Senior Cyber Threat Defense - Security Operations Engineer
Proofpoint · Draper, UT · 1 mo ago
Information TechnologyFull-time
About the role
We are seeking an experienced Senior Cyber Threat Defense - Security Operations Engineer to join our global security team in Draper, UT.
This critical role sits within the Global Information Security Operation team and is responsible for investigating and responding to sophisticated security incidents across Proofpoint's global operations.
Responsibilities
- Own Level 3 escalation for high-severity and technically complex incidents within the global 24/7 SOC.
- Lead major investigations involving malware, ransomware, phishing, identity attacks, insider threats, cloud compromise, and advanced persistent threats.
- Set containment, eradication, recovery, remediation, and post-incident improvement strategy, balancing risk and business impact.
- Direct response across Security, IT, Cloud Engineering, Legal, Privacy, and business leaders, and communicate incident status and decisions to executives.
- Participate in a scheduled on-call rotation and provide after-hours support for critical security incidents, including nights, weekends, and holidays as required.
Qualifications
- Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations.
- U.S. citizenship.
- Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, and security monitoring.
- Experience investigating malware, phishing, identity attacks, cloud compromise, insider threats, data loss, and advanced persistent threats.
- Hands-on experience with SOAR platforms, APIs, and scripting languages such as Python, PowerShell, or Bash.
- Strong understanding of the MITRE ATT&CK framework, attacker tactics, techniques, and procedures, and the cyber kill chain.
- Experience applying threat modeling methods such as STRIDE, attack trees, or MITRE ATT&CK to enterprise or cloud systems.
- Experience creating or tuning detection rules, hunting queries, and response playbooks.
- Working knowledge of cloud security across AWS, Microsoft Azure, or Google Cloud Platform.
- Proven ability to own technical strategy, influence architecture and control decisions, and drive cross-functional security improvements.
- Strong executive communication, analytical, troubleshooting, and documentation skills, with the ability to make sound decisions during high-pressure incidents.