canada

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Sophos first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Senior
Country
CA
Work mode
Remote-friendly
First seen by hirly
11 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

About Us

Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.

Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.

Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com .

Role Summary

Sophos is seeking an experienced and motivated Senior Incident Response Consultant to join our Digital Forensics & Incident Response (IR) service. The Sophos DFIR team is an elite group of incident responders that are engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents.

As a Senior Incident Response Consultant on the Sophos DFIR team, you will be responsible for spearheading incident response engagements for customers who have experienced a cybersecurity attack. In this role, you will lead a team of Incident Response Consultants, running customer-facing calls, providing detailed written updates via email, and determining the priorities of the investigation, delegating tasks accordingly to your team. You will also be responsible for coordinating with legal counsel and cyber insurance carriers as needed.

In this role, you will be accountable for ensuring that the appropriate actions have been taken by both your team and the customer to effectively neutralize the threat. Additionally, you will be tasked with conducting a thorough root cause analysis to determine the origin of the incident, including identifying whether any data exfiltration occurred, provided the necessary evidence is available.

At the culmination of each engagement, you will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident and provide remediation guidance.

The ideal candidate will have superior experience in some of the example disciplines, computer, network, cloud, memory, and email forensics, incident response including the technical management of high-profile security incidents, threat hunting and analysis, web application security, penetration testing, leading red and / or blue teaming exercises, and open-source intelligence (OSINT). This role requires a logical, pragmatic, meticulous, analytical, and authoritative person who is highly skilled in managing technical teams and has an elite understanding of core advanced threat detection, forensic methodologies, and incident response best practices to effectively manage and mitigate the technical aspects of complex security incidents. This person leads the incident response, not just review and analyze data.

Original posting on Sophos's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job