Proofpoint Email Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Monitor Proofpoint dashboards, alerts, quarantine queues, digest activity, abuse mailboxes, and user-reported phishing submissions.
- Triage and investigate email threats including phishing, business email compromise (BEC), impersonation, malware delivery, spam, and fraudulent communications.
- Determine risk using email artifacts such as headers, sender reputation, authentication results (SPF/DKIM/DMARC), URLs, attachments, domains, and message content.
- Use Proofpoint search / message tracking capabilities to identify campaign scope and locate malicious messages across impacted mailboxes.
- Execute containment actions in Proofpoint: block/deny-list malicious senders, domains, URLs, and other indicators; manage allow/deny logic where appropriate.
- Drive remediation and takedown actions (e.g., message removal guidance, user notification, escalation to IR/SOC when needed).
- Administer and continuously tune Proofpoint policies, detection rules, and protection controls to improve efficacy and reduce false positives.
- Review quarantined messages and determine whether messages should be released, blocked, or escalated, documenting rationale and outcomes.
- Maintain and refine block lists, allow lists, and exception workflows with strong change control and documentation.
- Monitor and assist with SPF, DKIM, and DMARC posture to reduce spoofing/impersonation risk.
- Identify misconfigurations and coordinate corrective actions with domain owners, Microsoft 365 administrators, and relevant business stakeholders.
- Support investigations involving account compromise, suspicious mailbox rules/forwarding, unusual email access patterns, and suspicious outbound activity.
- Coordinate with SOC, IAM, Incident Response, Microsoft 365, Legal, HR, and business leaders during sensitive investigations.
- Document investigation steps, findings, remediation actions, recurring attack patterns, and lessons learned.
- Create and maintain SOPs and response playbooks for Proofpoint-driven workflows (triage, quarantine review, campaign response, indicator blocking).
- Track and report email-security metrics: message volume, blocked threats, phishing trends, user reporting rates, false positives, remediation SLAs, and emerging TTPs.
- Identify opportunities to automate repetitive tasks across investigation, containment, and reporting.
- Support email-security projects such as Proofpoint enhancements, platform upgrades, policy changes, onboarding new domains/business units, and M&A-related integration.
Requirements
- Demonstrated experience using Proofpoint in an operational security role (monitoring, quarantine triage, investigations, policy tuning).
- Strong knowledge of phishing/BEC tradecraft and email analysis (headers, routing, URLs/attachments, domain reputation).
- Working understanding of Microsoft 365 / Exchange Online concepts and email authentication (SPF/DKIM/DMARC).
- Strong analytical skills, attention to detail, sound judgment, and clear communication with both technical and non-technical users.
- Ability to document work cleanly and operate effectively in an alert-driven environment.
Benefits & conditions
Estimated Min Rate: $45.50 Estimated Max Rate: $65.00
What’s In It for You?
We welcome you to be a part of the largest and legendary global staffing companies to meet your career aspirations. Yoh’s network of client companies has been employing professionals like you for over 65 years in the U.S., UK and Canada. Join Yoh’s extensive talent community that will provide you with access to Yoh’s vast network of opportunities and gain access to this exclusive opportunity available to you. Benefit eligibility is in accordance with applicable laws and client requirements. Benefits include:
- Medical, Prescription, Dental & Vision Benefits (for employees working 20+ hours per week)
- Health Savings Account (HSA) (for employees working 20+ hours per week)
- Life & Disability Insurance (for employees working 20+ hours per week)
- MetLife Voluntary Benefits
- Employee Assistance Program (EAP)
- 401K Retirement Savings Plan
- Direct Deposit & weekly epayroll
- Referral Bonus Programs
- Certification and training opportunities
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The Overflow: Security and Privacy
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 164: AI Agents, AI Blindspots and MCP security problems