Cyber Incident Response Security Engineer at Proofpoint, responsible for incident response and security automation. Collaborating globally to defend against cyber threats and enhance incident response capabilities.
Responsibilities
Act as the Level 3 escalation point for high-severity security incidents within the global 24/7 SOC.
Lead complex investigations into advanced cyber threats, including malware outbreaks, targeted attacks, and persistent threats.
Provide expert-level guidance on containment, mitigation, and remediation strategies.
Proactively hunt for hidden threats within enterprise networks using threat intelligence and behavioral analytics.
Develop and refine threat detection rules to improve SOC visibility.
Assess emerging threats and provide actionable recommendations to enhance security posture.
Design and implement automated workflows to enhance security event triage and response.
Leverage SOAR (Security Orchestration, Automation, and Response) platforms to streamline incident response.
Work with SIEM (Security Information and Event Management) tools to optimize log ingestion and alerting mechanisms.
Collaborate with security architects and engineers to enhance detection and response capabilities.
Perform root cause analysis on security incidents and recommend improvements to security controls.
Stay updated on industry best practices and evolving attack techniques to ensure effective defenses.
Requirements
12 yrs + hands-on experience in Cybersecurity Incident Response or Security Operations.
Must be a US Citizen.
Strong background in SOC operations, SIEM, threat intelligence, and digital forensics.
Expertise in investigating malware, phishing, web attacks, insider threats, and advanced persistent threats (APTs).
Experience working with security automation and orchestration tools (SOAR).
Familiarity with scripting languages such as Python, PowerShell, or Bash for security automation.
Strong understanding of MITRE ATT&CK framework, TTPs (Tactics, Techniques, and Procedures), and cyber kill chain.
Hands-on experience with cloud security (AWS, Azure, GCP) is a plus.
Certifications such as GCIH, GCFA, CISSP, CISM, or OSCP are highly desirable.
Ability to work in a fast-paced, global environment and collaborate with cross-functional teams.
Information Security Consultant managing security standards implementation at LUZA Group in Lisbon, Portugal. Handling analysis of risk and supporting audits while working in a hybrid model.
Senior Cybersecurity Analyst at Boeing performing advanced cybersecurity assessments and risk evaluations for third - party vendors. Focusing on automation, lean processes, and collaborating with key stakeholders across departments.
Cybersecurity Manager ensuring regulatory compliance in information security within the Mexican framework. Collaborating with technology teams to strengthen governance, risk, and control model.
CISA Auditor focusing on cloud security audits for a Zurich - based international bank. Ensuring cybersecurity and identifying vulnerabilities in IT systems with risk - oriented audits.
Cybersecurity Specialist managing compliance for DoD security transition to Zero Trust Architecture. Involves overseeing RMF activities and ensuring ATO deadlines are met in cloud environments.
Engineer II responsible for managing enterprise customer support in Security Engineering. Focused on troubleshooting and diagnosing security incidents in a hybrid work environment.
Guest Safety Agent at HRI Hospitality ensuring safety and hospitality for guests and managing outlet spaces. Maintaining a secure environment while engaging with guests and visitors in New Orleans.
Cybersecurity Architect for Saint Louis University developing and assessing security strategies and architecture. Ensuring secure IT services through effective security technologies and practices.
Senior Commercial Manager developing and executing Cyber Security strategies, managing client portfolios and leading complex negotiations in São Paulo.
Security Officer responsible for maintaining safety at WarHorse Casino. Enforcing policies, responding to incidents, and providing customer service to guests.