
Sophos · Australia
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organization...
About Us
Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.
Role Summary
As an MDR Threat Analyst, you will work with enterprise systems, log analysis systems, and endpoint collection systems to facilitate the investigation, identification and neutralization of cyber threats. You will work alongside and contribute to a team of analysts with the objective of providing best in class monitoring, detection and response services.
This role offers an opportunity to grow investigative expertise, work closely with senior analysts, and participate in real-world threat response while helping strengthen the organization’s overall security posture.
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase. You'll join the Insider Threat team within Coinbase's Security Operations organization as an Insider Threat Analyst. This team protects billions of dollars in digital assets and the trust of millions of customers by detecting, investigating, and mitigating threats from inside the organization. You'll serve as the front line for insider threat detection, triaging alerts, conducting investigations, and partnering cross-functionally with Security, Legal, HR, and business teams to safeguard Coinbase as it scales globally. What you'll do: * Execute alert triage, correlation, and analysis across insider threat detection systems (SIEM, UBA, DLP, endpoint detection), prioritizing findings and escalating recommendations for investigation and mitigation. * Support investigations end to end, from initial triage and evidence collection through employee interviews and stakeholder coordination, delivering clear documentation of findings, risk assessment, and recommended next steps. * Partner with Security, Legal, HR, and business teams to design and execute processes that identify and mitigate insider risks, including abuse and misuse across company systems. * Build case documentation and investigative reports that translate complex technical findings into concise, decision-ready briefs and assessments for leadership and cross-functional stakeholders. * Drive improvements to insider threat detection by identifying recurring control gaps, refining alerting logic, and recommending scalable solutions that reduce insider risk across the organization. Required Skills and Experience: * 2+ years of experience in insider threat, security operations, investigations, fraud detection, or a closely related discipline, with hands-on use of insider threat technologies (SIEM, UBA, DLP, endpoint detection) and log analysis. * Demonstrated experience conducting or supporting investigations involving sensitive employee matters, including evidence collection, interviewing techniques, and stakeholder coordination. * Proven ability to translate complex security problems into clear, actionable recommendations, including composing investigative briefs and assessments consumed by leadership. * Working knowledge of the insider threat landscape, including legal, regulatory, and ethical considerations of handling sensitive information, and experience with customer service tools or financial analysis. * Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality. Position ID: P77055 #LI-Remote Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)). Annual base salary range (excluding equity and bonus): $135,320—$159,200 USD * Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period. * Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws. * US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation. * Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial. * Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase. You'll join the Insider Threat team within Coinbase's Security Operations organization as a Senior Insider Threat Analyst, helping protect billions of dollars in digital assets and the trust of millions of customers. This team detects, investigates, and mitigates threats from inside the organization using a blend of tooling, automation, and strategic expertise. You'll own complex investigations end to end, shape detection and response processes, and partner cross-functionally with Security, Legal, HR, and business teams to mature Coinbase's insider threat program as it scales globally. What you'll do: * Own complex insider threat investigations end to end, from triage and evidence collection through employee interviews and stakeholder coordination, delivering clear findings, risk assessments, and actionable recommendations to leadership. * Lead detection and analysis efforts by prioritizing alert reviews across insider threat technologies (SIEM, UBA, DLP, endpoint detection), correlating signals, and identifying patterns that inform broader mitigation strategies. * Partner cross-functionally with Security, Legal, HR, and business teams to design, implement, and refine processes that systematically reduce insider risk and close recurring control gaps at scale. * Shape the team's investigative and analytical capabilities by refining alerting logic, developing scalable detection improvements, and mentoring junior analysts on tradecraft, evidence handling, and stakeholder communication. * Strengthen reporting and stakeholder communication by composing decision-ready briefs and assessments for senior leadership, translating complex investigative findings into concise narratives with clear risk context and recommended next steps. Required Skills and Experience: * 5+ years of experience in insider threat, security investigations, counterintelligence, fraud detection, or a closely related discipline, with deep hands-on expertise in insider threat technologies (SIEM, UBA, DLP, endpoint detection) and log analysis. * Track record of independently leading complex, sensitive investigations involving employee matters, including evidence collection, interviewing techniques, and coordination across Legal, HR, and business stakeholders. * Demonstrated ability to identify systemic control gaps and drive scaled improvements to insider threat detection and response processes, including refining alerting logic and recommending automation opportunities. * Proven experience composing investigative briefs, risk assessments, and analytical products consumed by senior leadership, with the ability to translate complex technical and behavioral findings into concise, decision-ready narratives. * Working knowledge of the legal, regulatory, and ethical frameworks governing insider threat programs, with experience applying sound judgment when handling highly sensitive and confidential information. * Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality. Position ID: P77056 #LI-Remote Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)). Annual base salary range (excluding equity and bonus): $167,280—$196,800 USD * Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period. * Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws. * US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation. * Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial. * Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.