Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Cyber Threat Defense - Security Operations Engineer

Proofpoint Inc

About Us:Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people.How We Work:At Proofpoint you’ll be part of a global team that breaks barriers to redefine cybersecurity guided by our BRAVE core values: Bold in how we dream and innovateResponsive to feedback, challenges and opportunitiesAccountable for results and best in class outcomesVisionary in future focused problem-solvingExceptional in execution and impactAbout Proofpoint At Proofpoint, we protect organizations and individuals from today's most advanced cyber threats. Through innovative security technologies, threat intelligence, and a global team of security experts, we help customers defend against phishing, malware, account compromise, insider threats, and data loss. Role Overview We are seeking an experienced Senior Cyber Threat Defense - Security Operations Engineer to join our global security team in Draper, UT. This critical role sits within the Global Information Security Operation team and is responsible for investigating and responding to sophisticated security incidents across Proofpoint's global operations. You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC), own complex investigations and technical decisions, participate in a scheduled on-call rotation, and set direction for detection, investigation, response, threat modeling, and security automation. The role also supports selected AI-enabled capabilities, including Agentic SOC workflows and AI Data Loss Prevention (AI DLP). Key Responsibilities:Incident Response and Escalation Own Level 3 escalation for high-severity and technically complex incidents within the global 24/7 SOC. Lead major investigations involving malware, ransomware, phishing, identity attacks, insider threats, cloud compromise, and advanced persistent threats. Set containment, eradication, recovery, remediation, and post-incident improvement strategy, balancing risk and business impact. Direct response across Security, IT, Cloud Engineering, Legal, Privacy, and business leaders, and communicate incident status and decisions to executives. Participate in a scheduled on-call rotation and provide after-hours support for critical security incidents, including nights, weekends, and holidays as required. Threat Hunting, Modeling, and Detection Engineering Proactively hunt for hidden threats across endpoints, identities, networks, cloud environments, SaaS applications, and data repositories. Lead cross-functional threat modeling for new and existing systems, cloud services, and security workflows to identify abuse cases, attack paths, and control gaps. Use threat intelligence and behavioral analytics to identify suspicious activity and emerging attack patterns. Develop, test, tune, and maintain detection rules, correlations, hunting queries, and response use cases. Translate threat intelligence and MITRE ATT&CK techniques into actionable detection and hunting use cases. Security Automation and Orchestration Define and implement automation strategy for alert enrichment, prioritization, triage, containment, notification, and remediation. Use SOAR platforms and security APIs to streamline repeatable incident-response activities. Develop scripts, integrations, and automation using Python, PowerShell, Bash, or similar languages. Optimize SIEM log ingestion, normalization, correlation, retention, and alerting. Emerging Security Capabilities Support practical Agentic SOC use cases for alert triage, investigation enrichment, case documentation, and response under defined human oversight. Help operate AI DLP controls that reduce sensitive-data exposure through generative AI applications and copilots. Continuous Improvement Own root-cause analysis and drive improvements to security controls, telemetry, processes, and architecture. Partner with security architects and engineering leaders to set technical direction and evaluate detection and response technologies. Mentor engineers and analysts, establish investigation standards, and raise technical capability across the SOC. Required Qualifications and Experience Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations. U.S. citizenship. Demonstrated experience leading major incidents and serving as the final technical escalation point for complex or high-severity security events. Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, and security monitoring. Experience investigating malware, phishing, identity attacks, cloud compromise, insider threats, data loss, and advanced persistent threats. Hands-on experience with SOAR platforms, APIs, and scripting languages such as Python, PowerShell, or Bash. Strong understanding of the MITRE ATT&CK framework, attacker tactics, techniques, and procedures, and the cyber kill chain. Experience applying threat modeling methods such as STRIDE, attack trees, or MITRE ATT&CK to enterprise or cloud systems. Experience creating or tuning detection rules, hunting queries, and response playbooks. Working knowledge of cloud security across AWS, Microsoft Azure, or Google Cloud Platform. Proven ability to own technical strategy, influence architecture and control decisions, and drive cross-functional security improvements. Strong executive communication, analytical, troubleshooting, and documentation skills, with the ability to make sound decisions during high-pressure incidents. Willingness and ability to participate in an on-call rotation and respond to critical incidents outside normal business hours, including nights, weekends, and holidays as required. Preferred Qualifications Experience with Agentic SOC, AI-assisted investigation, or AI DLP capabilities. Experience with identity, cloud, or data detection and response technologies. Experience leading incident simulations, purple-team exercises, or adversary-emulation activities. Relevant certifications such as GCIH, GCFA, CISSP, CISM, OSCP, GIAC, or cloud-security certifications. #LI-AN2Why Proofpoint?At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you’ll love working with us:Competitive compensationComprehensive benefitsCareer success on your termsFlexible work environmentAnnual wellness and community outreach daysAlways on recognition for your contributionsGlobal collaboration and networking opportunitiesOur Culture:Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone.We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to View email address on click.appcast.io to ApplyInterested? Submit your application along with any supporting information- we can’t wait to hear from you!Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and/or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.Base Pay Ranges:SF Bay Area, New York City Metro Area:Base Pay Range: 136,200.00 - 214,005.00 USDCalifornia (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska:Base Pay Range: 112,700.00 - 177,100.00 USDAll other cities and states excluding those listed above:Base Pay Range: 101,600.00 - 159,720.00 USDSummaryLocation: Draper, UTType: Full time

Vacancy posted 13 hours ago
Similar jobs that could be interesting for youBased on the Senior Cyber Threat Defense - Security Operations Engineer in Draper, UT vacancy
  •  ...Proofpoint to stop threats, prevent data loss...  ...people to work securely and confidently. Join...  ...individuals from cyber threats through innovative...  ...Security Engineer to help lead and evolve...  ...Security Operation. In this role, you...  ...threat detection and defense capabilities, and... 
    Cyber
    Full time
    Work at office
    Flexible hours

    Proofpoint

    Draper, UT
    13 hours ago
  • What does the Sr. IT Security Engineer, Operations & Engineering do at Swire Coca-Cola? A Senior IT Security Engineer in Operations & Engineering...  ...:Support security monitoring, threat detection, and incident...  ...vulnerabilities and reduce cyber riskAnalyze security findings... 
    Cyber
    Senior

    Swire Coca-Cola

    Draper, UT
    1 day ago
  • $91k - $120k

     ...where individuality is noticed and valued every day.Cyber Operations Engineer IIIJob Summary:We are seeking a Security Engineer with expertise in security automation,...  ...-functional teams—including security operations, threat intelligence, and development—to deliver robust... 
    Cyber
    Full time
    Remote work
    Work from home
    Flexible hours

    Conduent

    Sandy, UT
    2 days ago
  • $168.2k - $310.1k

    The Challenge Our Adobe Cyber Defense Center is seeking a highly...  ...Incident Responder. This senior role is pivotal in our incident...  ...against evolving cyber threats. You will work with a...  ...Linux, MacOS, and Windows operating systems. Cloud Security: Extensive experience in... 
    Cyber
    Full time
    Temporary work
    Local area
    Worldwide

    Adobe Systems

    Lehi, UT
    4 days ago
  •  ...Proofpoint to stop threats, prevent data loss...  ...people to work securely and confidently. Join...  ...Commercial Sales Engineering team are highly valued...  ...against today’s cyber threats. You will...  ...Engineer or senior level product support...  ...assessments, security operations, and policy... 
    Cyber
    Senior
    Full time
    Work at office
    Remote work
    Night shift

    Proofpoint

    Draper, UT
    18 hours ago
  • $144.8k - $261.45k

    The Challenge The Adobe Cyber Defense Center is looking for a Security Incident Responder to play an important role...  ...cybersecurity incident response team. Cyber threats are evolving, and perimeter...  .... You will work closely with senior incident responders and analysts to... 
    Cyber
    Senior
    Full time
    Temporary work
    Local area
    Worldwide

    Adobe Systems

    Lehi, UT
    4 days ago
  •  ...documented to support dispositions. Security Operations: Participate in rotational...  ..., including incident response, cyber threat hunting, and detection engineering. Continuous Improvement:...  ...active member of a global 24x7 cyber defensive operations team, which will... 
    Cyber
    Weekend work

    MW Partners

    Lehi, UT
    3 days ago
  • $120k - $180k

     ...come join us.THE ROLEAs a Security Operations Engineer in the Global Information Security...  .... You will report to the Senior Security Operations Manager...  ...alerts.Validate & Simulate Defenses: Execute targeted adversary...  ...have eliminated critical threats.WHAT YOU BRINGSecurity... 
    Work at office
    Flexible hours
    Shift work

    Pure Storage

    Lehi, UT
    2 days ago
  • $75k - $90k

     ...Cyber Defense Analyst UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security...  ...from today's dynamic threat landscape, UltraViolet Cyber...  ...diversified stakeholders and engineering teams using clear data... 
    Cyber
    Temporary work
    Shift work

    UltraViolet Cyber

    Lehi, UT
    1 day ago
  •  ...Trusted Disruptor in defense tech. With...  ...land, sea and cyber domains in the...  ...interest of national security. Job Title:...  ..., Electrical Engineer (Digital...  ...seeking a motivated Senior Hardware Engineer...  ...for special operations and intelligence...  ...areas such as threat deterrence, signals... 
    Cyber
    Local area

    L3Harris Technologies

    Riverton, UT
    1 day ago
  •  ...risks for advisory engagements Provide insights into IT and cyber risk exposures, control design, and governance effectiveness....  ...audits, as necessary. Understanding of financial institution operations and transactions. Ability to communicate effectively and courteously... 
    Cyber
    Senior
    Work at office
    Remote work
    Monday to Friday
    3 days per week

    Mountain America Credit Union

    Sandy, UT
    18 hours ago
  •  ...Senior Application Security Engineer American Fork, Utah, United States LVT is redefining how businesses operate in the physical world, moving beyond traditional...  ...and scaling our defenses alongside our rapid growth...  ...initiatives including threat modeling, deep-dive... 
    Senior
    Full time
    Work at office
    Flexible hours

    LVT Corp

    American Fork, UT
    3 days ago
  •  ...experienced Director of Cyber Security to lead a...  ...thinker who can also guide operational execution across governance...  ...against evolving threats.• Lead the design and...  ...security architecture and engineering to ensure...  ...dashboards, and reporting for senior leadership to... 
    Cyber
    For contractors

    Robert Half

    Draper, UT
    1 day ago
  • $131k - $197k

     ...come join us.THE ROLEAs a Senior Security Architect at Everpure, you...  ...environments. Partnering closely with engineering and security teams, you...  ...strict protection with operational scalability and product...  ...Environments: Define, promote, and threat-model secure design... 
    Senior
    Work at office
    Flexible hours

    Pure Storage

    Lehi, UT
    4 days ago
  •  ...is the Trusted Disruptor in defense tech. With customers’ mission...  ...the space, air, land, sea and cyber domains in the interest of national security. Job Title: Engineering Technician C Job Code: 386...  ...instructions while supporting the operation and testing of complex... 
    Cyber
    Local area
    Day shift

    L3Harris Technologies

    Riverton, UT
    4 days ago
  •  ...Tester to join our offensive security team. In this role, you will think...  ...comprehensive red team operations and objective-based testing to...  ...Remediation: Partner closely with Cyber Threat Intelligence, Incident Response, Detection Engineering and development groups to provide... 
    Cyber
    Work at office
    Work from home
    Flexible hours
    3 days per week

    Zions Bancorporation

    Midvale, UT
    3 days ago
  •  ...the Trusted Disruptor in defense tech. With customers mission...  ..., air, land, sea and cyber domains in the interest of national security. Job Title: Specialist, Systems Engineer Job Code: 39234...  ...technical support during the operational life cycle of the system.... 
    Cyber
    For subcontractor
    Local area

    L3Harris Technologies

    Sandy, UT
    1 day ago
  •  ...organizations trust Proofpoint to stop threats, prevent data loss, and build...  ...and empower people to work securely and confidently. Join us in...  ...for a highly motivated Senior Revenue Accountant to join our...  ...Proficient technical and operational knowledge of ASC 606 and multiple... 
    Senior
    Full time
    Work at office
    Flexible hours

    Proofpoint

    Draper, UT
    1 day ago
  •  ...organizations trust Proofpoint to stop threats, prevent data loss, and build...  ...and empower people to work securely and confidently. Join us in...  ...for a highly motivated Senior Revenue Accountant II to join...  ...required Proficient technical and operational knowledge of ASC 606 and... 
    Senior
    Full time
    Contract work
    Work at office
    Flexible hours

    Proofpoint

    Draper, UT
    1 day ago
  •  ...Description Job Description Senior Application Security Engineer Canopy, South Jordan,...  ...turning it into shipped, operational reality alongside...  ...AI is reshaping both the threats we defend against and the...  ...authentication and application-layer defenses, including anti-abuse... 
    Senior
    Remote work

    Canopy

    Draper, UT
    22 days ago
  •  ...the Trusted Disruptor in defense tech. With customers’ mission...  ...space, air, land, sea and cyber domains in the interest of national security. Job Title: Associate, Systems Engineer Job Code: 39649 Job...  ...Essential Functions: ~ Perform operational analysis and develop... 
    Cyber
    Local area

    L3Harris Technologies

    Sandy, UT
    1 day ago
  • $98.9k - $155.43k

     ...organizations trust Proofpoint to stop threats, prevent data loss, and build...  ...and empower people to work securely and confidently. Join us in...  ...a motivated and experienced Senior Deal Desk Analyst to join our...  ..., Revenue, Legal, Sales Operations, Order Management, Channel, Product... 
    Senior
    Work at office
    Flexible hours

    Proofpoint

    Draper, UT
    2 days ago
  •  ...the Trusted Disruptor in defense tech. With customers’...  ...space, air, land, sea and cyber domains in the interest of national security. Job Title: Manufacturing...  .... The position operates in a moderately structured...  ...process, partnering with engineers on equipment setup and calibration... 
    Cyber
    Local area
    Night shift
    Weekend work
    Day shift

    L3Harris Technologies

    Draper, UT
    3 days ago
  •  ...DevSecOps Engineer We are looking for a passionate, collaborative and driven DevSecOps...  ...contributing the DevSecOps team within Risk and Security. Influence and drive security standards...  ...make recommendations on security risks, threats, and issues. Build relationships with... 
    Senior

    Samprasoft

    Draper, UT
    3 days ago
  •  ...Job Description Job Description Position Description: Mountain West Financial is hiring a senior IT and Security Engineer to be the technology anchor in our Draper office. You will own on-site IT and endpoint engineering and help run our security and compliance program... 
    Senior
    Work at office
    Remote work

    Mountain West Financial, LLC

    Sandy, UT
    13 days ago
  •  ...retail brands. A Fortune 500 company, operating in the United States and Canada, NRG delivers...  ..., documenting, and implementing AI security standards, controls, and best practices...  ...2+ years of experience in software engineering, data engineering, or a related technical... 
    Senior
    Work experience placement
    Work at office
    Remote work

    NRG Energy

    Lehi, UT
    4 days ago
  •  ...Senior Enterprise Software Sales Anonyome Labs is creating a...  ...changing the identity, privacy and cyber safety paradigm—and resolving...  ...with global leaders in the security and privacy space....  ...also understand how business operates, including role of structure,... 
    Cyber
    Senior
    Temporary work
    Work at office

    Anonyome Labs, Inc.

    South Jordan, UT
    3 days ago
  • Remote Operations Engineer Full-Time, Permanent Sandy, UT (In-person)Graymont currently has an opening for the position of Remote Operations Engineer in the Sandy, Utah Remote Operations Center (ROC). The ROC is staffed with Remote Operations Engineers who remotely operate... 
    Permanent employment
    Full time
    Remote work
    Shift work
    Night shift
    Rotating shift
    Weekend work
    Day shift

    Graymont

    Sandy, UT
    3 days ago
  • $144.8k - $261.45k

     ...MissionThe team focuses on Identity Architecture & Solutions by crafting, building, and operationalizing scalable identity and SaaS security capabilities enterprise-wide. This technical role depends on members passionate about Identity & SaaS Security functions, identity... 
    Senior
    Full time
    Temporary work
    Local area
    Worldwide

    Adobe Systems

    Lehi, UT
    1 day ago
  • $114k - $148.2k

    Operations is at the heart of Amazon’s business. We are known for our speed, accuracy, and...  ...every day. The Reliability & Maintenance Engineering (RME) team are the business partners that...  ...us on our journey!About the Role:As a Senior Automation Engineer, you will play a crucial... 
    Senior
    Remote work
    Worldwide
    Flexible hours
    Shift work
    Night shift

    Amazon

    West Jordan, UT
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Cyber Threat Defense - Security Operations Engineer. Be the first to apply!