Sr. Security Research Engineer – Proofpoint
Apply to join the Threat Research team at Proofpoint. This highly technical role has a direct and real-time impact protecting Proofpoint customers.
About Us
Proofpoint is a leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We focus on staying ahead of bad actors and safeguarding the digital world. Join us to defend data and protect people.
The Role
As a Senior Security Research Engineer on the Threat Research team, you will track threat actors, malware, phishing, and TTPs to develop static and dynamic signatures that detect and prevent threats on a massive scale. Your work directly influences the efficacy of Proofpoint products, the quality of our intelligence, and the protection of our customers.
Your day-to-day
- Stay abreast of a constantly evolving threat landscape, including credential phishing.
- Analyse malware, malicious documents, and malicious URLs provided by internal and external sources.
- Conduct in-depth analysis of email messages to detect and classify threats such as business email compromise (BEC), phishing, and other malicious campaigns.
- Apply critical thinking to identify the most efficient and effective mitigation for analysed threats.
- Develop, test, and deploy static and / or behavioural signatures to mitigate the analysed threat.
- Identify, prioritize, and fill coverage gaps for relevant threats to minimise customer impact.
- Be on-call to respond to customer escalations that cannot be addressed by customer support.
- Work effectively as part of a remote team using chat, video chat, and conference calls.
- Collaborate with engineering teams to define requirements for continuous improvement of critical detection capabilities.
What You Bring to the Team
A passion for threat research and a deep understanding of the security threat landscape.Demonstrable knowledge of malware, credential phishing, TTPs, and experience overcoming bypass techniques.Experience proactively identifying, responding to, and defending against malware and credential phishing threats in production environments.Familiarity with browser internals and the Document Object Model.Broad understanding of malicious document formats (OLE, CDFv2, PDF, OpenOffice, RTF).Experience parsing and analysing malicious documents.Experience using sandbox environments for analysis.Ability to develop high-quality detection signatures based on malicious behaviour.Experience creating YARA and / or ClamAV signatures used in production.Regular expression expertise.Intermediate-level Python experience.Interest in sandbox engineering concepts and contributing to capability extensions.Interest in creating synthetic malicious samples to test capabilities.Willingness to work independently and collaboratively as part of a distributed research team.A self-directed, hard-working team player able to work remotely.Travel up to 10%.Location : Work from home in the United States; must work during local business hours.Benefits
Competitive compensation.Comprehensive benefits.Learning & Development programs, leadership workshops, and mentorship.Flexible work environment (remote options, hybrid schedules, flexible hours).Annual wellness and community outreach days.Recognition for contributions.Global collaboration and networking opportunities.Base Pay Ranges
SF Bay Area, New York City Metro Area : $161,625.00 – $237,050.00 USD
California (excluding SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska : $132,225.00 – $193,930.00 USD
All other cities and states : $120,525.00 – $176,770.00 USD
This role may be eligible for variable compensation and / or equity. Pay within these ranges varies and depends on job-related knowledge, skills, and experience.
How to Apply
Please submit your application at https : / / www.proofpoint.com / us / company / careers.
J-18808-Ljbffr