Staff Information Security Engineer - Threat Defense & Automation

Proofpoint

Sunnyvale (CA)

Hybrid

USD 188,000 - 275,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Comprehensive benefits
Career growth on your terms
Flexible work environment
Wellness & Volunteer days
Recognition program
Global collaboration

Job summary

Proofpoint is hiring a Staff Information Security Engineer to lead and evolve the Global Information Security Operation from a hybrid office in Sunnyvale, CA or Draper, UT. You will shape incident response strategy, advance threat detection, and drive complex investigations enterprise-wide.

As a Staff-level engineer, you’ll serve as a technical leader across SOC, Threat Intelligence, Detection Engineering, and Security Engineering, with a 24/7 on-call rotation and strong mentorship

Qualifications

  • 12+ years in Incident Response, DFIR, Threat Hunting, or Security Operations.
  • Deep expertise in incident response, threat hunting, and threat intelligence.
  • Strong knowledge of MITRE ATT&CK and adversary TTPs.
  • Experience with SIEM, EDR, SOAR, and cloud security.

Responsibilities

  • Serve as a Level 3 / Staff escalation point for high-severity incidents.
  • Lead investigations into APTs, ransomware, insider threats, and cloud compromises.
  • Act as incident commander and coordinate response efforts.
  • Lead threat hunting across endpoint, network, identity, and cloud.
  • Design and improve detections across SIEM, EDR, and SOAR.

Skills

Incident response
Threat hunting
Threat intelligence
MITRE ATT&CK
Scripting
Leadership

Tools

SIEM
EDR
SOAR
Cloud security

Job description

About Us:

Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people.

How We Work:

At Proofpoint you’ll be part of a global team that breaks barriers to redefine cybersecurity guided by our BRAVE core values:

Bold in how we dream and innovate

Responsive to feedback, challenges and opportunities

Accountable for results and best in class outcomes

Visionary in future focused problem-solving

Exceptional in execution and impact

About Proofpoint

At Proofpoint, we are committed to protecting organizations and individuals from cyber threats through innovative security solutions. Our mission is to safeguard customers from advanced threats, phishing attacks, and data breaches throughcutting-edgetechnology and a global team of security experts.

Role Overview

We’reseeking a Staff Information Security Engineer to help lead and evolve our Global Information SecurityOperation. In this role,you’llshapeincidentresponse strategy, push forward advanced threat detection anddefensecapabilities, and take point on the most complex security investigations across the enterprise.

As a Staff-level engineer, you willoperateas a subject matter expert and technical leader, partnering across SOC, Threat Intelligence, Detection Engineering, and Security Engineering to improve Proofpoint’s ability to detect, respond to, and proactively hunt advanced threats.
This role includes participation in a 24/7 on-call incident response rotation.

Location:

This is a hybrid role based in our Draper, UT or Sunnyvale, CA office 4 days a week.

Key Responsibilities
  • Serve as a Level 3 / Staff escalation point for high-severity incidents.
  • Lead investigations into APTs, ransomware, insider threats, and cloud compromises.
  • Act as incident commander and coordinate response efforts.
  • Participatein 24/8 on-call incident response.
  • Lead threat hunting acrossendpoint,network, identity, andcloud.
  • Operationalize threat intelligence into detections and response.
  • Design and improvedetectionsacross SIEM, EDR, and SOAR.
  • Automate incident triage and response workflows.
  • Drive post-incident reviews and continuous improvement.
  • Mentor team members and influence security strategy.
Required Qualifications
  • 12+ years in Incident Response, DFIR, Threat Hunting, or Security Operations.
  • Deepexpertisein incident response, threat hunting, and threat intelligence.
  • Strong knowledge of MITRE ATT&CK and adversary TTPs.
  • Experience with SIEM, EDR, SOAR, and cloud security.
  • Scripting experience (Python, PowerShell, or Bash).
  • Strong communicationand leadership skills.
  • US Citizen.
Preferred Qualifications
  • Experience building threat hunting or detection programs.
  • Background in threat intelligence or red/purple teaming.
  • Certifications such as GCFA, GCIH, CISSP, CISM, OSCP.

#LI-AN2

Why Proofpoint?

At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you’ll love working with us:

  • Competitive compensation
  • Comprehensive benefits
  • Career success on your terms
  • Flexible work environment
  • Annual wellness and community outreach days
  • Always on recognition for your contributions
  • Global collaboration and networking opportunities

_ _

Our Culture:

Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone.

We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to accessibility@proofpoint.com.

Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and/or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.

Base Pay Ranges:

SF Bay Area, New York City Metro Area:

Base Pay Range: 187,700.00 - 275,275.00 USD

California (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska:

Base Pay Range: 151,000.00 - 221,430.00 USD

All other cities and states excluding those listed above:

Base Pay Range: 137,000.00 - 200,915.00 USD

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Information Security Engineer - Threat Defense & Automation
Staff Information Security Engineer - Threat Defense & Automation

Proofpoint • Draper (UT)

Hybrid
USD 137,000 - 276,000
Competitive pay
Comprehensive benefits
Flexible work environment
+3
Senior Cyber Threat Defense - Security Operations Engineer
Senior Cyber Threat Defense - Security Operations Engineer

Segment (Twilio) • Draper (UT)

On-site
USD 110,000 - 160,000
Competitive compensation
Comprehensive benefits
Flexible work environment
+1
Senior Full Stack Software Engineer, Threat Intelligence Services
Senior Full Stack Software Engineer, Threat Intelligence Services

Proofpoint • Dallas (TX)

On-site
USD 124,000 - 182,000
Competitive compensation
Comprehensive benefits
Flexible work environment
+3
Manager, Security Platform Engineering
Manager, Security Platform Engineering

Proofpoint • Sunnyvale (CA)

On-site
USD 166,000 - 244,000
Competitive compensation
Comprehensive benefits
Flexible work environment
+1
Senior Full Stack Software Engineer, Threat Intelligence Services
Senior Full Stack Software Engineer, Threat Intelligence Services

Proofpoint • Salt Lake City (UT)

On-site
USD 124,000 - 182,000
Competitive compensation
Comprehensive benefits
Work from Anywhere
+3
Senior Full-Stack Engineer: AWS, React & Automation (Remote)
Senior Full-Stack Engineer: AWS, React & Automation (Remote)

Proofpoint • Salt Lake City (UT)

On-site
USD 124,000 - 182,000
Competitive compensation
Comprehensive benefits
Work from Anywhere
+3
Manager, Security Platform Engineering
Manager, Security Platform Engineering

Proofpoint • Salem (IN)

Hybrid
USD 124,000 - 182,000
Competitive compensation
Comprehensive benefits
Flexible work environment
+3
Manager, Threat Protection Services
Manager, Threat Protection Services

Proofpoint • Carson City (NV)

On-site
USD 101,000 - 160,000
Competitive compensation
Comprehensive benefits
Flexible work environment
Senior Full Stack Software Engineer, Threat Intelligence Services
Senior Full Stack Software Engineer, Threat Intelligence Services

Proofpoint • Minneapolis (MN)

On-site
USD 124,000 - 182,000
Competitive compensation
Comprehensive benefits
Flexible work environment
+3
Senior Full Stack Software Engineer, Threat Intelligence Services
Senior Full Stack Software Engineer, Threat Intelligence Services

Proofpoint • Raleigh (NC)

On-site
USD 124,000 - 182,000
Competitive compensation
Comprehensive benefits
Flexible work environment