Information Security Engineer 4 - Contingent
Job Description
Assist in the development of automation and integrations to enhance operational efficiency, telemetry analysis, and threat response capabilities across endpoint and email security systems.
Provide security consulting on medium to large-scale projects to ensure alignment with corporate security policies, standards, and architecture.
Apply subject matter expertise in endpoint and email security to implement controls supporting availability, integrity, confidentiality, threat modeling, monitoring, access management, and business continuity.
Engineer and support for both Endpoint and Email security platforms across Windows, macOS, and Linux environments, including:
- Endpoint Applications: CrowdStrike, Microsoft Defender, BitLocker, Eclypsium, Symantec Endpoint Protection, WinMagic, SecureDoc
- Email Security Applications: Proofpoint (Email Protection, TAP, DLP, Threat Response), FireEye/Mandiant Email Security (NX/EX or equivalent threat detection platforms)
Affirmatively assist in the development of automation and integrations to enhance operational efficiency, telemetry analysis, and threat response capabilities across endpoint and email security systems.
Provide security consulting on medium to large-scale projects to ensure alignment with corporate security policies, standards, and architecture.
Apply subject matter expertise in endpoint and email security to implement controls supporting availability, integrity, confidentiality, threat modeling, monitoring, access management, and business continuity.
Threat Detection, Monitoring and Incident Response:
- Lead and participate in endpoint and email-related security incident response, including investigation, containment, and recovery.
- Investigate phishing, malware delivery, and email-based attacks, including analysis of headers, payloads, URLs, and attachments.
- Conduct technical investigations and post-incident digital forensics to identify root causes and recommend mitigation strategies.
- Review and correlate endpoint telemetry, email logs, and security alerts to identify anomalies and threats.
- Identify vulnerabilities, perform risk assessments, and evaluate remediation strategies across endpoint and email ecosystems.
- Collaborate with incident response, threat intelligence, SOC, and infrastructure teams to investigate and remediate threats.
- Perform advanced troubleshooting and root cause analysis across endpoint and email security platforms.
- Continuously improve security posture through policy tuning, detection engineering, and proactive threat hunting.
- Collaborate with email security teams, SOC, and messaging infrastructure teams to ensure cohesive threat defense.
Documentation, Standards and Continuous Improvement:
- Create and maintain technical documentation, security standards, and training materials.
- Translate complex security requirements into actionable, scalable technical solutions.
- Stay current with emerging threats, particularly phishing, business email compromise (BEC), and advanced malware campaigns.
- Promote a security-first mindset and contribute to a culture of continuous improvement and operational excellence.
Required Qualifications
- 4 plus years of Information Security Engineering experience, or equivalent demonstrated through work experience, training, military experience, or education.
- 2 plus years of Windows Administration experience.
- 2 plus years of hands-on experience with EDR tools (CrowdStrike, Defender, etc.).
- Experience supporting enterprise email security platforms (Proofpoint, FireEye, or similar).
- 2 plus years of PowerShell or Python experience.
- 2 plus years of SDLC experience.
- 1 plus year of Splunk experience.
- Experience analyzing email threats (phishing, malware, URL-based attacks).
- Flexibility to support implementations outside of standard business hours.
- Ability to deliver high-quality technical artifacts and engineering solutions aligned with business objectives.
Desired Qualifications
- Experience working with REST APIs.
- Experience with Network Routing.
- Bachelor’s or higher degree in Computer Science, Information Security, or related field.
- Certifications such as CISSP, GIAC, OSCP, or Microsoft Certified: Security Operations Analyst.
- Familiarity with cloud security (AWS, Azure, GCP) and hybrid environments.
- Experience integrating email security, EDR/XDR, and SIEM platforms.
- Knowledge of Zero Trust architecture, secure device onboarding, and network segmentation.
- Understanding of security frameworks (e.g., NIST, ISO 27001, MITRE ATT&CK).
- Experience with phishing detection, email authentication (DMARC, DKIM, SPF), and BEC prevention strategies.
- Ability to collaborate across technical and non-technical teams and clearly document technical requirements.
Note
The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment.
Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.