Endpoint & Email Security Engineer
الوصف الوظيفي
Position Overview
We are seeking a highly skilled and proactive Endpoint & Email Security Engineer to join our cybersecurity team. In this critical role, you will be responsible for safeguarding our organization’s digital infrastructure by administering, optimizing, and securing our endpoint and email security platforms. Your expertise will be instrumental in defending against evolving cyber threats, ensuring the integrity of corporate devices, and maintaining robust email security protocols. This position requires a deep understanding of cybersecurity principles, hands-on technical proficiency, and the ability to collaborate effectively with cross-functional teams to mitigate risks and enhance our security posture.
Key Responsibilities
The Endpoint & Email Security Engineer will play a pivotal role in protecting our organization from cyber threats through the following core responsibilities:
Endpoint Security Operations
- Platform Administration: Manage, maintain, and optimize enterprise Endpoint Detection and Response (EDR/XDR) and Endpoint Protection Platform (EPP) solutions to ensure robust protection against malware, ransomware, and advanced threats.
- Threat Monitoring & Investigation: Continuously monitor endpoint security alerts, investigate suspicious activities, and perform malware analysis to identify and neutralize potential threats.
- Incident Response & Remediation: Lead containment, eradication, and recovery efforts for compromised endpoints, coordinating with Desktop Support and Infrastructure teams to restore secure operations.
- Policy Management: Develop, implement, and enforce endpoint security policies, including antivirus configurations, device control, application whitelisting, host firewall rules, and system hardening measures.
- Compliance & Health Monitoring: Ensure endpoint protection agents are deployed, operational, and up to date across the enterprise while monitoring compliance with security standards and resolving deployment or health issues.
Email Security Operations
- Platform Administration: Oversee the enterprise email security platform and secure email gateway, ensuring robust protection against phishing, spam, malware, and business email compromise (BEC) attacks.
- Threat Detection & Analysis: Monitor, investigate, and remediate phishing attempts, spoofing, impersonation attacks, and malicious attachments or URLs by analyzing email headers, content, and metadata.
- Policy Optimization: Manage email filtering, quarantine policies, and threat protection rules while fine-tuning detection mechanisms to minimize false positives and maximize threat detection accuracy.
- Email Authentication & Security: Implement and monitor SPF, DKIM, and DMARC protocols to enhance email security and prevent domain spoofing and impersonation attacks.
- Phishing Response & Awareness: Coordinate phishing campaign remediation efforts and provide technical support for security awareness initiatives to educate users on identifying and reporting suspicious emails.
Incident Response & Continuous Improvement
- Incident Investigation: Lead the investigation of endpoint and email security incidents, executing containment, eradication, and recovery procedures in accordance with established response protocols.
- Documentation & Reporting: Maintain detailed records of incident findings, evidence, and remediation actions while escalating complex issues to senior security engineers or the SOC as needed.
- Threat Intelligence Integration: Monitor emerging threats targeting endpoints and email systems, develop new detection use cases based on threat intelligence, and participate in proactive threat hunting activities.
- Process Enhancement: Recommend improvements to endpoint and email security controls, automate repetitive tasks to enhance operational efficiency, and support the development of incident response playbooks.
Platform Administration & Collaboration
- System Maintenance: Perform configuration, maintenance, and upgrades of endpoint and email security platforms while ensuring seamless integration with SIEM, SOAR, Identity, and IT Service Management (ITSM) systems.
- Cross-Functional Collaboration: Work closely with the Security Operations Center (SOC), Infrastructure, Messaging, Identity, and End User Computing teams to align security strategies and address operational challenges.
- Troubleshooting & Support: Diagnose and resolve operational issues affecting security tools, maintain up-to-date documentation, and provide guidance on best practices for endpoint and email security.
Qualifications & Skills
To excel in this role, candidates should possess the following qualifications and competencies:
- Technical Expertise: Proficiency in endpoint security solutions (EDR/XDR, EPP), email security platforms, and security frameworks such as NIST or ISO 27001.
- Certifications: Relevant certifications such as CISSP, CEH, CompTIA Security+, or vendor-specific certifications (e.g., Microsoft, CrowdStrike, Proofpoint) are highly desirable.
- Analytical Skills: Strong problem-solving abilities with experience in malware analysis, incident response, and forensic investigations.
- Communication & Collaboration: Excellent written and verbal communication skills to document findings, report incidents, and collaborate with stakeholders at all levels.
- Automation & Scripting: Familiarity with scripting languages (Python, PowerShell) and automation tools to streamline security operations.
This role offers a unique opportunity to contribute to the security resilience of a dynamic organization while working alongside a talented team of cybersecurity professionals. If you are passionate about protecting digital assets and thrive in a fast-paced, collaborative environment, we encourage you to apply.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.