|
Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title: Senior Security Engineer - Proofpoint & VM Location(s): Chicago, IL (Remote) Position Summary We are seeking a Senior Security Engineer with strong hands-on experience in Proofpoint Email Security, Vulnerability Management, and Incident Response. The engineer will support day-to-day security operations, email threat monitoring and remediation, vulnerability assessment and tracking, remediation coordination, and incident handling. Experience with CrowdStrike Falcon Endpoint Security is preferred and will be considered an added advantage. Primary Skills
- Proofpoint Email Security administration and platform support
- Vulnerability Management using Tenable, Qualys, or similar platforms
- Incident Response and security alert triage
- Email threat analysis and phishing investigation
- Vulnerability remediation tracking and reporting
Secondary Skills
- CrowdStrike Falcon Endpoint Security
- Endpoint Detection and Response (EDR)
- Basic threat hunting and endpoint alert triage
Key Responsibilities
- Administer and support Proofpoint email security solutions, including PPS, TAP, TRAP, URL Defense, Attachment Defense, DLP, and related email protection controls.
- Monitor email security health and investigate phishing, malicious email, malware, and other email-based security threats.
- Configure and maintain email security policies, including spam filtering, impersonation protection, DLP, encryption, SPF, DKIM, and DMARC.
- Perform vulnerability management activities, including vulnerability scan review, validation, risk prioritization, remediation tracking, and SLA follow-up.
- Coordinate with application, infrastructure, endpoint, and security teams to drive vulnerability remediation and closure.
- Assist with Incident Response activities, including alert analysis, evidence collection, containment support, escalation, and incident documentation.
- Analyze phishing campaigns, malicious payloads, indicators of compromise (IOCs), and other email-related threats.
- Prepare operational reports, dashboards, vulnerability metrics, and security service health summaries for management and leadership review.
- Support integration of security tools with SIEM, SOAR, Microsoft 365, Azure AD/Entra ID, ITSM, and CMDB platforms where applicable.
- Provide secondary support for CrowdStrike Falcon alerts, endpoint investigations, threat analysis, and coordination with SOC or endpoint teams.
- Contribute to continuous improvement of security monitoring, vulnerability remediation, and incident response processes.
Required Qualifications and Experience
- 5-8 years of experience in cybersecurity operations, email security, vulnerability management, incident response, or a related security discipline.
- Strong hands-on experience administering and supporting Proofpoint solutions such as PPS, TAP, TRAP, DLP, URL Defense, and Attachment Defense.
- Practical experience with phishing analysis, email threat campaigns, malware indicators, and malicious payload investigation.
- Experience with vulnerability management platforms such as Qualys, Tenable, Rapid7, Wiz, or similar tools.
- Strong understanding of CVEs, CVSS scoring, vulnerability prioritization, remediation workflows, patch management, and risk-based vulnerability management.
- Working knowledge of the Incident Response lifecycle, including alert triage, evidence collection, containment, escalation, documentation, and post-incident activities.
- Familiarity with Microsoft 365, Exchange Online, hybrid mail environments, SMTP, DNS, TLS, and email routing/mail-flow concepts.
- Exposure to CrowdStrike Falcon Endpoint Security is preferred.
- Ability to analyze security events and coordinate remediation across multiple technical teams.
Good to Have
- Knowledge of SIEM/SOAR workflows and SOC operations.
- Experience with CrowdStrike Falcon, Microsoft Defender, or other EDR platforms.
- Understanding of CIS Benchmarks, OWASP, NIST frameworks, and secure configuration standards.
- Relevant cybersecurity certifications such as Security+, CEH, Proofpoint Certified Administrator, or equivalent.
Soft Skills
- Strong analytical and problem-solving skills.
- Excellent communication and technical documentation abilities.
- Strong attention to detail.
- Ability to collaborate effectively with multiple technical teams and stakeholders.
- Ability to work independently in a fast-paced, global security operations environment.
Education
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Security, or a related field.
Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veterans or individuals with disabilities.
|