Staff Information Security Engineer leading advanced threat detection and incident response at Proofpoint. Shaping strategies for complex security investigations and mentoring team members.
Responsibilities
Serve as a Level 3 / Staff escalation point for high-severity incidents.
Lead investigations into APTs, ransomware, insider threats, and cloud compromises.
Act as incident commander and coordinate response efforts.
Participate in 24/7 on-call incident response.
Lead threat hunting across endpoint, network, identity, and cloud.
Operationalize threat intelligence into detections and response.
Design and improve detections across SIEM, EDR, and SOAR.
Automate incident triage and response workflows.
Drive post-incident reviews and continuous improvement.
Mentor team members and influence security strategy.
Requirements
12+ years in Incident Response, DFIR, Threat Hunting, or Security Operations.
Deep expertise in incident response, threat hunting, and threat intelligence.
Strong knowledge of MITRE ATT&CK and adversary TTPs.
Experience with SIEM, EDR, SOAR, and cloud security.
Scripting experience (Python, PowerShell, or Bash).
Strong communication and leadership skills.
US Citizen.
Benefits
Competitive compensation
Comprehensive benefits
Career success on your terms
Flexible work environment
Annual wellness and community outreach days
Always on recognition for your contributions
Global collaboration and networking opportunities
Job title
Staff Information Security Engineer – Threat Defense, Automation
Microsoft Success Manager helping partners grow secure, scalable Microsoft practices across ANZ. Championing Microsoft security solutions and supporting partner success strategies in the region.
Assistant AVP overseeing a 5 - member team for Access Management services in Pune and Mumbai, ensuring high standards of service delivery and compliance.
Own global security systems infrastructure for QVC, managing access control and networked security systems across multiple regions. Collaborate with IT to ensure security and technology initiatives meet organizational needs.
Sales Account Manager growing ADAPTIT Cybersecurity business in Greece and Cyprus. Responsible for client relations, sales pipeline, and collaboration with the cybersecurity team.
Information Security Engineer focusing on Identity & Access Management and SSO at Westfield. Design, operate, and mature enterprise authentication and federation capabilities.
Cyber Security Engineer responsible for operational support and development activities with Ping Identity. Collaborate with global teams to strengthen cybersecurity and improve customer satisfaction.
Application Security Specialist focusing on security in software development lifecycle at Insight Investment in Manchester, driving DevSecOps practices across teams.
Cyber Security Engineer supporting mission - critical DoD contract at CACI. Involves reviewing infrastructure changes and implementing security measures in a cloud - based environment.
Security Incident Management Analyst coordinating information security incidents. Overseeing cyber incident response and providing guidance to senior management within a leading industrial software company.
Customer Security Engineer managing end - to - end pentesting services at Aikido Security. Ensuring customer value and addressing vulnerabilities for a developer - first security product.