
Sophos · Japan
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organization...
About Us
Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.
Role Summary
インシデント対応および脅威インテリジェンスのリーダーは、日々高度化するセキュリティ脅威への対応において、お客様を支援します。インシデント発生時の対応を支援するだけでなく、効果的なインシデント対応に向けた事前準備も支援します。小規模なインシデントから複雑で大規模インシデントまで、技術的な調査を実施し、攻撃者の行動に基づいてインシデントの根本原因と範囲を特定し、推奨される対応戦略を提供することでお客様を支援します。
さらに、この役割はソフォスの脅威対策ユニット(CTU)との主要な連絡窓口として、調査結果に攻撃者の戦術、技術、インフラに関する最新のインテリジェンスを反映させます。また、運用上の知見を、お客様や社内チーム向けの実行可能なガイダンスに変換する役割も担います。
リーダーは技術レベルおよび経営層向けの質の高いプレゼンテーションやブリーフィングを行う責任も担います。これには、調査結果の提示、脅威インテリジェンスの動向の説明、多様な聴衆に対して対応策の推奨事項を明確に伝達し、情報に基づいた意思決定を支援することが含まれます。
Incident Response & Threat Intelligence Leads support clients in managing increasingly sophisticated security threats daily. They not only assist in responding to incidents as they occur but also help clients prepare in advance for effective incident response. Whether handling small‑scale or complex, large‑scale incidents, we assist clients by conducting technical investigations, identifying the root cause and scope of the incident based on attacker behavior, and providing recommended response strategies.
In addition, this role will act as a key liaison with the Sophos Counter Threat Unit, ensuring investigative findings are enriched with the latest intelligence on attacker tactics, techniques, and infrastructure. The role also translates operational intelligence into actionable guidance for clients and internal teams.
Leads are also responsible for delivering high‑quality presentations and briefings, both technical and executive‑level. This includes presenting investigation findings, explaining threat intelligence trends, and clearly communicating response recommendations to diverse audiences to support informed decision‑making.
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com. Role Overview ソフォスのインシデントレスポンスチームでは、アドバイザリーサービス事業を拡大するため、各チームやインシデントレスポンス/レディネスコンサルタントと連携するシニアマネージャーを募集しています。インシデントレスポンスシニアマネージャーは、アドバイザリーサービス事業内のIRマネジメントチーム、IRチームリーダー、インシデントレスポンダー、インシデントレディネスコンサルタントと協力し、コンサルティング業務全般を統括します。業務内容は、予防的な取り組み(能力構築や脅威ハンティングなど)から、事後対応としてのインシデント/侵害対応まで多岐にわたります。サービス提供の質向上やコンサルティングスキルに関するチームメンバーへの指導、および顧客と直接連携して課題や障害を解決することも、この役職の重要な役割です。候補者には、契約案件への従事(請求可能業務の割合は最低15%)が求められます。 採用候補者には、インシデント対応能力の開発、管理、運用、トレーニング、演習、ワークショップの実施経験が求められます。また、脅威アクターが一般的に使用する戦術、手法、手順に精通している必要があります。組織がインフラやデータのセキュリティを確保しようとする際に直面する要因や制約について熟知していることが不可欠です。オンコール(プライマリ/サポート)対応が求められます。 The Sophos Incident Response team is looking for a Senior Manager who will work with various Sophos teams and Incident Response\Readiness consultants to grow the Sophos Advisory Services practice. The Incident Response Senior Manager will work with the IR management team, IR team leads, incident responders, and incident readiness consultants within the Sophos Advisory Services practice to oversee all consulting matters. Deliverables may be proactive (e.g. capability building or threat hunting) or reactive incident/breach response. Mentoring team members on service delivery excellence and consulting skills, as well as working directly with customers to resolve any blockers/issues, is a key component of the role. The candidate will be expected to work on engagements with a minimum requirement of 15% billable work. The successful candidate will have experience in developing, managing, and operating incident response capabilities, conducting training, exercises, and workshops, and will be familiar with tactics, techniques, and procedures commonly employed by and used to thwart threat actors. Familiarity with the drivers and constraints that organizations are working with and against while trying to secure their infrastructure and data is a necessity. On call (primary / support) is required.
Who we are S-RM is a global intelligence and cyber security consultancy. Since 2005, we’ve helped some of the most demanding clients in the world solve some of their toughest information security challenges. We’ve been able to do this because of our outstanding people. We’re committed to developing sharp, curious, driven individuals who want to think critically, solve complex problems, and achieve success. But we also know that work isn’t everything. It’s about the lives and careers it helps us build. We’re immensely proud of this culture and we invest in our people’s wellbeing, learning, and ideas every day. We’re excited you’re thinking about joining us Working in Cyber at S-RM Our Cyber Security division is the fastest-growing part of S-RM. The cyber sector is always evolving, and our Incident Response and Managed Services practices are in more demand than ever. We’re building a team to meet this challenge. We’re quick to respond, innovate, and improve. We don’t get too hung up on hierarchy or bureaucracy. If your ideas are good enough, we’ll empower you to implement them. If you’re the best person to talk to a customer, you’ll get that opportunity, regardless of the title in your email signature. And when you need a hand, your team will always have your back. We also don’t believe there’s a typical cyber security professional. We’ve built a team of intelligence analysts, technical specialists, software developers, investigators, risk managers, and more. You’ll always find a range of perspectives and expertise to help you learn and grow. If that sounds like your kind of team, we’d like to hear from you. The role Cyber Threat Intelligence (CTI) is an integral part of S-RM's Managed Services practice. As a CTI Analyst, you will work closely with the Global Cyber Threat Intelligence Lead and Customer Success Managers to deliver high-value intelligence services to clients. Your core responsibilities will include: * Dark Web Monitoring: Use threat intelligence platforms and specialist tools to conduct targeted research across dark web sources, and set up and deliver regular monitoring engagements for clients. * Managed Threat Intelligence Services: Conduct targeted investigations using threat intelligence platforms, tools, and open-source intelligence across a growing portfolio of managed intelligence offerings. * CTI-lead analysis: Support in-depth investigations with a strong threat intelligence component, including conducting research and drafting client-facing reports. * Thought leadership: Contribute to public write-ups and presentations on emerging vulnerabilities, trends, and threat actor techniques. * Business development: Help cultivate relationships with external intelligence-sharing partners and identify opportunities to grow the practice. Beyond these core responsibilities, you will be expected to stay current with threat intelligence developments and collaborate closely with S-RM's Incident Response and Risk & Resilience teams where CTI adds value to their engagements. You will also work alongside the Managed Detection and Response (MDR) and Attack Surface Management (ASM) teams to ensure unified service delivery across all managed service offerings. This role offers the opportunity to shape the development of S-RM's CTI services — working with the practice lead, managed service teams, and technical development teams to identify opportunities for innovation and improvement. We will actively support your professional growth, including opportunities to develop and share domain expertise through internal initiatives. What we're looking for Candidates with the following qualifications and experience are likely to succeed as Cyber Threat Intelligence Analysts at S-RM. That said, if you don't think you meet all of the criteria below but are still interested in the role, please apply. Nobody checks every box — we're looking for candidates who are particularly strong in a few areas and have some interest and capability in others. We nurture a culture of equality, diversity, and inclusion, and are dedicated to developing a workforce that reflects a variety of talents, experiences, and perspectives. Required Skills: * Excellent written and verbal communication skills, with the ability to produce clear, concise, and well-structured analytical reports. Candidates should be prepared to demonstrate strong writing ability (e.g., via a writing sample or assessment). * Strong analytical and problem-solving skills, including the ability to work with incomplete, ambiguous, or conflicting information, and to assess the credibility, reliability, and relevance of sources and data. * Strong attention to detail and the ability to maintain focus and quality when processing large volumes of data across multiple sources. * Understanding of foundational cyber concepts, such as common attack vectors (e.g., phishing, credential misuse), high-level security terminology, and general threat actor motivations. * Understanding of core intelligence concepts, including the intelligence lifecycle, requirements gathering, and the distinction between tactical, operational, and strategic intelligence outputs. * A demonstrated interest in the cyber threat landscape, including financially-motivated activity (e.g., ransomware, extortion), as well as broader geopolitical, industry-specific, or emerging threats. Preferred Skills: * Academic or professional background in a research-focused discipline (qualitative or quantitative), such as Political Science, International Relations or Security Studies, Intelligence Studies, Criminology, Cybersecurity, Data Science, or related fields. * Experience using OSINT methodologies and/or threat intelligence platforms (e.g., Recorded Future, Flashpoint, MISP, VirusTotal, Shodan, Maltego, or similar tools) to collect, enrich, and analyse threat data from open, deep, and dark web sources. * Familiarity with dark web environments, underground forums, or illicit marketplaces, including an awareness of how threat actors communicate and operate in these spaces. * Ability to contextualize findings into business-relevant assessments, including potential impact, likelihood and recommended mitigations. * A foundational understanding of how cyber threats are categorised and communicated, including awareness of widely-used frameworks such as MITRE ATT&CK, the Diamond Model, or the Cyber Kill Chain. * Experience engaging with clients or stakeholders across the intelligence lifecycle, from requirements gathering through delivery, or a demonstrated willingness to develop this skill. * Proficiency in a second language is a strong advantage, particularly Russian, Spanish, Arabic, Portuguese, French, Mandarin, or other languages relevant to cyber threat actor communities. Successful candidates are likely to show the following personal attributes: * An investigative mindset and genuine enthusiasm for research. * A collaborative approach and willingness to work across teams. * Ability to manage competing priorities and deliver under pressure. * Initiative and ownership — a self-starter who identifies opportunities to enhance S-RM's cyber capabilities. Certifications & Training: Relevant industry certifications are not required for this role. However, we value evidence of continued learning. The following are considered beneficial: * Cyber Threat Intelligence: GCTI, CTIA, CREST CRTIA * Cybersecurity Foundations: Security+, CySA+ * OSINT & Open Source Research: GOSI, C|OSINT, SANS SEC497, OSINT Combine courses, Trace Labs OSINT training * Investigative Research & Verification: Bellingcat Online Investigation Workshops, etc. Participation in OSINT competitions (e.g., Trace Labs Search Party CTF) or contributions to open source research communities are also welcomed as evidence of practical skill development. Candidates must have permission to work in the UK by the start of their employment Our benefits We offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside of work. This includes but is not exhaustive of: * 25 days holiday per year in addition to public holidays (+1 day for every year of service up to a maximum of 30 days in total);yes * Hybrid working and flexible working hours; * Matching pension contribution up to 7% (up to a maximum of 14% combined), and financial education; * Life Insurance 4X annual salary. Parental Support: * Fertility treatment leave – 5 days of leave per cycle of treatment per year; * Maternity leave – 26 weeks of full pay followed by 13 weeks of half pay; * Paternity leave – 6 weeks of full pay. Various Health and Medical Benefits including: * Medical insurance (taxable benefit) for you and your family; * Virtual GP for you and your family members that live in the same household; * EAP programme for you and your immediate family; * Free access to the world-famous mindfulness app The application process We want to get to know you, and for you to get to know us, to see if we’d be a good fit. We are responsive and respectful of people’s time throughout our hiring process: A typical application process includes: * Initial screening of your application by our recruiting team. * An interview to assess your baseline technical skills. * An interview to discuss your previous experience, broader competencies, and suitability for the role. To apply for this role, please submit a tailored cover letter and CV to: Job Application for Analyst, Cyber Threat Intelligence at S-RM
ABOUT OUTTAKE Outtake exists to empower and facilitate trust for a digital-first world. Today, impersonation, fraud, AI-driven scams, and identity abuse spread faster than any security team can respond to. So we built something different: an agentic AI platform that proactively detects, monitors, and takes down impersonators, automating protection in hours, not weeks. Built by ex-Palantir, ex-CTO/founders, and ex-Notion engineers, Outtake is designed for clarity, autonomy, and velocity. Our goal is ambitious: become the trust layer of the modern internet. And we intend to do it with a lean, dense, exceptionally talented team. Outtake is backed by top-tier investors and operators who believe in our mission and our model. With strong financial footing and a long runway, we prioritize creating an environment where people can do the best work of their careers. Outtake isn’t a place for order-takers. It’s a place for enterprise sellers who think like builders—who love crafting value, navigating ambiguity, and convincing executives to bet on a new category. Our product solves a problem with universal demand and immediate ROI, which means you’ll have the chance to create and close meaningful business quickly. We’re looking for ambitious individuals who can navigate multiple decision-makers at the highest levels, creatively engage new prospects, and consistently exceed targets. You’ll be part of a nimble team with a bias toward action, building new relationships with global enterprise organizations. WHAT YOU’LL NEED TO BRING * Proven track record of closing six-figure B2B SaaS deals at the enterprise level, including experience selling to multiple stakeholders and aligning with their business goals. * Creative hunter mindset: You don’t wait for leads to show up; you proactively reach out, experiment with new tactics, and push forward—even in the face of no. * Technical fluency: You’re comfortable discussing relevant product features and integrations with highly technical buyers (CISOs, Threat Intel teams, etc.), and can translate complex concepts into business value. WHAT YOU’LL ACHIEVE * Build a new category in the threat intelligence and brand risk space, working hand-in-hand with the product team to refine and capitalize on strong market fit. * Partner with the biggest names in the world—CISOs, Threat Intelligence leaders, and brand owners who handle crucial security and PR incidents daily. * Champion Outtake’s solutions through high-impact product demos and strategic sales engagements that showcase how we can transform incident response and brand protection on a global scale. * Collaborate with a world-class team of product experts, engineers, and go-to-market professionals to continually evolve sales strategy and processes. * Maintain a relentless focus on growth by continuously improving our outbound strategy, refining messaging, and experimenting with new ways to break into untapped verticals. WHAT SUCCESS LOOKS LIKE * Consistently exceeding monthly and quarterly revenue targets, with a strong pipeline of enterprise opportunities. * Streamlining and iterating on the enterprise sales cycle to deliver a high-quality buyer experience from first touch to close. * Providing product feedback that directly impacts the roadmap, ensuring Outtake remains the premier incident management and brand protection platform. * Becoming an indispensable resource for our customers—someone who fosters trust, builds strong relationships, and is the go-to point of contact for strategic escalations and long-term success. LIFE AT OUTTAKE * Office: For those in NY, we are an in-person team (5 days a week, with flexibility as needed) working out of a stunning waterfront office in Brooklyn. Collaboration, speed, and clarity matter. * Health: 100% company-paid medical, dental, and vision for employees. * Time Away: Flexible PTO. We trust adults to manage energy, not clock time. * Culture & Team: Annual company retreats and regular in-person events. Outtake is an equal opportunity employer. We are committed to building a diverse, inclusive team.