368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$136k – $214k per year
Location
Remote (United States)
Seniority
Senior · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Proofpoint is an enterprise cybersecurity and compliance company specializing in human-centric security solutions. Headquartered in Sunnyvale, California (and operating as a portfolio company of Thoma Bravo), the firm provides threat protection, information protection, identity threat defense, and cloud security platforms designed to mitigate risks targeting employees, email systems, and corporate data assets.

About Us:

Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people.

How We Work:

At Proofpoint you’ll be part of a global team that breaks barriers to redefine cybersecurity guided by our BRAVE core values:

Bold in how we dream and innovate

Responsive to feedback, challenges and opportunities

Accountable for results and best in class outcomes

Visionary in future focused problem-solving

Exceptional in execution and impact

About Proofpoint

At Proofpoint, we protect organizations and individuals from today's most advanced cyber threats. Through innovative security technologies, threat intelligence, and a global team of security experts, we help customers defend against phishing, malware, account compromise, insider threats, and data loss.

Role Overview

We are seeking an experienced Senior Cyber Threat Defense - Security Operations Engineer to join our global security team in Draper, UT. This critical role sits within the Global Information Security Operation team and is responsible for investigating and responding to sophisticated security incidents across Proofpoint's global operations.

You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC), own complex investigations and technical decisions, participate in a scheduled on-call rotation, and set direction for detection, investigation, response, threat modeling, and security automation. The role also supports selected AI-enabled capabilities, including Agentic SOC workflows and AI Data Loss Prevention (AI DLP).

Key Responsibilities:

Incident Response and Escalation

  • Own Level 3 escalation for high-severity and technically complex incidents within the global 24/7 SOC.
  • Lead major investigations involving malware, ransomware, phishing, identity attacks, insider threats, cloud compromise, and advanced persistent threats.
  • Set containment, eradication, recovery, remediation, and post-incident improvement strategy, balancing risk and business impact.
  • Direct response across Security, IT, Cloud Engineering, Legal, Privacy, and business leaders, and communicate incident status and decisions to executives.
  • Participate in a scheduled on-call rotation and provide after-hours support for critical security incidents, including nights, weekends, and holidays as required.

Threat Hunting, Modeling, and Detection Engineering

  • Proactively hunt for hidden threats across endpoints, identities, networks, cloud environments, SaaS applications, and data repositories.
  • Lead cross-functional threat modeling for new and existing systems, cloud services, and security workflows to identify abuse cases, attack paths, and control gaps.
  • Use threat intelligence and behavioral analytics to identify suspicious activity and emerging attack patterns.
  • Develop, test, tune, and maintain detection rules, correlations, hunting queries, and response use cases.
  • Translate threat intelligence and MITRE ATT&CK techniques into actionable detection and hunting use cases.

Security Automation and Orchestration

  • Define and implement automation strategy for alert enrichment, prioritization, triage, containment, notification, and remediation.
  • Use SOAR platforms and security APIs to streamline repeatable incident-response activities.
  • Develop scripts, integrations, and automation using Python, PowerShell, Bash, or similar languages.
  • Optimize SIEM log ingestion, normalization, correlation, retention, and alerting.

Emerging Security Capabilities

  • Support practical Agentic SOC use cases for alert triage, investigation enrichment, case documentation, and response under defined human oversight.
  • Help operate AI DLP controls that reduce sensitive-data exposure through generative AI applications and copilots.
  • Continuous Improvement
  • Own root-cause analysis and drive improvements to security controls, telemetry, processes, and architecture.
  • Partner with security architects and engineering leaders to set technical direction and evaluate detection and response technologies.
  • Mentor engineers and analysts, establish investigation standards, and raise technical capability across the SOC.

Required Qualifications and Experience

  • Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations.
  • U.S. citizenship.
  • Demonstrated experience leading major incidents and serving as the final technical escalation point for complex or high-severity security events.
  • Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, and security monitoring.
  • Experience investigating malware, phishing, identity attacks, cloud compromise, insider threats, data loss, and advanced persistent threats.
  • Hands-on experience with SOAR platforms, APIs, and scripting languages such as Python, PowerShell, or Bash.
  • Strong understanding of the MITRE ATT&CK framework, attacker tactics, techniques, and procedures, and the cyber kill chain.
  • Experience applying threat modeling methods such as STRIDE, attack trees, or MITRE ATT&CK to enterprise or cloud systems.
  • Experience creating or tuning detection rules, hunting queries, and response playbooks.
  • Working knowledge of cloud security across AWS, Microsoft Azure, or Google Cloud Platform.
  • Proven ability to own technical strategy, influence architecture and control decisions, and drive cross-functional security improvements.
  • Strong executive communication, analytical, troubleshooting, and documentation skills, with the ability to make sound decisions during high-pressure incidents.
  • Willingness and ability to participate in an on-call rotation and respond to critical incidents outside normal business hours, including nights, weekends, and holidays as required.

Preferred Qualifications

  • Experience with Agentic SOC, AI-assisted investigation, or AI DLP capabilities.
  • Experience with identity, cloud, or data detection and response technologies.
  • Experience leading incident simulations, purple-team exercises, or adversary-emulation activities.
  • Relevant certifications such as GCIH, GCFA, CISSP, CISM, OSCP, GIAC, or cloud-security certifications.

Why Proofpoint?

At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you’ll love working with us:

  • Competitive compensation

  • Comprehensive benefits

  • Career success on your terms

  • Flexible work environment

  • Annual wellness and community outreach days

  • Always on recognition for your contributions

  • Global collaboration and networking opportunities

Our Culture:

Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone.

We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to [email protected].

How to Apply

Interested? Submit your application along with any supporting information- we can’t wait to hear from you!

Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and/or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.

Base Pay Ranges:

SF Bay Area, New York City Metro Area:

Base Pay Range: 136,200.00 - 214,005.00 USD

California (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska:

Base Pay Range: 112,700.00 - 177,100.00 USD

All other cities and states excluding those listed above:

Base Pay Range: 101,600.00 - 159,720.00 USD
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Draper
$24k – $64k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Chennai
Python
Scala
SQL
TypeScript
JavaScript
Java
Python
pySpark
Java
Spring Boot
Databases
Apache Kafka
Databricks
AI/ML
AI Agents
Copilot
Google ADK
LLM
NLP
Prompt Engineering
Spark
Devin
Model Context Protocol
Frontend
Angular
React.js
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
OpenShift
GitHub
Analytics
ETL/ELT
Apply
$42k – $104k per year (Estimated) • In office • Internship • 5+ years exp
Bash
PowerShell
Python
DevOps
Amazon EC2
Amazon EKS
Ansible
AWS
AWS Lambda
Azure
CentOS Stream
Chef
CI/CD
CloudFormation
Configuration Management
Datadog
FinOps
GCP
Git
GitHub Actions
GitLab CI
Grafana
Hyper-V
Istio
Jenkins
Kubernetes
KVM
Linkerd
Platform Engineering
Prometheus
Puppet
Service Mesh
Splunk
Terraform
Ubuntu
VMWare
Windows Server
Amazon CloudWatch
Amazon ECS
Amazon S3
API Gateway
AWS Step Functions
GitHub
GitLab
IAM
Cybersecurity
GDPR
ISO 27001
SOC 2
Apply
Data Engineer 1 day ago
In office • Full-Time • Singapore
Node JS
Python
SQL
JavaScript
Python
Beautiful Soup
Databases
Apache Kafka
MySQL
PostgreSQL
RabbitMQ
SQLite
AI/ML
Hadoop
Spark
DevOps
AWS
AWS Lambda
Azure
CI/CD
GCP
Amazon ECS
Amazon EventBridge
Amazon S3
Analytics
ETL/ELT
QA
Selenium
Apply
up to $48k per year (net) • Remote/Hybrid • Moscow
Node JS
Python
TypeScript
JavaScript
Node JS
Nest.JS
Python
Django
FastAPI
Databases
Apache Kafka
pgvector
Pinecone
PostgreSQL
Qdrant
RabbitMQ
Redis
AI/ML
Chain-of-Thought
Claude
Claude Code
Copilot
Cursor
LangChain
LlamaIndex
LLM
Prompt Engineering
RAG
Anthropic
Function Calling
OpenAI
Structured Outputs
Frontend
GraphQL
Next.js
React.js
Redux
Redux Toolkit
Zustand
Mobile
State Management
DevOps
AWS
CI/CD
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Kubernetes
Prometheus
Yandex Cloud
GitHub
GitLab
Apply
$30k – $38k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Cluj-Napoca
C#
JavaScript
Node JS
Python
SQL
TypeScript
AI/ML
Claude
Claude Code
Copilot
Cursor
Frontend
Angular
React.js
DevOps
AWS
Azure
Azure DevOps
Git
GitHub Actions
Jenkins
Rest API
GitHub
Apply
$121k – $195k per year (Estimated) • In office • Full-Time • United Kingdom • Ireland
Databases
MySQL
AI/ML
AI Agents
Apply
$188k – $275k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree • Boston
AI/ML
AI Agents
Apply
$68k – $99k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree • Draper
AI/ML
AI Agents
Management
Jira
Apply
$46k – $101k per year (Estimated) • In office • Full-Time • 3+ years exp • Toronto
PowerShell
AI/ML
AI Agents
Model Context Protocol
DevOps
Amazon EC2
AWS
Grafana
SLI/SLO/SLA
Windows Server
Amazon CloudWatch
Amazon S3
IAM
Marketing
Salesforce
Apply
$167k – $244k per year • Remote • Full-Time • Toronto
JavaScript
Node JS
Python
SQL
Node JS
Strapi
Python
FastAPI
Databases
ElasticSearch
PostgreSQL
AI/ML
AI Agents
LLM
Model Context Protocol
Frontend
React.js
DevOps
Amazon EC2
AWS
AWS Lambda
CI/CD
Docker
Git
Rest API
Terraform
Amazon CloudWatch
API Gateway
IAM
Cybersecurity
MISP
STIX
Apply
$68k – $99k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree • Draper
AI/ML
AI Agents
Management
Jira
Apply
$82k – $177k per year (Estimated) • Equity • Remote • 2+ years exp • Draper
AI/ML
LLM
Apply
$74k – $111k per year • Remote • Full-Time • 2+ years exp • Draper
C#
C++
JavaScript
Frontend
React.js
Apply
$133k – $261k per year (Estimated) • Equity • Remote • Internship • Draper
Apply
$160k – $270k per year (Estimated) • Equity • Remote • 8+ years exp • Draper
Python
SQL
Databases
Snowflake
Trino
AI/ML
AI Agents
dbt
Analytics
ETL/ELT
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.