Security Engineer (Threat Response), Sophos Security Team (IDR)

New
S
SophosCybersecurity
Based in CanadaFull-TimeSenior
SalaryBase salary ranging from $86,000 to $143,000 CAD. Additional compensation, including bonus eligibility.
Apply NowOpens the employer's application page

Job Details

Required Skills
PythonSQLGitRESTful APIsGitHub

Requirements

  • Bring strong enterprise incident response experience across endpoint, identity, cloud, network, and product-focused investigations.
  • Have practical experience with DFIR, endpoint and firewall forensics, threat hunting, and detection engineering.
  • Be able to analyze unstructured telemetry.
  • Develop reliable automation using Python or a comparable programming language.
  • Have experience working with APIs and querying data using SQL.
  • Have working knowledge of Git and GitHub practices, including pull requests, code reviews, testing, and CI/CD concepts.
  • Have hands-on familiarity with Claude, Codex, Copilot, or comparable coding-agent technologies.
  • Understand context design, task decomposition, and validation of AI-generated output.
  • Be able to design evaluations for agentic workflows and reusable skills, covering task success, quality, safety, regressions, and failure modes.
  • Understand agent architecture, tool usage, skill-based design, model portability, and AI or automation safety controls.
  • Be able to design observability for automated workflows and use telemetry to troubleshoot, measure quality, and improve reliability.
  • Apply sound operational security judgment when handling security-sensitive activities.

Responsibilities

  • Lead complex investigations through triage, evidence collection, containment, recovery, and lessons learned.
  • Coordinate incident response across incident detection and response, engineering, product, and business teams.
  • Conduct DFIR and endpoint forensics, including log, network, packet, malware, and firewall analysis.
  • Develop detections, playbooks, orchestrations, and prevention mechanisms using incident and threat-hunting evidence.
  • Build production-quality automation to reduce repetitive work and improve consistency.
  • Design reusable, model-agnostic skills and workflows for approved AI and agent platforms.
  • Use AI-assisted tools for coding, testing, documentation, investigations, and detection engineering.
  • Contribute to GitHub workflows, including branching, pull requests, code reviews, testing, and controlled deployments.
  • Instrument agentic workflows with logs, traces, metrics, evaluations, and failure signals.
  • Apply least privilege, scoped tool access, approval gates, evidence validation, rollback mechanisms, and human review.
View Full Description & ApplyYou'll be redirected to the employer's site
Base salary ranging from $86,000 to $143,000 CAD. Additional compensation, including bonus eligibility.
Apply Now