About The Position

About Us: Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people. How We Work: At Proofpoint you’ll be part of a global team that breaks barriers to redefine cybersecurity guided by our BRAVE core values: Bold in how we dream and innovate Responsive to feedback, challenges and opportunities Accountable for results and best in class outcomes Visionary in future focused problem-solving Exceptional in execution and impact About Proofpoint At Proofpoint, we are committed to protecting organizations and individuals from cyber threats through innovative security solutions. Our mission is to safeguard our customers from advanced threats, phishing attacks, and data breaches with cutting-edge technology and a global team of security experts. Role Overview We are seeking an experienced Cyber Incident Response Security Engineer to join our global security team. This is a critical role within our Cyber Incident Response Team (CIRT), responsible for managing and responding to security incidents across our global operations. You will serve as an escalation point for our 24/7 Security Operations Center (SOC) and play a key role in the automation, orchestration, and enhancement of our security incident response capabilities. This position requires deep expertise in cybersecurity, strong analytical skills, and the ability to work collaboratively in a fast-paced environment. If you thrive in a role where you can actively defend against cyber threats, conduct threat hunting, and drive security automation, this opportunity is for you.

Requirements

  • 12 yrs + hands-on experience in Cybersecurity Incident Response or Security Operations.
  • Must be a US Citizen.
  • Strong background in SOC operations, SIEM, threat intelligence, and digital forensics.
  • Expertise in investigating malware, phishing, web attacks, insider threats, and advanced persistent threats (APTs).
  • Experience working with security automation and orchestration tools (SOAR).
  • Familiarity with scripting languages such as Python, PowerShell, or Bash for security automation.
  • Strong understanding of MITRE ATT&CK framework, TTPs (Tactics, Techniques, and Procedures), and cyber kill chain.
  • Ability to work in a fast-paced, global environment and collaborate with cross-functional teams.

Nice To Haves

  • Hands-on experience with cloud security (AWS, Azure, GCP) is a plus.
  • Certifications such as GCIH, GCFA, CISSP, CISM, or OSCP are highly desirable.

Responsibilities

  • Incident Response & Escalation: Act as the Level 3 escalation point for high-severity security incidents within the global 24/7 SOC.
  • Lead complex investigations into advanced cyber threats, including malware outbreaks, targeted attacks, and persistent threats.
  • Provide expert-level guidance on containment, mitigation, and remediation strategies.
  • Threat Hunting & Threat Assessment: Proactively hunt for hidden threats within enterprise networks using threat intelligence and behavioral analytics.
  • Develop and refine threat detection rules to improve SOC visibility.
  • Assess emerging threats and provide actionable recommendations to enhance security posture.
  • Security Automation & Orchestration: Design and implement automated workflows to enhance security event triage and response.
  • Leverage SOAR (Security Orchestration, Automation, and Response) platforms to streamline incident response.
  • Work with SIEM (Security Information and Event Management) tools to optimize log ingestion and alerting mechanisms.
  • Security Tooling & Continuous Improvement: Collaborate with security architects and engineers to enhance detection and response capabilities.
  • Perform root cause analysis on security incidents and recommend improvements to security controls.
  • Stay updated on industry best practices and evolving attack techniques to ensure effective defenses.

Benefits

  • Competitive compensation
  • Comprehensive benefits
  • Career success on your terms
  • Flexible work environment
  • Annual wellness and community outreach days
  • Always on recognition for your contributions
  • Global collaboration and networking opportunities

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

1,001-5,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service