Proofpoint is a leading cybersecurity company protecting organizations' greatest assets and biggest risks vulnerabilities in people. With an integrated suite of cloud-based solutions, Proofpoint helps companies around the world stop targeted threats, safeguard their data, and make their users more resilient against cyber-attacks.
Job Description :
We are seeking a Staff Security Research Engineer to join our Threat Research team. As a Security Research Engineer, you will be part of an amazing, collaborative, industry-leading team focused on tracking threat actors, malware, phishing, and TTPs and responding to the quickly changing threat landscape with innovative software that detects and prevents threats from reaching Proofpoint customers.
Responsibilities :
- Design and develop software using a variety of languages, primarily Python, with little external guidance, while providing technical leadership to guide other software engineers on the team
- Develop and maintain web browser interaction capabilities using Chrome web driver
- Analyze and Reverse Engineer JavaScript that fingerprints web browser artifacts to identify sandbox web browsers or instrumentation, and innovate solutions to defeat those checks
- Familiarity with analyzing web front-end and the Document Object Model (DOM)
- Develop and maintain software for processing network traffic, including TLS decryption and processing PCAP files
- Work closely with threat analysts and detection engineers who research threat actors and write detection rules which run on the systems you develop
- Make use of AI Large Language Models as appropriate to enhance threat detection pipelines, produce samples to test evasion countermeasures, and make sound decisions about when applying AI is a benefit vs. a detriment to achieving goals
- Stay abreast of a constantly evolving threat landscape
- Understand the latest tactics, techniques, and procedures used by threat actors to bypass detection environments, especially URL sandbox fingerprinting / detection / evasion techniques used by threat actors
Requirements :
A passion for threat research and a well-rounded yet deep understanding of the security threat landscape and actor TTPs, especially understanding how to develop countermeasures for threat actor evasions and sandbox detection techniquesAbility to write production-grade, reliable Python code with instrumentation that supports observability and monitoring of performance and errors is requiredExperience developing software using Docker containers is requiredExperience developing web browser automation is requiredExperience analyzing network traffic for threat detection and a solid understanding of TLS, HTTP, and other network protocols used by malware is requiredWhat We Offer :
Competitive compensationComprehensive benefitsLearning & Development opportunitiesFlexible work environment [Remote options, hybrid schedules, flexible hours, etc.].Annual wellness and community outreach daysJ-18808-Ljbffr