Staff Information Security Engineer (Incident Response)
Proofpoint
Job Summary
Proofpoint is seeking a Staff Information Security Engineer to join its Cyber Incident Response Team (CIRT), managing and responding to security incidents globally. This role involves acting as an L3 escalation point for high-severity incidents, leading complex investigations into advanced cyber threats, proactively hunting for hidden threats using intelligence and analytics, and designing automated workflows to enhance security event triage and response. The engineer will also collaborate on improving detection capabilities and performing root cause analysis.
Must Have
- Act as the L3 escalation point for high-severity security incidents
- Lead complex investigations into advanced cyber threats
- Proactively hunt for hidden threats within enterprise networks
- Design and implement automated workflows to enhance security event triage and response
- Leverage SOAR (Security Orchestration, Automation, and Response) platforms
- Collaborate with security architects and engineers to enhance detection and response capabilities
- Perform root cause analysis on security incidents
- Extensive hands-on experience in Cybersecurity Incident Response or Security Operations
- Proven background in SOC operations, SIEM, threat intelligence, and digital forensics
- Expertise in investigating malware, phishing, web attacks, insider threats, and advanced persistent threats (APTs)
- Experience working with security automation and orchestration tools (SOAR)
- Familiarity with scripting languages such as Python, PowerShell, or Bash for security automation
- Solid understanding of MITRE ATT&CK framework, TTPs (Tactics, Techniques, and Procedures), and cyber kill chain
Good to Have
- Hands-on experience with cloud security (AWS, Azure, GCP)
- Certifications such as GCIH, GCFA, CISSP, CISM, or OSCP
Perks & Benefits
- Competitive compensation
- Comprehensive benefits
- Learning & Development programs (leadership, professional development workshops, stretch project assignments, mentoring)
- Flexible work environment
- Annual wellness and community outreach days
- Always on recognition for your contributions
- Global collaboration and networking opportunities
Job Description
About Us:
We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead of bad actors and safeguard the digital world. Join us in our pursuit to defend data and protect people.
How We Work:
At Proofpoint, you’ll be part of a global team that breaks barriers to redefine cybersecurity, guided by our BRAVE core values: Bold in how we dream and innovate, Responsive to feedback, challenges, and opportunities, Accountable for results and best-in-class outcomes, Visionary in future-focused problem-solving, Exceptional in execution and impact.
The Role
Proofpoint is seeking a Staff Information Security Engineer to join our Cyber Incident Response Team (CIRT), responsible for managing and responding to security incidents across our global operations. This position will report to our Security Operations Manager and will serve as an escalation point for our 24/7 Security Operations Centre (SOC) and play a key role in the automation, orchestration, and enhancement of our security incident response capabilities.
This position requires deep expertise in cybersecurity. If you thrive in a role where you can actively defend against cyber threats, conduct threat hunting, and drive security automation, this opportunity is for you.
Your Day To Day
- Incident Response & Escalation: Act as the L3 escalation point for high-severity security incidents within the global 24/7 SOC
- Lead complex investigations into advanced cyber threats, including malware outbreaks, targeted attacks, and persistent threats
- Threat Hunting & Threat Assessment: Proactively hunt for hidden threats within enterprise networks using threat intelligence and behavioural analytics.
- Security Automation & Orchestration: Design and implement automated workflows to enhance security event triage and response.
- Leverage SOAR (Security Orchestration, Automation, and Response) platforms to streamline incident response.
- Security Tooling & Continuous Improvement: Collaborate with security architects and engineers to enhance detection and response capabilities.
- Perform root cause analysis on security incidents and recommend improvements to security controls
Qualifications
- Extensive hands-on experience in Cybersecurity Incident Response or Security Operations
- Proven background in SOC operations, SIEM, threat intelligence, and digital forensics.
- Expertise in investigating malware, phishing, web attacks, insider threats, and advanced persistent threats (APTs)
- Experience working with security automation and orchestration tools (SOAR).
- Familiarity with scripting languages such as Python, PowerShell, or Bash for security automation
- Solid understanding of MITRE ATT&CK framework, TTPs (Tactics, Techniques, and Procedures), and cyber kill chain
Desired
- Hands-on experience with cloud security (AWS, Azure, GCP) is a plus
- Certifications such as GCIH, GCFA, CISSP, CISM, or OSCP are highly desirable
#LI-CB1
Why Proofpoint? At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you’ll love working with us:
• Competitive compensation
• Comprehensive benefits
• Learning & Development: We are committed to the growth and development of our team members, offering a range of programs including leadership and professional development workshops, stretch project assignments, and mentoring opportunities to help employees reach their full potential.
• Flexible work environment: [Remote options, hybrid schedules, flexible hours, etc.].
• Annual wellness and community outreach days
• Always on recognition for your contributions
• Global collaboration and networking opportunities
Our Culture:
Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone. We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to accessibility@proofpoint.com.
How to Apply Interested? Submit your application here https://www.proofpoint.com/us/company/careers. We can’t wait to hear from you!
Proofpoint Best Places to Work Awards
Proofpoint has been honored with six Best Places to Work Awards in 2024 by workplace culture leader Comparably, including Best Company Career Growth, Best Company Outlook, Best Global Culture, Best Engineering Teams, Best Sales Teams, and Best HR Teams.
Read More
About Us
We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead of bad actors and safeguard the digital world. Join us in our pursuit to defend data and protect people.
Our BRAVE Values:
At Proofpoint, we are BRAVE in everything we do, and our values aren’t just words—they shape how we work, collaborate, and grow.
We seek people who are bold enough to challenge the status quo, responsive in the face of ever-evolving threats, and accountable for delivering real impact.
We value those with a visionary mindset who anticipate what’s next and push cybersecurity forward, and we celebrate exceptional execution that ensures we continue to defend data and protect people.
Proofpoint is an equal opportunity employer, we hire without consideration to race, religion, creed, color, national origin, age, gender, sexual orientation, marital status, veteran status or disability.
Read More
Build Meaningful Connections:
Find your network, your allies, and your biggest fans. We know that work is simply better when you’re surrounded by people who inspire you—who share ideas, cheer you on, and genuinely want to see you succeed. That’s why we offer social circles, sponsored networks, and connection points across teams and time zones—to help you find your people, build your community, and thrive together.
Read More
Do Your Best Work:
This isn’t just a job—it’s a mission to protect people and defend data in a world that never slows down. We’re building the future of human-centric cybersecurity, and that future belongs to all of us. We take ownership, move fast, and hold ourselves accountable—because that’s what it takes to stay ahead. And we do it together, winning as one.
Read More
Build success on your terms:
Be empowered to reach your full potential through meaningful challenges and personalized support—designed around you and your goals. Whether you're growing as a leader or leveling up from great to exceptional as an individual contributor, we’re here to help you get there.
Read More