Security Engineer (Threat Response), Sophos Security Team (IDR)
New
S
SophosCybersecurity
Based in CanadaFull-TimeSenior
SalaryBase salary ranging from $86,000 to $143,000 CAD. Additional compensation, including bonus eligibility.
Apply NowOpens the employer's application page
Job Details
- Required Skills
- PythonSQLGitRESTful APIsGitHub
Requirements
- Bring strong enterprise incident response experience across endpoint, identity, cloud, network, and product-focused investigations.
- Have practical experience with DFIR, endpoint and firewall forensics, threat hunting, and detection engineering.
- Be able to analyze unstructured telemetry.
- Develop reliable automation using Python or a comparable programming language.
- Have experience working with APIs and querying data using SQL.
- Have working knowledge of Git and GitHub practices, including pull requests, code reviews, testing, and CI/CD concepts.
- Have hands-on familiarity with Claude, Codex, Copilot, or comparable coding-agent technologies.
- Understand context design, task decomposition, and validation of AI-generated output.
- Be able to design evaluations for agentic workflows and reusable skills, covering task success, quality, safety, regressions, and failure modes.
- Understand agent architecture, tool usage, skill-based design, model portability, and AI or automation safety controls.
- Be able to design observability for automated workflows and use telemetry to troubleshoot, measure quality, and improve reliability.
- Apply sound operational security judgment when handling security-sensitive activities.
Responsibilities
- Lead complex investigations through triage, evidence collection, containment, recovery, and lessons learned.
- Coordinate incident response across incident detection and response, engineering, product, and business teams.
- Conduct DFIR and endpoint forensics, including log, network, packet, malware, and firewall analysis.
- Develop detections, playbooks, orchestrations, and prevention mechanisms using incident and threat-hunting evidence.
- Build production-quality automation to reduce repetitive work and improve consistency.
- Design reusable, model-agnostic skills and workflows for approved AI and agent platforms.
- Use AI-assisted tools for coding, testing, documentation, investigations, and detection engineering.
- Contribute to GitHub workflows, including branching, pull requests, code reviews, testing, and controlled deployments.
- Instrument agentic workflows with logs, traces, metrics, evaluations, and failure signals.
- Apply least privilege, scoped tool access, approval gates, evidence validation, rollback mechanisms, and human review.
View Full Description & ApplyYou'll be redirected to the employer's site