×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

MDR Team Lead

Job in Oxford, Oxfordshire, OX1, England, UK
Listing for: Sophos Group
Full Time position
Listed on 2026-07-10
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 90000 - 120000 GBP Yearly GBP 90000.00 120000.00 YEAR
Job Description & How to Apply Below

Role Summary

Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement.

As part of the Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes.

What you will do
  • Lead day-to-day MDR operations, overseeing case queues, analyst workloads, SLA performance, escalations, and resource allocation to ensure consistent service delivery.
  • Guide and review incident investigations, validating findings, assessing business impact, recommending response actions, and ensuring appropriate escalation management.
  • Serve as a key point of coordination during customer and internal escalations, providing clear updates, risk assessments, recommendations, and resolution plans.
  • Coach, mentor, and develop MDR analysts through case reviews, feedback, skills development, and performance management.
  • Conduct quality reviews of investigations, customer communications, documentation, and calls to drive operational excellence and continuous improvement.
  • Analyse operational metrics and dashboards to identify trends, risks, capacity constraints, and opportunities to improve service quality, efficiency, and customer outcomes.
  • Develop and maintain SOPs, playbooks, workflows, and knowledge-base content to improve consistency and operational readiness.
  • Provide technical leadership in intrusion analysis, incident response, digital forensics, malware investigations, and threat hunting activities.
  • Lead response efforts during significant security incidents, ensuring effective coordination, decision-making, and ownership through resolution.
  • Stay current on threat actor tactics, techniques, and procedures (TTPs), leveraging threat intelligence to enhance investigations, detections, and response capabilities.
  • Partner with Engineering, Labs, and Content teams to improve detection quality, reduce false positives, and address recurring investigation gaps.
What you will bring
  • Up to 12 years of total work experience.
  • 5+ years of experience in cybersecurity, with a minimum of 2-3 years leading, mentoring, or coordinating analysts in a SOC, MDR, Incident Response, or similar environment.
  • Bachelor’s degree in Information Technology, Computer Science, or a related field, or equivalent practical experience.
  • Hands‑on experience in security operations, including threat detection, incident investigation, and response.
  • Strong understanding of endpoint and network security technologies, including IDS/IPS, EDR, ATP, malware protection, and monitoring platforms.
  • Experience with threat hunting methodologies and familiarity with the MITRE ATT&CK framework preferred.
  • Working knowledge of incident response processes, adversary tactics and techniques, and cyber threat intelligence.
  • Strong technical expertise in Windows environments, including host artefacts, endpoint telemetry, event log analysis, and operating system security events; exposure to macOS and Linux is a plus.
  • Solid understanding of network fundamentals, including TCP/IP, routing, switching, and traffic analysis.
  • Experience with SIEM platforms and enterprise security data management; database querying skills are advantageous.
  • Working knowledge of Power Shell and Python for automation and investigation support.
  • Strong analytical, troubleshooting, and decision‑making skills, with the ability to prioritise effectively in high‑pressure situations.
  • Excellent written and verbal communication skills, including the ability to produce clear reports, case summaries, operational updates, and executive‑ready communications.
  • Experience performing quality reviews and providing actionable feedback that improves investigation outcomes and analyst performance.
  • Proven ability to build…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary