Email Security and Social Engineering Analyst

First-Horizon-Bank

Memphis (TN)

On-site

USD 65,000 - 90,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

First Horizon Bank is seeking an Email Security and Social Engineering Analyst to protect associates and customers by managing email controls and investigating suspicious messages. You will work with Proofpoint and Outlook, triage phishing, support incident response, and help strengthen detection and response to email threats.

The role emphasizes clear communication with technical teams and business partners, along with strong attention to detail and collaborative problem solving in a fast-paced

Qualifications

  • Current associate in good standing with reliability and attention to detail.
  • Strong written and verbal communication skills, including the ability to interact with associates, leaders, technical teams, and external contacts.
  • Ability to analyze incomplete or conflicting information, recognize patterns, and make well-reasoned decisions.
  • Ability to follow procedures while adapting to new attack techniques and changing business conditions.
  • Comfort handling sensitive information and maintaining confidentiality.
  • Ability to manage competing priorities and work independently in a fast-paced environment.
  • General proficiency with Microsoft Office and collaboration tools.
  • Education and experience sufficient to perform the responsibilities of the role; relevant internal experience and transferable skills will be considered.

Responsibilities

  • Review and manage email traffic, alerts, quarantines, and threat activity using Proofpoint and related tools.
  • Lead day-to-day phishing response by monitoring, triaging, investigating, containing, and documenting suspicious emails.
  • Address ServiceNow tickets related to phishing, email security, and delivery within SLA expectations.
  • Troubleshoot email delivery issues by reviewing message tracking, filtering decisions, and policy routes.
  • Analyze headers, sender behavior, URLs, and attachments to classify emails as legitimate or suspicious.
  • Investigate social engineering, including phishing, impersonation, BEC, credential theft, and fraudulent requests.
  • Support digital risk protection by identifying external threats such as brand impersonation and fraudulent domains.
  • Perform Tier 1 phishing triage and escalate complex cases as needed.
  • Use sandboxing, threat intelligence, and EDR tools to validate findings and assess impact.
  • Support email authentication controls (DMARC, SPF, DKIM) and firewall rules.

Skills

Written communication
Verbal communication
Analytical thinking
Attention to detail
Independent work
Time management

Tools

Proofpoint
Microsoft 365 security
Splunk
Endpoint detection and response
Ticketing systems
Security sandboxes

Job description

Email Security and Social Engineering Analyst

Business Area: Information Security - Security Operations

Posting Type: Internal Applicants

Work Arrangement: On-site preferred (Memphis, New Orleans, other sites to be considered)

Summary

We are seeking an associate to join the Security Operations team as an Email Security Analyst. This role will help protect the organization, our associates, and our customers by managing email security controls and investigating suspicious messages. The analyst will work extensively in Proofpoint and Outlook, triage reported phishing emails, support incident response, and help improve how we detect and respond to email-based threats.

The ideal candidate brings a healthy sense of paranoia: someone who notices when details do not add up, verifies assumptions, follows evidence, and remains appropriately skeptical without losing sight of business context. Just as important, this associate must communicate clearly and calmly with technical teams, business partners, leaders, and end users.

Why Consider This Opportunity?

This position is a great opportunity to be on the front line of threats impacting our associates and customers. You will see firsthand—and help defend against—cybersecurity and social engineering threats while gaining hands‑on experience with enterprise email security, phishing response, digital risk protection, threat analysis, incident response, and security operations. You will also partner with teams across the company to investigate issues, contain threats, and protect the organization.

Essential Duties and Responsibilities
  • Use the Proofpoint Secure Email Gateway and related Proofpoint tools to review and manage email traffic, alerts, quarantines, and threat activity.
  • Lead day-to-day phishing response by monitoring, triaging, investigating, containing, and documenting suspicious emails reported by associates and customers.
  • Address ServiceNow tickets related to phishing, email security, email delivery, and other assigned security issues within established service-level expectations.
  • Troubleshoot email delivery issues by reviewing message tracking, filtering decisions, quarantines, authentication results, policy routes, allow and block controls, and other relevant data.
  • Analyze message headers, sender behavior, URLs, attachments, redirects, and message context to determine whether an email is legitimate, suspicious, or malicious.
  • Investigate social engineering activity, including phishing, impersonation, business email compromise, credential theft, malicious links, and fraudulent requests.
  • Support digital risk protection activities by identifying, reviewing, and escalating external threats such as brand impersonation, fraudulent domains, malicious websites, and other risks targeting the organization, its associates, or its customers.
  • Perform Tier 1 phishing triage and elevate confirmed threats or complex investigations as appropriate.
  • Use sandboxing, threat intelligence, endpoint, identity, and logging tools to validate findings and determine potential impact.
  • Support email authentication and protection controls, including DMARC, SPF, DKIM, policy routes, and email firewall rules.
  • Search for related messages, contain threats, remove malicious emails, and support affected-user response actions.
  • Support incident response for compromised user accounts and devices, including evidence collection, scoping, containment, escalation, remediation coordination, and documentation.
  • Work with Identity, Endpoint, Security Operations, and other response teams to protect affected users, reset or secure access, isolate devices when appropriate, and confirm that threats have been contained.
  • Document investigations, evidence, decisions, and actions accurately and consistently.
  • Communicate findings and recommended actions to associates in clear, professional, and timely language.
  • Partner with Security Operations, Threat Management, Security Engineering, Messaging, Identity, and other teams during investigations and incidents.
  • Identify recurring patterns, control gaps, and opportunities to improve phishing detection, email delivery support, digital risk protection, and incident response processes.
  • Participate in an after-hours rotation or respond outside normal business hours when required.
  • Perform other duties as assigned.
What Success Looks Like
  • You are naturally curious and willing to investigate beyond the first obvious answer.
  • You maintain a healthy sense of paranoia while making evidence-based, practical decisions.
  • You can distinguish unusual activity from normal business behavior and know when to ask more questions.
  • You communicate with empathy and confidence, especially when an associate may be worried about a suspicious message or possible compromise.
  • You remain organized and accurate while managing a queue of time-sensitive work.
  • You explain technical findings in plain language and tailor your message to the audience.
  • You take ownership, follow through, and elevate promptly when risk or impact is unclear.
Qualifications
  • Current associate in good standing with demonstrated reliability, sound judgment, and attention to detail.
  • Strong written and verbal communication skills, including the ability to interact effectively with associates, leaders, technical teams, and external contacts.
  • Ability to analyze incomplete or conflicting information, recognize patterns, and make well-reasoned decisions.
  • Ability to follow procedures while adapting to new attack techniques and changing business conditions.
  • Comfort handling sensitive information and maintaining confidentiality.
  • Ability to manage competing priorities and work independently in a fast-paced environment.
  • General proficiency with Microsoft Office and collaboration tools.
  • Education and experience sufficient to perform the responsibilities of the role; relevant internal experience and transferable skills will be considered.
Preferred Experience
  • Experience in Information Security, fraud, investigations, technology support, risk management, compliance, customer service, operations, or another role requiring careful review and sound judgment.
  • Familiarity with phishing, business email compromise, social engineering, malware, or common email threats.
  • Experience with Proofpoint, Microsoft 365 email security, Splunk, endpoint detection and response tools, ticketing systems, and/or security sandboxes.
  • Understanding of email headers, URLs, domains, DNS, DMARC, SPF, or DKIM.
  • Experience documenting investigations or communicating findings to non-technical audiences.
  • Relevant security training or certificates, including Security+, CySA+, or Proofpoint certifications.
Supervisory Responsibilities

This position has no supervisory responsibilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer / Architect – Email Security
Product Security Engineer / Architect – Email Security

State Street • Berwyn (PA)

Hybrid
USD 120,000 - 203,000
401K with company match
Health insurance
Paid time off
+2
Product Security Engineer / Architect – Email Security
Product Security Engineer / Architect – Email Security

State Street • Boston (MA)

Hybrid
USD 120,000 - 202,500
401K with company match
Insurance coverage
Paid time off
Product Security Engineer / Architect – Email Security
Product Security Engineer / Architect – Email Security

State Street • Clifton (NJ)

Hybrid
USD 120,000 - 202,500
401K matching
Medical, dental, vision insurance
Generous paid time off
Product Security Engineer / Architect – Email Security
Product Security Engineer / Architect – Email Security

State Street • Princeton (NJ)

Hybrid
USD 120,000 - 203,000
Email Security & Phishing Response Analyst
Email Security & Phishing Response Analyst

First-Horizon-Bank • Memphis (TN)

On-site
USD 65,000 - 90,000
Microsoft 365 & Proofpoint Email Security Engineer
Microsoft 365 & Proofpoint Email Security Engineer

Veriipro • California City (CA)

On-site
USD 80,000 - 100,000
Product Security Engineer / Architect – Email Security
Product Security Engineer / Architect – Email Security

State Street • Austin (TX)

Hybrid
USD 120,000 - 203,000
Senior Email Security Architect & Strategist
Senior Email Security Architect & Strategist

State Street • Boston (MA)

Hybrid
USD 120,000 - 202,500
401K with company match
Insurance coverage
Paid time off
Lead Email Security Architect
Lead Email Security Architect

State Street • Princeton (NJ)

Hybrid
USD 120,000 - 203,000
Cyber Security Engineer
Cyber Security Engineer

Veriipro • San Antonio (TX)

On-site
USD 90,000 - 120,000