Senior Cyber Threat Defense Security Operations Engineer

Proofpoint

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Draper, UT
Salary
$136,200–$214,005 / yr
Posted
23 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $175k
This role $175k
$119k most similar roles pay here $224k

This role pays more than 57% of similar roles. Most pay $150,000–$200,000 — the shaded band above. At the midpoint, this role pays about $175k versus about $175k for comparable roles.

Based on 240 similar postings.

Employer

About Proofpoint

Proofpoint is a cybersecurity company specializing in email security, threat protection, data loss prevention, and compliance. Privately held by Thoma Bravo since 2021, it serves over 500,000 organizations including 87 of the Fortune 100.

Proofpoint currently has 15 open roles on FindRole.

Listed pay typically runs $136,200–$214,005 across 9 roles with salary data.

Most-posted roles

View all roles at Proofpoint

At a glance

TL;DR · Senior Cyber Threat Defense Security Operations Engineer

The Senior Cyber Threat Defense - Security Operations Engineer joins the Global Information Security Operation team as a senior Level 3 escalation point for the 24/7 Security Operations Center. This role involves leading complex investigations into malware, ransomware, phishing, and advanced persistent threats while managing containment and remediation strategies. The engineer will perform proactive threat hunting across cloud environments and networks, conduct cross-functional threat modeling, and develop detection rules based on MITRE ATT&CK techniques. Key responsibilities include implementing security automation via SOAR platforms and scripting in Python, PowerShell, or Bash to streamline incident response. Additionally, the role supports emerging capabilities like Agentic SOC workflows and AI Data Loss Prevention. The position requires expertise in SIEM, EDR/XDR, and cloud security across AWS, Azure, or Google Cloud Platform to defend against sophisticated cyber threats.

What you'll do

  • Serve as the Level 3 escalation point for high-severity and technically complex security incidents within the global SOC.
  • Lead major investigations involving malware, ransomware, phishing, identity attacks, and advanced persistent threats.
  • Develop and maintain detection rules, hunting queries, and response use cases based on threat intelligence and MITRE ATT&CK.
  • Perform proactive threat hunting across endpoints, networks, cloud environments, and SaaS applications to identify hidden risks.
  • Design and implement security automation strategies using SOAR platforms and scripting languages like Python, PowerShell, or Bash.
  • Conduct cross-functional threat modeling for new systems and services to identify attack paths and control gaps.
  • Support AI-enabled capabilities including Agentic SOC workflows and AI Data Loss Prevention (AI DLP) controls.
  • Mentor junior engineers and analysts while establishing investigation standards and technical roadmap improvements.

What we're looking for

  • Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations.
  • Demonstrated experience leading major incidents and serving as the final technical escalation point for complex or high-severity events.
  • Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, and security monitoring.
  • Experience investigating malware, phishing, identity attacks, cloud compromise, insider threats, data loss, and advanced persistent threats.
  • Hands-on experience with SOAR platforms, APIs, and scripting languages such as Python, PowerShell, or Bash.
  • Strong understanding of the MITRE ATT&CK framework and experience applying threat modeling methods like STRIDE or attack trees.
  • Experience with Agentic SOC, AI-assisted investigation, AI DLP, purple-team exercises, or relevant certifications like GCIH, GCFA, CISSP, CISM, OSCP, GIAC (preferred).
  • U.S. citizenship.

More like this

Similar roles

Senior Security Operations Engineer

Microsoft

Redmond, WA 13 days ago $119,800$234,700
Microsoft Sentinel KQL Python C++ C# PowerShell Logic Apps SIEM SOC NOC LLM AI Networking DNS TCP/IP Firewalls Purview DTEX Proofpoint ITM Magnet Axiom Forcepoint
4+ yrs exp

Senior Security Engineer, Cloud Threat Detection

The Hartford

Hartford, CT +3 23 days ago $128,400$192,600
AWS GCP Splunk SIEM Python PowerShell Bash MITRE ATT&CK SOAR CloudTrail GuardDuty CrowdStrike Wiz Orca SentinelOne Microsoft Defender XDR Identity and Access Management (IAM)
5+ yrs exp Hybrid

Specialist, Cyber Detection Engineer

Prudential Financial

Newark, NJ 50 days ago $96,200$158,800
SIEM XDR Splunk KQL SQL Python PowerShell GraphQL MITRE ATT&CK Incident Response Threat Hunting
3+ yrs exp

Senior Security Operations Engineer

Brex

Seattle, WA 56 days ago $192,000$240,000
Go Python AWS Kubernetes Terraform CI/CD Buildkite Flux Git SIEM SOAR Data Pipelines Cloud Security DevOps Infrastructure Security Security Incident Response
5+ yrs exp

Senior Security Operations Engineer

Brex

New York, NY 56 days ago $192,000$240,000
Go Python AWS Kubernetes Terraform CI/CD Buildkite Flux Git SIEM SOAR Data Pipelines Cloud Security Infrastructure Security Incident Response
5+ yrs exp

Senior Security Operations Engineer

Brex

San Francisco, CA 56 days ago $192,000$240,000
Go Python AWS Kubernetes Terraform CI/CD Buildkite Flux Git SIEM SOAR Data Pipelines Cloud Security Infrastructure Security Security Incident Response DevOps
5+ yrs exp