Staff Cyber Information Security Engineer

Sunnyvale, CA, United States

Proofpoint

Proofpoint helps protect people, data and brands against cyber attacks. Offering compliance and cybersecurity solutions for email, web, cloud, and more.

View all jobs at Proofpoint

Apply now Apply later

It's fun to work in a company where people truly BELIEVE in what they're doing!

We're committed to bringing passion and customer focus to the business.

About Proofpoint

At Proofpoint, we are committed to protecting organizations and individuals from cyber threats through innovative security solutions. Our mission is to safeguard our customers from advanced threats, phishing attacks, and data breaches with cutting-edge technology and a global team of security experts.

Role Overview

We are seeking an experienced Cyber Incident Response Security Engineer to join our global security team in Sunnyvale, CA and Draper, UT. This is a critical role within our Cyber Incident Response Team (CIRT), responsible for managing and responding to security incidents across our global operations. You will serve as an escalation point for our 24/7 Security Operations Center (SOC) and play a key role in the automation, orchestration, and enhancement of our security incident response capabilities. This position requires deep expertise in cybersecurity, strong analytical skills, and the ability to work collaboratively in a fast-paced environment. If you thrive in a role where you can actively defend against cyber threats, conduct threat hunting, and drive security automation, this opportunity is for you.

Key Responsibilities:

  • Incident Response & Escalation:

    • Act as the Level 3 escalation point for high-severity security incidents within the global 24/7 SOC.
    • Lead complex investigations into advanced cyber threats, including malware outbreaks, targeted attacks, and persistent threats.

    • Provide expert-level guidance on containment, mitigation, and remediation strategies.
       

  • Threat Hunting & Threat Assessment:

    • Proactively hunt for hidden threats within enterprise networks using threat intelligence and behavioral analytics.

    • Develop and refine threat detection rules to improve SOC visibility.

    • Assess emerging threats and provide actionable recommendations to enhance security posture.
       

  • Security Automation & Orchestration:

    • Design and implement automated workflows to enhance security event triage and response.

    • Leverage SOAR (Security Orchestration, Automation, and Response) platforms to streamline incident response.

    • Work with SIEM (Security Information and Event Management) tools to optimize log ingestion and alerting mechanisms.
       

  • Security Tooling & Continuous Improvement:

    • Collaborate with security architects and engineers to enhance detection and response capabilities.

    • Perform root cause analysis on security incidents and recommend improvements to security controls.

    • Stay updated on industry best practices and evolving attack techniques to ensure effective defenses.

Required Qualifications & Experience

  • Extensive hands-on experience in Cybersecurity Incident Response or Security Operations.
  • Must be a US Citizen.
  • Strong background in SOC operations, SIEM, threat intelligence, and digital forensics. Expertise in investigating malware, phishing, web attacks, insider threats, and advanced persistent threats (APTs).
  • Experience working with security automation and orchestration tools (SOAR).
  • Familiarity with scripting languages such as Python, PowerShell, or Bash for security automation.
  • Strong understanding of MITRE ATT&CK framework, TTPs (Tactics, Techniques, and Procedures), and cyber kill chain.
  • Hands-on experience with cloud security (AWS, Azure, GCP) is a plus.
  • Certifications such as GCIH, GCFA, CISSP, CISM, or OSCP are highly desirable.
  • Ability to work in a fast-paced, global environment and collaborate with cross-functional teams.

Why Proofpoint

Protecting people is at the heart of our award-winning lineup of cybersecurity solutions, and the people who work here are the key to our success.  We’re a customer-focused and a driven-to-win organization with leading-edge products. We are an inclusive, diverse, multinational company that believes in culture fit, but more importantly ‘culture-add’, and we strongly encourage people from all walks of life to apply.

We believe in hiring the best and the brightest to help cultivate our culture of collaboration and appreciation. Apply today and explore your future at Proofpoint! #LifeAtProofpoint

#LI-AN2

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!

Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and/or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.

Base Pay Ranges:

SF Bay Area, New York City Metro Area:

Base Pay Range: 182,175.00 - 267,190.00 USD

California (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska:

Base Pay Range: 146,550.00 - 214,940.00 USD

All other cities and states excluding those listed above:

Base Pay Range: 132,975.00 - 195,030.00 USD
Apply now Apply later
Job stats:  0  0  0

Tags: Analytics Automation AWS Azure Bash CISM CISSP Cloud Cyber Kill Chain Forensics GCFA GCIH GCP Incident response Malware MITRE ATT&CK OSCP PowerShell Python Scripting SIEM SOAR SOC Threat detection Threat intelligence TTPs

Perks/benefits: Competitive pay Equity / stock options Flex hours Flex vacation Startup environment Transparency

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.