Manager, Incident Response
Sophos
Full Time7+ yearsPosted 23 days ago
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
7+ years
Job Description
Role Summary
Sophos is seeking an experienced and motivated Incident Response Manager to lead the Critical Incident Response Team (CIRT) supporting its Managed Detection and Response (MDR) customers. The successful candidate will be responsible for the people leadership and operational management of the CIRT, ensuring consistent, high-quality execution across active cyber security incidents and customer engagements.
What you will do
- Lead and develop squads of analysts across CIRT; set clear expectations, provide coaching and feedback, support career development, and build an inclusive, high-performing team culture.
- Own day-to-day CIRT operations across multiple squads, ensuring appropriate staffing, coverage, workload balancing, prioritization, and service-level performance for concurrent customer engagements.
- Provide senior technical leadership and act as Incident Commander for complex or high-severity engagements, coordinating investigation, containment, eradication, recovery, and customer communications through to resolution.
- Establish and maintain operational and investigative quality standards, ensuring teams follow approved processes and playbooks and that engagement documentation, case reviews, and post-incident actions are complete and accurate.
- Use engagement, quality, response-time, capacity, and customer-outcome metrics to identify trends, manage performance, inform resource planning, and drive measurable improvements across the function.
- Build operational readiness by maintaining skills coverage, onboarding and training plans, incident exercises, tooling needs, and playbook updates for a fast-changing threat landscape.
- Serve as a senior escalation point for customer concerns, material findings, delivery risks, and resource conflicts, translating complex technical issues into clear updates and actionable decisions for technical and executive stakeholders.
- Partner cross-functionally with Threat Intelligence, the Security Operations Center, Detection Engineering, Product, and other teams to close detection and response gaps and strengthen MDR’s overall response capability.
- Drive continuous improvement and standardization by turning incident lessons, analyst feedback, and operational data into improved workflows, automation opportunities, training, and service enhancements.
Required Skills
Cybersecurity OperationsIncident ResponseDigital ForensicsPeople LeadershipTechnical Background In Endpoint Network And Cloud SecurityCommunication SkillsTroubleshooting And Analytical SkillsSiemEdrThreat IntelligenceOs QuerySqlPowershellKqlCy Lr