Staff Information Security Engineer, Threat Defense & Automation

Proofpoint

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Sunnyvale, CADraper, UT
Salary
$187,700–$275,275 / yr
Employment
Full-time
Posted
46 days ago
Freshness
Confirmed live today

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $183k
This role $231k
$125k most similar roles pay here $291k

This role pays more than 88% of similar roles. Most pay $152,150–$214,428 — the shaded band above. At the midpoint, this role pays about $231k versus about $183k for comparable roles.

Based on 240 similar postings.

Employer

About Proofpoint

Proofpoint is a cybersecurity company specializing in email security, threat protection, data loss prevention, and compliance. Privately held by Thoma Bravo since 2021, it serves over 500,000 organizations including 87 of the Fortune 100.

Proofpoint currently has 11 open roles on FindRole.

Listed pay typically runs $166,500–$244,200 across 7 roles with salary data.

Most-posted roles

View all roles at Proofpoint

At a glance

TL;DR · Staff Information Security Engineer, Threat Defense & Automation

Staff Information Security Engineer - Threat Defense & Automation joins the Global Information Security Operation team as a technical leader and subject matter expert. This role focuses on shaping incident response strategy, advancing threat detection capabilities, and leading complex investigations into APTs, ransomware, insider threats, and cloud compromises. The engineer will act as an incident commander, perform proactive threat hunting across endpoint, network, identity, and cloud environments, and automate triage workflows. Key responsibilities include operationalizing threat intelligence into detections and mentoring team members. Required skills include deep expertise in DFIR and the MITRE ATT&CK framework, along with proficiency in SIEM, EDR, and SOAR tools. Candidates must possess scripting experience in Python, PowerShell, or Bash to improve security posture and drive continuous improvement through post-incident reviews and automated response systems.

What you'll do

  • Serve as a Level 3 escalation point for high-severity security incidents.
  • Lead investigations into APTs, ransomware, insider threats, and cloud compromises.
  • Act as an incident commander to coordinate response efforts across the enterprise.
  • Participate in a 24/7 on-call rotation for incident response.
  • Lead threat hunting across endpoint, network, identity, and cloud environments.
  • Operationalize threat intelligence into actionable detections and response strategies.
  • Design and improve detection capabilities across SIEM, EDR, and SOAR platforms.
  • Automate incident triage and response workflows to improve operational efficiency.

What we're looking for

  • Must be a US Citizen.
  • 12+ years of experience in Incident Response, DFIR, Threat Hunting, or Security Operations.
  • Deep expertise in incident response, threat hunting, and threat intelligence.
  • Strong knowledge of MITRE ATT&CK and adversary TTPs.
  • Experience with SIEM, EDR, SOAR, and cloud security.
  • Scripting experience in Python, PowerShell, or Bash.
  • Strong communication and leadership skills.
  • Experience building threat hunting or detection programs (preferred); background in threat intelligence or red/purple teaming (preferred); certifications such as GCFA, GCIH, CISSP, CISM, OSCP (preferred).

More like this

Similar roles

Threat Detection Security Engineer

CoStar Group

Arlington, VA +1 96 days ago $90,000–$154,000
Incident Response Sentinel Defender Azure Kubernetes Python Mitre Att&ck Automation Detection Engineering
4+ yrs exp

Senior Cyber Threat Defense Security Operations Engineer

Proofpoint

Draper, UT 46 days ago $136,200–$214,005
Incident Response SIEM SOAR EDR XDR Python PowerShell Bash MITRE ATT&CK Threat Hunting Threat Modeling AWS Microsoft Azure Google Cloud Platform Digital Forensics AI DLP STRIDE
8+ yrs exp

Lead Information Security Systems Engineer

L3Harris

Greenville, TX 10 days ago
AWS SIEM Wazuh Splunk Incident Response Detection Engineering Identity and Access Management Risk Management Framework MITRE ATT&CK Threat Hunting vulnerability-management Linux Windows Networking Cloud Security
9+ yrs exp

Lead Detection and Response Security Engineer

CoStar Group

Arlington, VA +1 40 days ago $147,000–$247,000
Incident Response MITRE ATT&CK Python PowerShell Perl Sentinel Defender Active Directory Windows Server CI/CD Threat Hunting Endpoint Security
8+ yrs exp