Senior Cyber Threat Defense - Security Operations Engineer

ProofpointDraper, UT
$101,600 - $214,005Onsite

About The Position

We are seeking an experienced Senior Cyber Threat Defense - Security Operations Engineer to join our global security team in Draper, UT. This critical role sits within the Global Information Security Operation team and is responsible for investigating and responding to sophisticated security incidents across Proofpoint's global operations. You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC), own complex investigations and technical decisions, participate in a scheduled on-call rotation, and set direction for detection, investigation, response, threat modeling, and security automation. The role also supports selected AI-enabled capabilities, including Agentic SOC workflows and AI Data Loss Prevention (AI DLP).

Requirements

  • Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations.
  • U.S. citizenship.
  • Demonstrated experience leading major incidents and serving as the final technical escalation point for complex or high-severity security events.
  • Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, and security monitoring.
  • Experience investigating malware, phishing, identity attacks, cloud compromise, insider threats, data loss, and advanced persistent threats.
  • Hands-on experience with SOAR platforms, APIs, and scripting languages such as Python, PowerShell, or Bash.
  • Strong understanding of the MITRE ATT&CK framework, attacker tactics, techniques, and procedures, and the cyber kill chain.
  • Experience applying threat modeling methods such as STRIDE, attack trees, or MITRE ATT&CK to enterprise or cloud systems.
  • Experience creating or tuning detection rules, hunting queries, and response playbooks.
  • Working knowledge of cloud security across AWS, Microsoft Azure, or Google Cloud Platform.
  • Proven ability to own technical strategy, influence architecture and control decisions, and drive cross-functional security improvements.
  • Strong executive communication, analytical, troubleshooting, and documentation skills, with the ability to make sound decisions during high-pressure incidents.
  • Willingness and ability to participate in an on-call rotation and respond to critical incidents outside normal business hours, including nights, weekends, and holidays as required.

Nice To Haves

  • Experience with Agentic SOC, AI-assisted investigation, or AI DLP capabilities.
  • Experience with identity, cloud, or data detection and response technologies.
  • Experience leading incident simulations, purple-team exercises, or adversary-emulation activities.
  • Relevant certifications such as GCIH, GCFA, CISSP, CISM, OSCP, GIAC, or cloud-security certifications.

Responsibilities

  • Own Level 3 escalation for high-severity and technically complex incidents within the global 24/7 SOC.
  • Lead major investigations involving malware, ransomware, phishing, identity attacks, insider threats, cloud compromise, and advanced persistent threats.
  • Set containment, eradication, recovery, remediation, and post-incident improvement strategy, balancing risk and business impact.
  • Direct response across Security, IT, Cloud Engineering, Legal, Privacy, and business leaders, and communicate incident status and decisions to executives.
  • Participate in a scheduled on-call rotation and provide after-hours support for critical security incidents, including nights, weekends, and holidays as required.
  • Proactively hunt for hidden threats across endpoints, identities, networks, cloud environments, SaaS applications, and data repositories.
  • Lead cross-functional threat modeling for new and existing systems, cloud services, and security workflows to identify abuse cases, attack paths, and control gaps.
  • Use threat intelligence and behavioral analytics to identify suspicious activity and emerging attack patterns.
  • Develop, test, tune, and maintain detection rules, correlations, hunting queries, and response use cases.
  • Translate threat intelligence and MITRE ATT&CK techniques into actionable detection and hunting use cases.
  • Define and implement automation strategy for alert enrichment, prioritization, triage, containment, notification, and remediation.
  • Use SOAR platforms and security APIs to streamline repeatable incident-response activities.
  • Develop scripts, integrations, and automation using Python, PowerShell, Bash, or similar languages.
  • Optimize SIEM log ingestion, normalization, correlation, retention, and alerting.
  • Support practical Agentic SOC use cases for alert triage, investigation enrichment, case documentation, and response under defined human oversight.
  • Help operate AI DLP controls that reduce sensitive-data exposure through generative AI applications and copilots.
  • Own root-cause analysis and drive improvements to security controls, telemetry, processes, and architecture.
  • Partner with security architects and engineering leaders to set technical direction and evaluate detection and response technologies.
  • Mentor engineers and analysts, establish investigation standards, and raise technical capability across the SOC.

Benefits

  • Competitive compensation
  • Comprehensive benefits
  • Career success on your terms
  • Flexible work environment
  • Annual wellness and community outreach days
  • Always on recognition for your contributions
  • Global collaboration and networking opportunities
  • flexible time off
  • comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year
  • three-week Work from Anywhere option
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service