Skip to content

Open nowPosted 19 hours ago

Security Engineer (Threat Response), Sophos Security Team (IDR)

Jobgether4,233 open roles

Where
Canada
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer (Threat Response), Sophos Security Team (IDR)Jobgether · Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 4 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 19 hours ago

Jobgether median: 4 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer (Threat Response), Sophos Security Team (IDR) based in Canada.

This is a senior security engineering role combining hands-on incident response with detection engineering, automation, and threat research. You will investigate complex cyber threats across endpoints, identity, cloud, networks, and security products while helping strengthen internal detection and response capabilities. The role goes beyond traditional incident response, with a strong focus on building scalable automations, reusable workflows, and agentic security tooling. You will use modern AI-assisted development tools while applying rigorous safety, observability, and validation practices. Collaboration spans security, engineering, product, and business teams in a globally coordinated environment. The position is remote-first and offers the opportunity to shape how advanced security operations evolve through engineering and responsible AI adoption.

Accountabilities:

  • Lead complex investigations throughout the incident lifecycle, from triage and evidence collection through containment, recovery, and lessons learned.
  • Act as a trusted point of contact for security issues, coordinating response across incident detection and response, engineering, product, and business teams.
  • Conduct DFIR and endpoint forensics, including log, network, and packet analysis, malware analysis, and firewall investigations where applicable.
  • Develop and improve detections, playbooks, orchestrations, and prevention mechanisms using evidence from incidents and threat-hunting activities.
  • Build production-quality automation that reduces repetitive work, improves consistency, and enables analysts to focus on higher-value activities.
  • Design reusable, model-agnostic skills and workflows that can operate across approved AI and agent platforms.
  • Use AI-assisted development and investigation tools to accelerate coding, testing, documentation, investigations, and detection engineering.
  • Contribute to GitHub-based engineering workflows, including branching, pull requests, code reviews, testing, feedback cycles, and controlled deployments.
  • Instrument agentic workflows with logs, traces, metrics, evaluation results, and failure signals to ensure behavior and outcomes remain observable.
  • Apply secure harness design, least-privilege principles, scoped tool access, approval gates, evidence validation, rollback mechanisms, and human review for consequential actions.
  • Communicate incidents, risks, technical decisions, and outcomes clearly to engineering teams and leadership.
  • Continuously improve security processes and engineering practices based on incident findings, threat intelligence, operational data, and lessons learned.
  • Strong enterprise incident response experience across endpoint, identity, cloud, network, and product-focused investigations.
  • Practical experience with DFIR, endpoint and firewall forensics, threat hunting, detection engineering, and analysis of unstructured telemetry.
  • Ability to develop reliable automation using Python or a comparable programming language.
  • Experience working with APIs and querying data using SQL.
  • Working knowledge of Git and GitHub engineering practices, including pull requests, code reviews, testing, and CI/CD concepts.
  • Hands-on familiarity with Claude, Codex, Copilot, or comparable coding-agent technologies.
  • Understanding of context design, task decomposition, and validation of AI-generated output.
  • Ability to design and write evaluations for agentic workflows and reusable skills, covering task success, output quality, safety, regressions, and common failure modes.
  • Understanding of agent architecture, tool usage, skill-based design, model portability, and AI or automation safety controls.
  • Ability to design observability for automated workflows and use telemetry to troubleshoot, measure quality, and improve reliability.
  • Strong written and verbal communication skills.
  • Sound operational security judgment and attention to safe handling of security-sensitive activities.
  • Ability to work effectively within a globally coordinated and distributed environment.
  • Legal authorization to work in Canada without requiring employer sponsorship.
  • Base salary ranging from $86,000 to $143,000 CAD.
  • Additional compensation, including bonus eligibility.
  • Comprehensive employee benefits package.
  • Remote-first working model, with remote work serving as the primary option for most employees.
  • Employee-led diversity and inclusion networks focused on community, education, and advocacy.
  • Annual charity, fundraising, and employee volunteer initiatives.
  • Global sustainability initiatives supporting efforts to reduce environmental impact.
  • Global fitness and trivia activities supporting employee connection and wellbeing.
  • Global wellbeing days designed to provide time to relax and recharge.
  • Monthly wellbeing webinars and training focused on employee health and wellbeing.
  • Inclusive environment that values diverse perspectives, collaboration, innovation, and continuous learning.
  • Opportunity to work at the intersection of incident response, threat intelligence, detection engineering, automation, and responsible AI adoption.
  • Recruitment and selection accommodations available to support candidates who require adjustments.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.