Cyber Incident Response Security Engineer at Proofpoint, responsible for incident response and security automation. Collaborating globally to defend against cyber threats and enhance incident response capabilities.
Responsibilities
Act as the Level 3 escalation point for high-severity security incidents within the global 24/7 SOC.
Lead complex investigations into advanced cyber threats, including malware outbreaks, targeted attacks, and persistent threats.
Provide expert-level guidance on containment, mitigation, and remediation strategies.
Proactively hunt for hidden threats within enterprise networks using threat intelligence and behavioral analytics.
Develop and refine threat detection rules to improve SOC visibility.
Assess emerging threats and provide actionable recommendations to enhance security posture.
Design and implement automated workflows to enhance security event triage and response.
Leverage SOAR (Security Orchestration, Automation, and Response) platforms to streamline incident response.
Work with SIEM (Security Information and Event Management) tools to optimize log ingestion and alerting mechanisms.
Collaborate with security architects and engineers to enhance detection and response capabilities.
Perform root cause analysis on security incidents and recommend improvements to security controls.
Stay updated on industry best practices and evolving attack techniques to ensure effective defenses.
Requirements
12 yrs + hands-on experience in Cybersecurity Incident Response or Security Operations.
Must be a US Citizen.
Strong background in SOC operations, SIEM, threat intelligence, and digital forensics.
Expertise in investigating malware, phishing, web attacks, insider threats, and advanced persistent threats (APTs).
Experience working with security automation and orchestration tools (SOAR).
Familiarity with scripting languages such as Python, PowerShell, or Bash for security automation.
Strong understanding of MITRE ATT&CK framework, TTPs (Tactics, Techniques, and Procedures), and cyber kill chain.
Hands-on experience with cloud security (AWS, Azure, GCP) is a plus.
Certifications such as GCIH, GCFA, CISSP, CISM, or OSCP are highly desirable.
Ability to work in a fast-paced, global environment and collaborate with cross-functional teams.
Facility Security Officer managing Industrial Security at Curtiss - Wright. Overseeing physical, personnel, and information security while ensuring compliance with government regulations.
Cybersecurity Engineer protecting organizational systems and data at Legends Global. Designing secure infrastructures and automating security tooling in a dynamic tech environment.
Security Architect providing expertise to secure software development ecosystems including CI/CD pipelines and code repositories. Ensuring security principles are integrated throughout the Software Development Lifecycle (SSDL).
Security Architect designing security frameworks to protect industrial control and IoT systems. Collaborating with teams to ensure compliance and mitigate cyber threats in OT environments.
Security Engineer at G+D Group ensuring secure service delivery across IT environments. Collaborating with teams to translate security policies into operational solutions while monitoring threats.
ICT & Security Risk Manager managing ICT risk framework and assessments in BCR, a leading banking organization. Ensuring effective risk monitoring and reporting for secure operations.
Leading the Application Security team at Clio, focusing on building scalable security solutions. Collaborating across teams and leading security initiatives in a hybrid work environment.
Senior Project Manager overseeing cybersecurity initiatives at Australian Payments Plus. Responsible for project planning, execution, and stakeholder management while leading cross - functional teams.