Sophos in Oxford, UK, is seeking a Change & Adoption Lead to drive IT service experience transformation across a global workforce. You will champion user-centred design, accelerate technology adoption, and embed continuous improvement across the organization, ensuring productive workplaces and higher employee satisfaction. Responsibilities include shaping change strategies, crafting communications, and leading training initiatives, while partnering with IT and business leaders to deliver
04/08/2026
Full time
Sophos in Oxford, UK, is seeking a Change & Adoption Lead to drive IT service experience transformation across a global workforce. You will champion user-centred design, accelerate technology adoption, and embed continuous improvement across the organization, ensuring productive workplaces and higher employee satisfaction. Responsibilities include shaping change strategies, crafting communications, and leading training initiatives, while partnering with IT and business leaders to deliver
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies - including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at . The Change & Adoption Lead will be the primary driver of IT service experience transformation, acting as the critical interlock between IT Service & Operations and our 5,500 employees globally. This role owns the end-to-end customer journey for IT services, championing user-centred design, driving technology adoption, and embedding continuous improvement practices across the organization. The successful candidate will be responsible for developing and executing change management strategies, building compelling communication campaigns, and facilitating employee engagement to ensure seamless adoption of new technologies, processes, and ways of working that enhance productivity and employee satisfaction. Day-to-day responsibilities Customer Experience & Journey Design Own the end-to-end IT service customer experience, mapping user journeys and identifying friction points that impact employee productivity Develop and implement customer experience metrics, dashboards, and feedback mechanisms to drive continuous service improvement Host regular end-user focus groups, listening sessions, and workshops to gather insights and co-create solutions with the business Design and manage customer experience improvement initiatives from ideation through implementation and measurement Change Management & Adoption Develop compelling communications campaigns that drive awareness, understanding, and adoption across diverse employee populations Create engaging training materials, user guides, self-service resources, and enablement content tailored to different user personas Facilitate virtual and onsite training sessions, drop-in clinics, and hands-on workshops to accelerate technology adoption Stakeholder Engagement & Influence Serve as the voice of the employee, translating user feedback into actionable improvement recommendations for IT leadership Build trusted relationships with business unit leaders, resolving teams, and key stakeholders to drive collaboration and alignment Present data-driven insights, trend analysis, and business cases to leadership that demonstrate ROI and business value Influence service design decisions by advocating for user needs and industry best practices Process Improvement & Innovation Identify and prioritize service improvement opportunities through data analysis, user feedback, and industry benchmarking Develop business cases including investment requirements, expected returns, and benefit realization plans Collaborate with process owners, knowledge management, and engineering teams to design and implement automation opportunities Drive adoption of best-in-class tooling, processes, and self-service capabilities aligned to ITIL and industry standards Required Experience Change Management & Adoption: Demonstrated success leading organization-wide technology adoption programs, preferably in global enterprises with 1,000+ employees Customer Experience Design: Track record of mapping customer journeys, implementing user personas, and driving measurable improvements in user satisfaction (CSAT/NPS) Communication & Enablement: Exceptional ability to create engaging, multi-channel communication campaigns and training content for technical and non-technical audiences Stakeholder Influence: Proven ability to influence without authority, building consensus across IT and business stakeholders at all organizational levels Process Transformation: Experience driving process change initiatives, documenting current vs. future state, and managing change resistance Data-Driven Decision Making: Proficiency with analytics tools (Power BI, Tableau, etc.) to develop dashboards, identify trends, and present actionable insights to leadership Facilitation & Training: Comfortable hosting workshops, focus groups, and training sessions both virtually and in-person with groups ranging from 5-100+ participants ITSM & Self-Service: Understanding of IT service management principles and experience implementing self-service technologies and knowledge management solutions Business Case Development: Ability to build compelling business cases that articulate ROI, productivity gains, and strategic value of technology investments Ready to Join Us? At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back -we encourage you to apply. What's Great About Sophos? Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship. Our people - we innovate and create, all of which are accompanied by a great sense of fun and team spirit Employee-led diversity and inclusion networks that build community and provide education and advocacy Annual charity and fundraising initiatives and volunteer days for employees to support local communities Global employee sustainability initiatives to reduce our environmental footprint Global fitness and trivia competitions to keep our bodies and minds sharp Global wellbeing days for employees to relax and recharge Monthly wellbeing webinars and training to support employee health and wellbeing Our Commitment To You We're proud of the diverse and inclusive environment we have at Sophos, and we're committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered Sophos
03/08/2026
Full time
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies - including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at . The Change & Adoption Lead will be the primary driver of IT service experience transformation, acting as the critical interlock between IT Service & Operations and our 5,500 employees globally. This role owns the end-to-end customer journey for IT services, championing user-centred design, driving technology adoption, and embedding continuous improvement practices across the organization. The successful candidate will be responsible for developing and executing change management strategies, building compelling communication campaigns, and facilitating employee engagement to ensure seamless adoption of new technologies, processes, and ways of working that enhance productivity and employee satisfaction. Day-to-day responsibilities Customer Experience & Journey Design Own the end-to-end IT service customer experience, mapping user journeys and identifying friction points that impact employee productivity Develop and implement customer experience metrics, dashboards, and feedback mechanisms to drive continuous service improvement Host regular end-user focus groups, listening sessions, and workshops to gather insights and co-create solutions with the business Design and manage customer experience improvement initiatives from ideation through implementation and measurement Change Management & Adoption Develop compelling communications campaigns that drive awareness, understanding, and adoption across diverse employee populations Create engaging training materials, user guides, self-service resources, and enablement content tailored to different user personas Facilitate virtual and onsite training sessions, drop-in clinics, and hands-on workshops to accelerate technology adoption Stakeholder Engagement & Influence Serve as the voice of the employee, translating user feedback into actionable improvement recommendations for IT leadership Build trusted relationships with business unit leaders, resolving teams, and key stakeholders to drive collaboration and alignment Present data-driven insights, trend analysis, and business cases to leadership that demonstrate ROI and business value Influence service design decisions by advocating for user needs and industry best practices Process Improvement & Innovation Identify and prioritize service improvement opportunities through data analysis, user feedback, and industry benchmarking Develop business cases including investment requirements, expected returns, and benefit realization plans Collaborate with process owners, knowledge management, and engineering teams to design and implement automation opportunities Drive adoption of best-in-class tooling, processes, and self-service capabilities aligned to ITIL and industry standards Required Experience Change Management & Adoption: Demonstrated success leading organization-wide technology adoption programs, preferably in global enterprises with 1,000+ employees Customer Experience Design: Track record of mapping customer journeys, implementing user personas, and driving measurable improvements in user satisfaction (CSAT/NPS) Communication & Enablement: Exceptional ability to create engaging, multi-channel communication campaigns and training content for technical and non-technical audiences Stakeholder Influence: Proven ability to influence without authority, building consensus across IT and business stakeholders at all organizational levels Process Transformation: Experience driving process change initiatives, documenting current vs. future state, and managing change resistance Data-Driven Decision Making: Proficiency with analytics tools (Power BI, Tableau, etc.) to develop dashboards, identify trends, and present actionable insights to leadership Facilitation & Training: Comfortable hosting workshops, focus groups, and training sessions both virtually and in-person with groups ranging from 5-100+ participants ITSM & Self-Service: Understanding of IT service management principles and experience implementing self-service technologies and knowledge management solutions Business Case Development: Ability to build compelling business cases that articulate ROI, productivity gains, and strategic value of technology investments Ready to Join Us? At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back -we encourage you to apply. What's Great About Sophos? Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship. Our people - we innovate and create, all of which are accompanied by a great sense of fun and team spirit Employee-led diversity and inclusion networks that build community and provide education and advocacy Annual charity and fundraising initiatives and volunteer days for employees to support local communities Global employee sustainability initiatives to reduce our environmental footprint Global fitness and trivia competitions to keep our bodies and minds sharp Global wellbeing days for employees to relax and recharge Monthly wellbeing webinars and training to support employee health and wellbeing Our Commitment To You We're proud of the diverse and inclusive environment we have at Sophos, and we're committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered Sophos
Sophos is seeking a Software Engineer to join its SRE platform team. You will help build and maintain a cloud-based platform enabling multiple development teams to deploy and operate SaaS applications and microservices. You will apply Java, Spring Boot, AWS, and Terraform to automate builds, manage APIs, and enhance CI/CD pipelines in an agile environment. Remote-first with UK/global opportunities.
26/07/2026
Full time
Sophos is seeking a Software Engineer to join its SRE platform team. You will help build and maintain a cloud-based platform enabling multiple development teams to deploy and operate SaaS applications and microservices. You will apply Java, Spring Boot, AWS, and Terraform to automate builds, manage APIs, and enhance CI/CD pipelines in an agile environment. Remote-first with UK/global opportunities.
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies - including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at . Role Summary A SRE platform team is responsible to build and maintain a platform for other teams to use. The platform can support the development, deployment, and operations of software applications. Platform teams may also be called SRE specialists. Optimize the software delivery process: Platform teams can simplify how developers interact with infrastructure, streamline onboarding, and make testing and development faster The Software Engineer will play a key role in the Sophos development process by facilitating, managing, communicating, and automating tasks for the deployment and configuration of continuous feature builds for multiple development teams. By leveraging knowledge and expertise in the development and deployment of SaaS applications and microservices hosted in the cloud, the SRE engineer will streamline the process of quick and frequent automated builds, managing the public endpoints API's and help elevate the Sophos development process to the next level of agility. As a member of the Sophos SRE team, you will work closely with Senior software engineers and Product Managers to design and build the foundational toolset and capabilities that allow Sophos developers to quickly bring new features to market. What You Will Do Build new product/ Customizing terraform automations using Java technologies. Carry out the analysis, design, and implementation of new features across the Java Backend software stack, leveraging modern design patterns. Address defects within well-defined SLAs to ensure that our customers stay happy. Build features and modules using Java, Spring Boot, Microservices & AWS. Write automated unit and integration tests to execute within CI/CD pipelines & terraform in Platform code. Will be part of platform/ could implementing for the Infrastructure as a Service (IAAS) using Docker & Kubernetes. Take pride in authorship of code and hold your teammates to equally high standards. Work with best of breed Cloud technologies. Learn new technologies and skills and apply them to your work. Work in an Agile environment, releasing software frequently. What You Will Bring 1-2 years of development experience in Java, Spring Boot, Microservices & AWS. Strong understanding of APIs development principles, including concepts on design Patterns, problem solving, Data structures, Should have fare understanding / experience in product development area. Should have knowledge of CICD pipelines - Dockers, Kubernetes, Jenkins, Should have worked on complete SDLC. What's Great About Sophos? Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship. Our people - we innovate and create, all of which are accompanied by a great sense of fun and team spirit Employee-led diversity and inclusion networks that build community and provide education and advocacy Annual charity and fundraising initiatives and volunteer days for employees to support local communities Global employee sustainability initiatives to reduce our environmental footprint Global fitness and trivia competitions to keep our bodies and minds sharp Global wellbeing days for employees to relax and recharge Monthly wellbeing webinars and training to support employee health and wellbeing Our Commitment To You We're proud of the diverse and inclusive environment we have at Sophos, and we're committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered Sophos
26/07/2026
Full time
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies - including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at . Role Summary A SRE platform team is responsible to build and maintain a platform for other teams to use. The platform can support the development, deployment, and operations of software applications. Platform teams may also be called SRE specialists. Optimize the software delivery process: Platform teams can simplify how developers interact with infrastructure, streamline onboarding, and make testing and development faster The Software Engineer will play a key role in the Sophos development process by facilitating, managing, communicating, and automating tasks for the deployment and configuration of continuous feature builds for multiple development teams. By leveraging knowledge and expertise in the development and deployment of SaaS applications and microservices hosted in the cloud, the SRE engineer will streamline the process of quick and frequent automated builds, managing the public endpoints API's and help elevate the Sophos development process to the next level of agility. As a member of the Sophos SRE team, you will work closely with Senior software engineers and Product Managers to design and build the foundational toolset and capabilities that allow Sophos developers to quickly bring new features to market. What You Will Do Build new product/ Customizing terraform automations using Java technologies. Carry out the analysis, design, and implementation of new features across the Java Backend software stack, leveraging modern design patterns. Address defects within well-defined SLAs to ensure that our customers stay happy. Build features and modules using Java, Spring Boot, Microservices & AWS. Write automated unit and integration tests to execute within CI/CD pipelines & terraform in Platform code. Will be part of platform/ could implementing for the Infrastructure as a Service (IAAS) using Docker & Kubernetes. Take pride in authorship of code and hold your teammates to equally high standards. Work with best of breed Cloud technologies. Learn new technologies and skills and apply them to your work. Work in an Agile environment, releasing software frequently. What You Will Bring 1-2 years of development experience in Java, Spring Boot, Microservices & AWS. Strong understanding of APIs development principles, including concepts on design Patterns, problem solving, Data structures, Should have fare understanding / experience in product development area. Should have knowledge of CICD pipelines - Dockers, Kubernetes, Jenkins, Should have worked on complete SDLC. What's Great About Sophos? Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship. Our people - we innovate and create, all of which are accompanied by a great sense of fun and team spirit Employee-led diversity and inclusion networks that build community and provide education and advocacy Annual charity and fundraising initiatives and volunteer days for employees to support local communities Global employee sustainability initiatives to reduce our environmental footprint Global fitness and trivia competitions to keep our bodies and minds sharp Global wellbeing days for employees to relax and recharge Monthly wellbeing webinars and training to support employee health and wellbeing Our Commitment To You We're proud of the diverse and inclusive environment we have at Sophos, and we're committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered Sophos
Role Summary Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement. As part of the Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes. What you will do Lead day-to-day MDR operations, overseeing case queues, analyst workloads, SLA performance, escalations, and resource allocation to ensure consistent service delivery. Guide and review incident investigations, validating findings, assessing business impact, recommending response actions, and ensuring appropriate escalation management. Serve as a key point of coordination during customer and internal escalations, providing clear updates, risk assessments, recommendations, and resolution plans. Coach, mentor, and develop MDR analysts through case reviews, feedback, skills development, and performance management. Conduct quality reviews of investigations, customer communications, documentation, and calls to drive operational excellence and continuous improvement. Analyse operational metrics and dashboards to identify trends, risks, capacity constraints, and opportunities to improve service quality, efficiency, and customer outcomes. Develop and maintain SOPs, playbooks, workflows, and knowledge-base content to improve consistency and operational readiness. Provide technical leadership in intrusion analysis, incident response, digital forensics, malware investigations, and threat hunting activities. Lead response efforts during significant security incidents, ensuring effective coordination, decision-making, and ownership through resolution. Stay current on threat actor tactics, techniques, and procedures (TTPs), leveraging threat intelligence to enhance investigations, detections, and response capabilities. Partner with Engineering, Labs, and Content teams to improve detection quality, reduce false positives, and address recurring investigation gaps. What you will bring Up to 12 years of total work experience. 5+ years of experience in cybersecurity, with a minimum of 2-3 years leading, mentoring, or coordinating analysts in a SOC, MDR, Incident Response, or similar environment. Bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent practical experience. Hands on experience in security operations, including threat detection, incident investigation, and response. Strong understanding of endpoint and network security technologies, including IDS/IPS, EDR, ATP, malware protection, and monitoring platforms. Experience with threat hunting methodologies and familiarity with the MITRE ATT&CK framework preferred. Working knowledge of incident response processes, adversary tactics and techniques, and cyber threat intelligence. Strong technical expertise in Windows environments, including host artefacts, endpoint telemetry, event log analysis, and operating system security events; exposure to macOS and Linux is a plus. Solid understanding of network fundamentals, including TCP/IP, routing, switching, and traffic analysis. Experience with SIEM platforms and enterprise security data management; database querying skills are advantageous. Working knowledge of PowerShell and Python for automation and investigation support. Strong analytical, troubleshooting, and decision making skills, with the ability to prioritise effectively in high pressure situations. Excellent written and verbal communication skills, including the ability to produce clear reports, case summaries, operational updates, and executive ready communications. Experience performing quality reviews and providing actionable feedback that improves investigation outcomes and analyst performance. Proven ability to build team capability through coaching, onboarding, training, and knowledge sharing. Strong stakeholder management and customer facing skills, with the capability to explain technical findings, risks, and recommendations to both technical and non technical audiences. Advanced cybersecurity certifications are preferred but not required. Equal Opportunity Employer All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy.
10/07/2026
Full time
Role Summary Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement. As part of the Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes. What you will do Lead day-to-day MDR operations, overseeing case queues, analyst workloads, SLA performance, escalations, and resource allocation to ensure consistent service delivery. Guide and review incident investigations, validating findings, assessing business impact, recommending response actions, and ensuring appropriate escalation management. Serve as a key point of coordination during customer and internal escalations, providing clear updates, risk assessments, recommendations, and resolution plans. Coach, mentor, and develop MDR analysts through case reviews, feedback, skills development, and performance management. Conduct quality reviews of investigations, customer communications, documentation, and calls to drive operational excellence and continuous improvement. Analyse operational metrics and dashboards to identify trends, risks, capacity constraints, and opportunities to improve service quality, efficiency, and customer outcomes. Develop and maintain SOPs, playbooks, workflows, and knowledge-base content to improve consistency and operational readiness. Provide technical leadership in intrusion analysis, incident response, digital forensics, malware investigations, and threat hunting activities. Lead response efforts during significant security incidents, ensuring effective coordination, decision-making, and ownership through resolution. Stay current on threat actor tactics, techniques, and procedures (TTPs), leveraging threat intelligence to enhance investigations, detections, and response capabilities. Partner with Engineering, Labs, and Content teams to improve detection quality, reduce false positives, and address recurring investigation gaps. What you will bring Up to 12 years of total work experience. 5+ years of experience in cybersecurity, with a minimum of 2-3 years leading, mentoring, or coordinating analysts in a SOC, MDR, Incident Response, or similar environment. Bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent practical experience. Hands on experience in security operations, including threat detection, incident investigation, and response. Strong understanding of endpoint and network security technologies, including IDS/IPS, EDR, ATP, malware protection, and monitoring platforms. Experience with threat hunting methodologies and familiarity with the MITRE ATT&CK framework preferred. Working knowledge of incident response processes, adversary tactics and techniques, and cyber threat intelligence. Strong technical expertise in Windows environments, including host artefacts, endpoint telemetry, event log analysis, and operating system security events; exposure to macOS and Linux is a plus. Solid understanding of network fundamentals, including TCP/IP, routing, switching, and traffic analysis. Experience with SIEM platforms and enterprise security data management; database querying skills are advantageous. Working knowledge of PowerShell and Python for automation and investigation support. Strong analytical, troubleshooting, and decision making skills, with the ability to prioritise effectively in high pressure situations. Excellent written and verbal communication skills, including the ability to produce clear reports, case summaries, operational updates, and executive ready communications. Experience performing quality reviews and providing actionable feedback that improves investigation outcomes and analyst performance. Proven ability to build team capability through coaching, onboarding, training, and knowledge sharing. Strong stakeholder management and customer facing skills, with the capability to explain technical findings, risks, and recommendations to both technical and non technical audiences. Advanced cybersecurity certifications are preferred but not required. Equal Opportunity Employer All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy.
Sophos in Oxford is seeking an experienced MDR Manager to lead its Managed Detection and Response operations. You will supervise MDR analysts, manage case queues, SLAs, escalations, and drive service quality across investigations and reporting. You will guide investigations, coach analysts, and coordinate during customer and internal escalations. The role requires strong technical security knowledge, risk assessment, and clear executive-ready communications to improve customer outcomes.
10/07/2026
Full time
Sophos in Oxford is seeking an experienced MDR Manager to lead its Managed Detection and Response operations. You will supervise MDR analysts, manage case queues, SLAs, escalations, and drive service quality across investigations and reporting. You will guide investigations, coach analysts, and coordinate during customer and internal escalations. The role requires strong technical security knowledge, risk assessment, and clear executive-ready communications to improve customer outcomes.