Talent.com
Staff Security Research Engineer
Staff Security Research EngineerProofpoint • Italy, TX, US
Staff Security Research Engineer

Staff Security Research Engineer

Proofpoint • Italy, TX, US
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Overview

About Us : We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We're driven by a mission to stay ahead of bad actors and safeguard the digital world. Join us in our pursuit to defend data and protect people.

How We Work : At Proofpoint, you'll be part of a global team that breaks barriers to redefine cybersecurity, guided by our BRAVE core values : Bold in how we dream and innovate, Responsive to feedback, challenges, and opportunities, Accountable for results and best-in-class outcomes, Visionary in future-focused problem-solving, Exceptional in execution and impact.

Corporate Overview

Proofpoint is a leading cybersecurity company protecting organizations' greatest assets and biggest risks : vulnerabilities in people. With an integrated suite of cloud-based solutions, Proofpoint helps companies around the world stop targeted threats, safeguard their data, and make their users more resilient against cyber-attacks. Leading organizations of all sizes, including more than half of the Fortune 1000, rely on Proofpoint for people-centric security and compliance solutions mitigating their most critical risks across email, the cloud, social media, and the web. We are singularly devoted to helping our customers protect their greatest assets and biggest security risk : their people. That's why we're a leader in next-generation cybersecurity. Protection Starts with People.

Staff Security Research Engineer

Your day-to-day

  • Design and develop software using a variety of languages, primarily Python, with little external guidance, while providing technical leadership to guide other software engineers on the team
  • Modify existing web-based UI for internal tools to maintain and extend the sandbox submission and report UI for Proofpoint threat researchers to use
  • Some work requires skill in writing C or C++ for low level interactions with the OS
  • Develop and maintain web browser interaction capabilities using Chrome web driver
  • Analyze and reverse engineer JavaScript that fingerprints web browser artifacts to identify sandbox web browsers or instrumentation, and innovate solutions to defeat those checks
  • Familiarity with analyzing web front-end and the Document Object Model (DOM)
  • Develop and maintain software for processing network traffic, including TLS decryption and processing PCAP files
  • Work closely with threat analysts and detection engineers who research threat actors and write detection rules which run on the systems you develop
  • As needed, create new detection languages and systems that allow threat researchers to develop detection rules
  • Add features to existing threat detection languages to allow greater flexibility by threat researchers to automate interactions with websites and detect threat patterns
  • Make use of AI Large Language Models as appropriate to enhance threat detection pipelines, produce samples to test evasion countermeasures, and make sound decisions about when applying AI is a benefit vs. a detriment to achieving goals
  • Design and develop automation pipelines to turn manual tasks into automated scripts
  • Stay abreast of a constantly evolving threat landscape
  • Understand the latest tactics, techniques, and procedures used by threat actors to bypass detection environments, especially URL sandbox fingerprinting / detection / evasion techniques used by threat actors
  • As needed, provide expert assistance and support to threat researchers and analysts as they analyze phishing websites, threat detection evasion techniques, and security research or red team demonstrations of new evasion techniques
  • As needed to support sandbox countermeasure development, reverse engineering malware executable files for Windows (note : primary malware reverse engineering responsibilities rest on other job roles and are not expected regularly for this role)
  • Apply critical thinking skills to identify the most efficient and effective way to mitigate threats and evasions
  • Work effectively as part of a remote team using chat, video chat and conference calls
  • Work with other engineering teams, defining requirements, for continuous improvement of critical detection capabilities

What you bring to the team

As a Security Research Engineer on Proofpoint's Threat Research team, you'll be part of an amazing, collaborative, industry-leading team focused on tracking threat actors, malware, phishing, and TTPs and responding to the quickly changing threat landscape with innovative software that detects and prevents threats from reaching Proofpoint customers. If you enjoy keeping abreast of and analyzing attacker techniques, malware and phishing campaigns, and using that knowledge to counteract those threats with innovative software solutions, then this is the role for you.

  • A passion for threat research and a well-rounded yet deep understanding of the security threat landscape and actor TTPs, especially understanding how to develop countermeasures for threat actor evasions and sandbox detection techniques
  • Ability to write production-grade, reliable Python code with instrumentation that supports observability and monitoring of performance and errors is required
  • Experience developing software using Docker containers is required
  • Experience developing web browser automation is required
  • Experience analyzing network traffic for threat detection and a solid understanding of TLS, HTTP, and other network protocols used by malware is required
  • Willing and able to work independently and collaboratively as part of a distributed team of industry-leading security researchers
  • Ability to perform the above in a fully remote work environment
  • The following skills and experience are nice to have, but candidates lacking them should still apply :

  • Experience with C and C++ is a plus
  • Experience developing Windows API hooks and knowing how to research undocumented Windows API internal functions is a plus
  • Experience writing malware behavior signatures
  • Some experience analyzing malware using a debugger, and willingness to learn is a plus
  • Experience with statically reverse engineering malware using IDA Pro, Ghidra, Binary Ninja, or other reverse engineering tools is a plus, although being an expert is not required
  • Ability to accurately interpret the forensic output of dynamic analysis (sandbox) environments
  • Experience with a variety of publicly-available malware sandboxes (for example : Cuckoo, Joe Sandbox, Any Run, Triage, etc.)
  • Additional Information

  • Travel : 1% - 10% (flexible) mainly for team collaboration or security conferences
  • Location : Canada (Remote), US (Remote), Argentina (Remote), UK (Remote), Ireland (Remote), Germany (Remote), France (Remote), Switzerland (Remote)
  • Must be able to work during business hours local to your time-zone
  • Why Proofpoint

    As a customer focused and driven-to-win organization with leading edge products, there are many exciting reasons to join the Proofpoint team. We believe in hiring the best the brightest and cultivating a culture of collaboration and appreciation. As we continue to grow and expand globally, we understand that hiring the right people and developing great teams is key to our success! We are a multi-national company with locations in many countries, with each location contributing to Proofpoint's amazing culture! #LI-AN1

    Why Proofpoint? At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you'll love working with us :

  • Competitive compensation
  • Comprehensive benefits
  • Learning & Development : We are committed to the growth and development of our team members, offering a range of programs including leadership and professional development workshops, stretch project assignments, and mentoring opportunities to help employees reach their full potential.
  • Flexible work environment : Remote options, hybrid schedules, flexible hours, etc.
  • Annual wellness and community outreach days
  • Always on recognition for your contributions
  • Global collaboration and networking opportunities
  • Our Culture :

    Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone. We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to accessibility@proofpoint.com. How to Apply Interested? Submit your application here : proofpoint.com / us / company / careers. We can't wait to hear from you!

    Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and / or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.

    Base Pay Ranges :

    SF Bay Area, New York City Metro Area :

    Base Pay Range : 194,475.00 - 285,230.00 USD

    California (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska :

    Base Pay Range : 162,375.00 - 238,150.00 USD

    All other cities and states excluding those listed above :

    Base Pay Range : 148,425.00 - 217,690.00 USD

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Staff Security Engineer • Italy, TX, US

    Job_description.internal_linking.related_jobs
    Product Security Engineer

    Product Security Engineer

    VirtualVocations • Fort Worth, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Product Security Engineer to maintain and enhance its Product Security Program.Key Responsibilities Lead Product Security Vulnerability Management efforts and ensure ti...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Security Architect Engineer

    Security Architect Engineer

    VirtualVocations • Fort Worth, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Architect / Engineer to design and implement secure enterprise architectures for a Department of Defense information system. Key Responsibilities Lead the design ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Staff Security Engineer - Industrial Control Systems

    Staff Security Engineer - Industrial Control Systems

    Union Technologies • Dallas, TX, US
    serp_jobs.job_card.full_time
    Union Technologies is reindustrializing America’s defense manufacturing base with a first-of-its-kind Factories-as-a-Stockpile™ model, integrating advanced robotics, manufacturing, and ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Security Systems Field Engineer

    Security Systems Field Engineer

    Digi Security Systems • Dallas, TX, US
    serp_jobs.job_card.full_time
    We've built our reputation on innovation and reliable service, and we're known as the industry's experts.Field Engineer to join our operations in the. This person will be responsible for...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    VirtualVocations • Arlington, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer to support corporate security and information technology operations.Key Responsibilities Champion application security program strategy and implementa...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Application Security Engineer

    Application Security Engineer

    VirtualVocations • Arlington, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for an Application Security Engineer - 100% Remote.Key Responsibilities Develop and implement a complete security stack for endpoint management, vulnerability management, and...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Sr. Security Engineer

    Sr. Security Engineer

    Varo Bank • Dallas, TX, US
    serp_jobs.job_card.full_time
    Varo is an entirely new kind of bank.All digital, mission-driven, FDIC insured and designed for the way our customers live their lives. We are looking for an experienced Senior Security Engineer res...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Staff Product Security Engineer - AI

    Staff Product Security Engineer - AI

    Match Group • Dallas, TX, US
    serp_jobs.job_card.full_time
    Match Group is on a mission to change the world, bringing people together and facilitating millions of connections that otherwise might not have been possible. With tens of millions of users and an ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Security & Technology Engineer

    Security & Technology Engineer

    M.E.P. Consulting Engineers, Inc • Irving, TX, US
    serp_jobs.job_card.full_time
    Security & Technology Engineer.Las Colinas (Irving), Texas 75063.Have a passion for designing security systems? Do you want to help prevent crime in buildings? As part of our team, this positio...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Surgical Technologist

    Surgical Technologist

    Baylor Waxahachie (13704) • WAXAHACHIE, Texas, United States
    serp_jobs.job_card.full_time
    Baylor Scott & White Surgicare Waxahachie is hiring a Surgical Technologist!.Position requires weekdays only no holidays, weekends, nights or calls •. Welcome to Baylor Surgicare Waxahachie.Why Ch...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Nuclear Cyber Security Engineer

    Nuclear Cyber Security Engineer

    VirtualVocations • Mesquite, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Lead Cyber Security Engineer 1 - Nuclear.Key Responsibilities Reviewing Critical Digital Asset (CDA) determinations and assessments for technical accuracy Supporting i...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Security Engineer (Dallas)

    Security Engineer (Dallas)

    Insight Global • Dallas, TX, US
    serp_jobs.job_card.full_time +1
    Job Title : Remote Security Engineer.We are seeking a hands-on Security Engineer to serve as the internal subject matter expert (SME) supporting a large managed security services partnership with HC...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    Secur-Serv • Fort Worth, TX, US
    serp_jobs.job_card.full_time
    Secur-Serv is a leading managed services provider of IT, print, and hardware services, with a security focus at the core of every service. Secur-Serv provides nationwide, on-site service to business...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Security Engineer FIPS Certified

    Security Engineer FIPS Certified

    VirtualVocations • Arlington, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer, FIPS / CC (Mobile Devices).Key Responsibilities Lead the end-to-end validation process for IT products, including assessment, development of security t...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Security Engineer - Detection & Response

    Security Engineer - Detection & Response

    Nerdy • Dallas, TX, US
    serp_jobs.job_card.full_time
    You are an AI-powered Security Engineer responsible for identifying and responding to malicious or suspicious activity across our environment with speed and confidence. This role leads the engineeri...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Lead Threat Detection Engineer

    Lead Threat Detection Engineer

    McKesson Corporation • Irving, TX, US
    serp_jobs.job_card.full_time
    McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.We are known for delivering insights, products, and services that make quality care more accessibl...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    AI Security Engineer

    AI Security Engineer

    VirtualVocations • Mesquite, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer with a focus on AI.Key Responsibilities Support ongoing security operations including monitoring, incident response, and risk assessment Assess and m...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    Insight Global • Dallas, TX, United States
    serp_jobs.job_card.full_time
    Job Title : Remote Security Engineer.We are seeking a hands-on Security Engineer to serve as the internal subject matter expert (SME) supporting a large managed security services partnership with HC...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted