> Markdown version of [/jobs/ext/2707072-security-engineer](https://www.wearedevelopers.com/jobs/ext/2707072-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Net2Source - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Agile Methodology, Microsoft Azure, Configuration Management Databases, CompTIA Security+, Cyber Security, Information Systems, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Domain Name System (DNS), Email Filtering, Email Management, Microsoft Exchange Server, Internet Security, Simple Mail Transfer Protocols, Open Web Application Security, Azure Active Directory, Phishing, Service Pack, Security Information and Event Management, Virtual Machines, Software Vulnerability Management, Transport Layer Security, Office365, Malware, Sender Policy Framework (SPF), Information Technology, Front End Software Development, CIS Benchmarks, Qualys, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-security-engineer-proofpoint-vm-new-york-ny--0902b8cf-d520-4c93-b878-5574cb9fa856 ## About the Role 5 to 8 years of experience in cybersecurity operations, email security, vulnerability management, or incident response. Hands-on experience with Proofpoint solutions such as PPS, TAP, TRAP, DLP, URL Defense, and Attachment Defense. Working knowledge of phishing analysis, email threat campaigns, malware indicators, and malicious payload investigation. Experience with vulnerability scanning tools such as Qualys, Tenable, Rapid7, Wiz, or similar platforms. Understanding of CVE, CVSS, remediation prioritization, patching workflows, and risk-based vulnerability management. Basic understanding of incident response lifecycle, alert triage, evidence collection, escalation, and documentation. Familiarity with Microsoft 365, Exchange Online, hybrid mail environments, SMTP, DNS, TLS, and mail-flow routing. Exposure to CrowdStrike Falcon endpoint security is preferred. Good to Have Knowledge of SIEM/SOAR workflows and SOC operations. Exposure to CrowdStrike Falcon, Defender, or other EDR tools. Understanding of CIS benchmarks, OWASP, NIST, and secure configuration standards. Certifications such as Security+, CEH, Proofpoint Certified Administrator, or equivalent cybersecurity certifications. Soft Skills Good communication and documentation skills. Ability to work with multiple technical teams and stakeholders. Strong analytical mindset and attention to detail. Ability to work in a fast-paced global delivery environment. Education Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field.?, Administrative Skills, Agile Programming Methodologies, Analysis Skills, Benchmarking, CEH - Certified Ethical Hacker, Campaigns, Communication Skills, CompTIA Security+, Computer Science, Computer Security, Cryptography, DNS (Domain Name System), Detail Oriented, Documentation, Email Management/Administration, Email Security, Endpoint Security, Establish Priorities, IT Service Management (ITSM), Incident Response, Industry/Trade Analysis, Information Technology & Information Systems, Internet Security, Leadership, Malware, Microsoft Exchange Server, Microsoft Windows Azure, Operational Audit, Operations Security (OPSEC), Phishing, Reporting Dashboards, Reporting Skills, Risk, SMTP (Simple Mail Transfer Protocol), SSL-TLS (Secure Socket Layer - Transport Layer Security), Security Analysis, Security Information and Event Management (SIEM), Security Infrastructure, Security Monitoring, Service Level Agreement (SLA), Software Patches, Spam Filtering, Support Documentation, Team Player, U.S. National Institute of Standards and Technology (NIST), Virtual Machine (VM), Vulnerability Scanners, Wheel/Front-End Loader, Work From Home ## Description We are looking for a Security Engineer with hands-on experience in Proofpoint Email Security, Vulnerability Management, and Incident Response skills. The candidate will support day-to-day security operations, email threat monitoring and remediation, vulnerability tracking, remediation coordination, and incident handling. Exposure to CrowdStrike Endpoint Security will be considered an added advantage. Primary Skills Proofpoint Email Security administration and platform support Vulnerability Management ( Tenable or Qualys preferably ) Incident Response Email threat analysis and phishing investigation Vulnerability remediation tracking and reporting Secondary Skills CrowdStrike Falcon Endpoint Security Endpoint detection and response support Basic threat hunting and endpoint alert triage Key Responsibilities Administer and support Proofpoint email security platforms, including PPS, TAP, TRAP, URL Defense, Attachment Defense, and related email protection controls. Monitor email security health, investigate phishing or malicious email alerts, and support remediation of email-based threats. Configure and maintain email security policies such as spam filtering, impersonation protection, DLP, encryption, SPF, DKIM, and DMARC. Support Vulnerability Management activities including scan review, vulnerability validation, risk prioritization, remediation tracking, and SLA follow-up. Work with application, infrastructure, and security teams to coordinate patching and closure of vulnerabilities. Assist in Incident Response activities by analyzing alerts, gathering evidence, supporting containment, and documenting incident outcomes. Prepare regular reports, dashboards, and service health summaries for operational and leadership review. Support integration of security tools with SIEM, SOAR, Azure AD, M365, ITSM, or CMDB platforms where applicable. Provide secondary support for CrowdStrike Falcon endpoint security alerts, endpoint investigation, and coordination with endpoint or SOC teams. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)