Cyber Incident Response Security Engineer at Proofpoint, responsible for incident response and security automation. Collaborating globally to defend against cyber threats and enhance incident response capabilities.
Responsibilities
Act as the Level 3 escalation point for high-severity security incidents within the global 24/7 SOC.
Lead complex investigations into advanced cyber threats, including malware outbreaks, targeted attacks, and persistent threats.
Provide expert-level guidance on containment, mitigation, and remediation strategies.
Proactively hunt for hidden threats within enterprise networks using threat intelligence and behavioral analytics.
Develop and refine threat detection rules to improve SOC visibility.
Assess emerging threats and provide actionable recommendations to enhance security posture.
Design and implement automated workflows to enhance security event triage and response.
Leverage SOAR (Security Orchestration, Automation, and Response) platforms to streamline incident response.
Work with SIEM (Security Information and Event Management) tools to optimize log ingestion and alerting mechanisms.
Collaborate with security architects and engineers to enhance detection and response capabilities.
Perform root cause analysis on security incidents and recommend improvements to security controls.
Stay updated on industry best practices and evolving attack techniques to ensure effective defenses.
Requirements
12 yrs + hands-on experience in Cybersecurity Incident Response or Security Operations.
Must be a US Citizen.
Strong background in SOC operations, SIEM, threat intelligence, and digital forensics.
Expertise in investigating malware, phishing, web attacks, insider threats, and advanced persistent threats (APTs).
Experience working with security automation and orchestration tools (SOAR).
Familiarity with scripting languages such as Python, PowerShell, or Bash for security automation.
Strong understanding of MITRE ATT&CK framework, TTPs (Tactics, Techniques, and Procedures), and cyber kill chain.
Hands-on experience with cloud security (AWS, Azure, GCP) is a plus.
Certifications such as GCIH, GCFA, CISSP, CISM, or OSCP are highly desirable.
Ability to work in a fast-paced, global environment and collaborate with cross-functional teams.
DevSecOps engineer at Ford ensuring secure software development and compliance with security standards. Collaborating with teams to embed security practices and assess vulnerabilities in software delivery.
Security Officer responsible for ensuring safety and security at the Genesee Brewing Company. Monitoring premises, responding to emergencies, and providing visitor assistance during shifts.
Security Estimator creating estimates and proposals for security projects at LINX. Collaborating with engineering and sales teams for system design and client relationships.
Product Security Architect at Expedia designing secure architecture for services and APIs. Collaborating with teams to guide secure practices and integrate AI - driven solutions.
IT Security Officer overseeing information security for a specific IT sector at Desjardins. Collaborating with cross - sector teams and managing information security risks and vulnerabilities.
Associate, Information Security professional at Santander focusing on Vulnerability Management and network security exposure. Collaborating with teams to enhance security posture and manage technology risks.
IAM Security & Technology Governance person driving IAM technical program with cutting - edge technology to improve security posture at MUFG. Manage IAM requirements, standards, governance and solutions across global implementation.
Senior Analyst in Mastercard's newly created Vocalink Control Office supporting control testing across Security domains. Ensuring a strong control environment and identifying gaps for improvement.
Senior Analyst focusing on Information Security and Compliance at Cirque du Soleil. Engaging in threat analysis and improvement of security tools and processes, within a creative company culture.
Security Architect designing and implementing cybersecurity architectures for UK Defence projects. Collaborating with stakeholders to safeguard client data against cyber threats.