Senior Endpoint Security Engineer

Procter & Gamble Philippines

Manila

On-site

PHP 1,200,000 - 2,400,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Performance bonus
Flexible schedule
Work from home
Health insurance
Fitness support
Employee Assistance Program

Job summary

Procter & Gamble Philippines is seeking a Senior Endpoint Security Engineer to lead threat modeling and automation across Windows, macOS, Linux, and Cloud/OT fleets. You will build data-driven threat models, create automated detection rules, and bridge endpoint telemetry with AI threat intelligence.

The role focuses on proactive defense, automated containment via SOAR, and cross-functional collaboration with IT, DevOps, and SOC teams to improve security posture and reduce operational toil.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent technical field.
  • Certifications such as SANS/GIAC or Python/Automation are a plus.
  • 3+ years in Endpoint Security, Detection Engineering, or SOC Automation across OS domains.

Responsibilities

  • Architect data-driven threat models and dynamic attack path diagrams using live asset graphs and EDR/XDR telemetry.
  • Design automated SOAR playbooks and machine-speed mitigation controls to neutralize exploits.
  • Implement CIS benchmarks and ASR policies to reduce attack surface across endpoints.
  • Collaborate with Business Tech, DevOps, and SOC teams to deploy endpoint automation without disrupting operations.
  • Develop and refine AI-driven threat intelligence and integration with security tooling.

Education

Bachelor's degree in Computer Science / Cybersecurity or equivalent
SANS/GIAC or Python/Automation certifications

Tools

Falcon Fusion
Torq
XSOAR
CrowdStrike
CQL
Sigma
YARA

Job description

Job Location

MANILA NET PARK OFFICE

Job Description

At P&G, your career is built to scale with our iconic brands like Ariel®, Safeguard ®, Tide ®, Head & Shoulders®, Old Spice®, and Vicks®.

Ready to join the team that powers our iconic brands? Here’s what you’ll be doing:

Senior Endpoint Security Engineer to lead our next-generation endpoint threat modeling and endpoint security automation program. In this role, you will be the primary technical engineer responsible for shifting our security posture from reactive vulnerability patching to proactive, data-driven threat modeling and machine-speed defense.

You will bridge the gap between deep endpoint telemetry, generative AI threat intelligence, and automated orchestration. By mapping complex multi-stage attack chains across Windows, macOS, Linux, and Cloud/OT host environments, you will design automated SOAR playbooks, virtual patching workflows, and behavioral detection rules that neutralize advanced AI-driven exploits before they materialize. You will also be the key automation engineer that will eliminate operational toil, drive endpoint security and SOC team efficiency, and build a cyber-resilient organization.

Key Responsibilities
  • Proactive & Continuous Threat Modeling & Detection Engineering: Architect living, data-driven threat models and dynamic attack path diagrams by integrating live asset graphs, identity trust boundaries, deep endpoint telemetry (EDR/XDR), and Generative AI threat intelligence across Windows, macOS, Linux, and Cloud/OT fleets; use these models alongside frameworks like MITRE ATT&CK to author high-fidelity behavioral detection rules (CrowdStrike Query Language (CQL), Sigma, and YARA to block multi-stage exploit), automated virtual patching workflows, and machine-speed mitigation controls that neutralize zero-days and advanced AI-driven exploits before physical patches are deployed.
  • AI & Predictive Threat Intelligence Integration: Operationalize cutting-edge AI threat intelligence (e.g., Claude/Glasswing research, ExPRT.ai, LLM-generated exploit models) to anticipate emergent adversary playbooks and automatically prioritize reachable, weaponized vulnerabilities.
  • Configuration Drift & Attack Surface Reduction (ASR): Maintain proactive posture control across cross-platform endpoints by enforcing CIS benchmarks, host-based isolation, device control policies, and automated OS security drift remediation.
  • Cross-Functional Collaboration and Continuous Improvement: Partner closely with Business Technical teams, DevOps, Infrastructure, and Security Engineering to integrate endpoint threat models into IT and OT operations without disrupting business productivity.GenAI & Tool Integration: Continually evaluate and integrate emerging GenAI security capabilities and modern APIs to keep the endpoint automation platform ahead of evolving threats
  • Machine-Speed Response & SOAR Automation: Design, test, and deploy automated containment playbooks using SOAR platforms (e.g., Falcon Fusion, Torq, XSOAR) to improve Mean Time to Containment (TTC) for critical systems.
  • Streamline Operations, SOC & Endpoint Efficiency: Architect and implement end-to-end endpoint SecOps automation to eliminate repetitive, high-volume manual tasks, drastically reducing alert fatigue and operational toil and build automated enrichment, triage, and context-gathering pipelines to empower SOC analysts to make faster decisions and focus on high-value threat hunting.
Job Qualifications
1. Hands-On Automation & SecOps Engineering
  • SOAR & Orchestration: Proven technical experience building, testing, and maintaining automated playbooks and containment workflows using SOAR platforms (e.g., Falcon Fusion, Torq, Palo Alto XSOAR).
  • Scripting & API Integration: Strong hands-on proficiency with Python, PowerShell, or Bash to interact with RESTful APIs, automate endpoint pipelines, and eliminate manual SecOps toil.
  • SecOps Optimization: Practical ability to build automated triage, context-gathering, and enrichment tools that lower MTTR/MTTD and reduce alert fatigue for SOC analysts.
2. Endpoint Telemetry & Detection Engineering
  • Multi-OS Internals: Deep engineering familiarity with OS security mechanisms and telemetry parsing across Windows, macOS, Linux, and Cloud/OT host environments.
  • Virtual Patching & Host Defense: Direct experience implementing automated virtual patching, host-based isolation, and policy controls to block zero-day exploits ahead of vendor patches.
  • Rule Authoring & Query Languages: Expert-level skills authoring, testing, and tuning behavioral detection rules using query languages such as CQL (CrowdStrike Query Language), Sigma, YARA, or SPL.
3. Applied Threat Modeling, Posture Control, AI and Predictive TI Integration
  • Technical Threat Modeling: Practical skill in mapping multi-stage attack chains (using MITRE ATT&CK) and building data-driven attack path maps from live asset graphs and EDR/XDR telemetry.
  • Hardening & Drift Remediation: Direct experience implementing CIS Benchmarks, Attack Surface Reduction (ASR) policies, and automated configuration drift fixes across host fleets.
  • AI and Predictive TI Integration: Operationalize cutting-edge AI threat intelligence (e.g., Claude/Glasswing research, ExPRT.ai, LLM-generated exploit models) to anticipate emergent adversary playbooks and automatically prioritize reachable, weaponized vulnerabilities.
4. Technical Cross-Collaboration
  • Cross-Functional Partnership: Strong collaborative working style with hands-on experience pairing directly with Business Technical teams, DevOps, System Administrators, and SOC analysts to roll out endpoint automation without breaking operational workflows.
5. Technical Experience
  • Professional Background: 3+ years of hands-on experience in Endpoint Security, Detection Engineering, SOC Automation, or Systems Operations across multiple OS domains.
  • AI Use: Proficient in leveraging Generative AI tools to enhance cyber defense capabilities and overall endpoint security posture
  • Education & Certifications (Preferred): Bachelor’s degree in Computer Science, Cybersecurity, or equivalent technical experience; practical certifications like SANS/GIAC (GCIH, GCED), CrowdStrike (CCFR/CCFA), or Python/Automation credentials.
Scale your career with P&G
  • Performance bonus (STAR program) that rewards managers in light with business results achieved.
  • Thrive at work and your personal life through our flexible work schedule with available work from home arrangements.
  • Your well-being is non-negotiable and supported by health insurance, fitness support, and an Employee Assistance Program.

Learn more about what’s in store for you at https://www.pgcareers.com/ph/en/benefits.

About us

We produce globally recognized brands and we grow the best business leaders in the industry. With a portfolio of trusted brands as diverse as ours, it is paramount our leaders are able to lead with courage the vast array of brands, categories and functions. We serve consumers around the world with one of the strongest portfolios of trusted, quality, leadership brands, including Always®, Ariel®, Gillette®, Head & Shoulders®, Herbal Essences®, Oral-B®, Pampers®, Pantene®, Tampax® and more. Our community includes operations in approximately 70 countries worldwide.

Visithttp://www.pg.comto know more.

We are an equal opportunity employer and value diversity at our company. We do not discriminate against individuals on the basis of race, color, gender, age, national origin, religion, sexual orientation, gender identity or expression, marital status, citizenship, disability, HIV/AIDS status, or any other legally protected factor.

Job Schedule

Full time

Job Number

R000156399

Job Segmentation

Experienced Professionals

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Endpoint Security Engineer
Senior Endpoint Security Engineer

Procter & Gamble • Philippines

On-site
PHP 1,200,000 - 2,000,000
Performance bonus
Flexible work schedule with work from{
Senior Automation Engineer (AI-Accelerated Threat Response),
Senior Automation Engineer (AI-Accelerated Threat Response),

Procter & Gamble • Manila

On-site
PHP 1,800,000 - 2,400,000
Performance bonus (STAR program)
Flexible work schedule / work from any
Health insurance
Senior Software Engineer - Technical Lead (Consumer Pulse)
Senior Software Engineer - Technical Lead (Consumer Pulse)

Procter & Gamble • Manila

On-site
PHP 1,800,000 - 2,400,000
STAR bonus
Flexible work schedule with work from
Health insurance and wellness programs
Senior Software Engineer - Technical Lead (Consumer Pulse)
Senior Software Engineer - Technical Lead (Consumer Pulse)

Procter & Gamble • Philippines

On-site
PHP 1,500,000 - 3,000,000
Health insurance
Flexible work schedule
Work from home arrangements
Site Reliability Engineer
Site Reliability Engineer

Procter & Gamble • Philippines

On-site
PHP 1,000,000 - 1,400,000
Performance bonus
Flexible work schedule / work from hom
Health insurance
+2
Data Engineering Senior Manager - Consumer Data Platform
Data Engineering Senior Manager - Consumer Data Platform

Procter & Gamble • Philippines

On-site
PHP 1,500,000 - 2,100,000
Senior Software Engineer - Technical Lead (Consumer Pulse)
Senior Software Engineer - Technical Lead (Consumer Pulse)

Procter & Gamble Philippines • Manila

On-site
PHP 1,800,000 - 2,600,000
Site Reliability Engineer - Warehousing IT Operations
Site Reliability Engineer - Warehousing IT Operations

Procter & Gamble • Philippines

On-site
PHP 1,200,000 - 1,800,000
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Procter & Gamble • Philippines

On-site
PHP 1,200,000 - 1,500,000
Performance bonus (STAR)
Flexible work schedule with work-from-
Health insurance
+2
Software Engineer - Information Technology
Software Engineer - Information Technology

Procter & Gamble • Manila

On-site
PHP 320,000 - 520,000