×
Register Here to Apply for Jobs or Post Jobs. X

Senior Cyber Threat Defense - Security Operations Engineer

Job in Draper, Salt Lake County, Utah, 84020, USA
Listing for: Segment (Twilio)
Full Time position
Listed on 2026-08-02
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 110000 - 159720 USD Yearly USD 110000.00 159720.00 YEAR
Job Description & How to Apply Below

About Us:

Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently.

Join us in our pursuit to defend data and protect people.

How We Work:
  • Bold in how we dream and innovate

    Responsive to feedback, challenges and opportunities

    Accountable for results and best in class outcomes

    Visionary in future focused problem-solving

    Exceptional in execution and impact

About Proofpoint At Proofpoint, we protect organizations and individuals from today's most advanced cyber threats. Through innovative security technologies, threat intelligence, and a global team of security experts, we help customers defend against phishing, malware, account compromise, insider threats, and data loss.

Role Overview

We are seeking an experienced Senior Cyber Threat Defense - Security Operations Engineer to join our global security team in Draper, UT. This critical role sits within the Global Information Security Operation team and is responsible for investigating and responding to sophisticated security incidents across Proofpoint's global operations. You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC), own complex investigations and technical decisions, participate in a scheduled on-call rotation, and set direction for detection, investigation, response, threat modeling, and security automation.

The role also supports selected AI-enabled capabilities, including Agentic SOC workflows and AI Data Loss Prevention (AI DLP).

Key Responsibilities
  • Incident Response and Escalation Own Level 3 escalation for high-severity and technically complex incidents within the global 24/7 SOC. Lead major investigations involving malware, ransomware, phishing, identity attacks, insider threats, cloud compromise, and advanced persistent threats. Set containment, eradication, recovery, remediation, and post-incident improvement strategy, balancing risk and business impact. Direct response across Security, IT, Cloud Engineering, Legal, Privacy, and business leaders, and communicate incident status and decisions to executives.

    Participate in a scheduled on-call rotation and provide after-hours support for critical security incidents, including nights, weekends, and holidays as required.
  • Threat Hunting, Modeling, and Detection Engineering Proactively hunt for hidden threats across endpoints, identities, networks, cloud environments, SaaS applications, and data repositories. Lead cross-functional threat modeling for new and existing systems, cloud services, and security workflows to identify abuse cases, attack paths, and control gaps. Use threat intelligence and behavioral analytics to identify suspicious activity and emerging attack patterns. Develop, test, tune, and maintain detection rules, correlations, hunting queries, and response use cases.

    Translate threat intelligence and MITRE ATT&CK techniques into actionable detection and hunting use cases.
  • Security Automation and Orchestration Define and implement automation strategy for alert enrichment, prioritization, triage, containment, notification, and remediation. Use SOAR platforms and security APIs to streamline repeatable incident-response activities. Develop scripts, integrations, and automation using Python, Power Shell, Bash, or similar languages. Optimize SIEM log ingestion, normalization, correlation, retention, and alerting.
  • Emerging Security Capabilities Support practical Agentic SOC use cases for alert triage, investigation enrichment, case documentation, and response under defined human oversight. Help operate AI DLP controls that reduce sensitive-data exposure through generative AI applications and copilots.
  • Continuous Improvement Own root-cause analysis and drive improvements to security controls, telemetry, processes, and architecture. Partner with security architects and engineering leaders to set technical direction and evaluate detection and response technologies. Mentor engineers and analysts, establish investigation standards, and raise technical capability across the SOC.
Required Qualifications and Experience
  • Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations.
  • U.S. citizenship.
  • Demonstrated experience leading major incidents and serving as the final technical escalation point for complex or high-severity security events.
  • Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, and security monitoring.
  • Experience investigating malware, phishing, identity attacks, cloud compromise, insider threats, data loss, and advanced…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary