Staff security research engineer
About Us
We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead of bad actors and safeguard the digital world. Join us in our pursuit to defend data and protect people. How We Work At Proofpoint, you’ll be part of a global team that breaks barriers to redefine cybersecurity, guided by our BRAVE core values Bold in how we dream and innovate, Responsive to feedback, challenges, and opportunities, Accountable for results and best-in-class outcomes, Visionary in future-focused problem-solving, Exceptional in execution and impact. Corporate Overview Proofpoint is a leading cybersecurity company protecting organizations’ greatest assets and biggest risks vulnerabilities in people. With an integrated suite of cloud-based solutions, Proofpoint helps companies around the world stop targeted threats, safeguard their data, and make their users more resilient against cyber-attacks. Leading organizations of all sizes, including more than half of the Fortune 1000, rely on Proofpoint for people-centric security and compliance solutions mitigating their most critical risks across email, the cloud, social media, and the web. We are singularly devoted to helping our customers protect their greatest assets and biggest security risk their people. That’s why we’re a leader in next-generation cybersecurity. Protection Starts with People. Staff Security Research Engineer Your day-to-day- Design and develop software using a variety of languages, primarily Python, with little external guidance, while providing technical leadership to guide other software engineers on the team
- Some skill in modifying existing web-based UI for internal tools is needed to maintain and extend the sandbox submission and report UI for Proofpoint threat researchers to use
- Some work requires skill in writing C or C++ for low level interactions with the OS
- Develop and maintain web browser interaction capabilities using Chrome web driver
- Analyze and Reverse Engineer JavaScript that fingerprints web browser artifacts to identify sandbox web browsers or instrumentation, and innovate solutions to defeat those checks
- Familiarity with analyzing web front-end and the Document Object Model (DOM)
- Develop and maintain software for processing network traffic, including TLS decryption and processing PCAP files
- Work closely with threat analysts and detection engineers who research threat actors and write detection rules which run on the systems you develop
- As needed, create new detection languages and systems that allow threat researchers to develop detection rules
- Add features to existing threat detection languages to allow greater flexibility by threat researchers to automate interactions with websites and detect threat patterns
- Make use of AI Large Language Models as appropriate to enhance threat detection pipelines, produce samples to test evasion countermeasures, and make sound decisions about when applying AI is a benefit vs. a detriment to achieving goals
- Design and develop automation pipelines to turn manual tasks into automated scripts
- Stay abreast of a constantly evolving threat landscape
- Understand the latest tactics, techniques, and procedures used by threat actors to bypass detection environments, especially URL sandbox fingerprinting / detection / evasion techniques used by threat actors
- As needed, provide expert assistance and support to threat researchers and analysts as they analyze phishing websites, threat detection evasion techniques, and security research or red team demonstrations of new evasion techniques
- As needed to support sandbox countermeasure development, reverse engineering malware executable files for Windows (note primary malware reverse engineering responsibilities rest on other job roles and are not expected regularly for this role).
- Apply critical thinking skills to identify the most efficient and effective way to mitigate threats and evasions
- Work effectively as part of a remote team using chat, video chat and conference calls
- Work with other engineering teams, defining requirements, for continuous improvement of critical detection capabilities
- A passion for threat research and a well-rounded yet deep understanding of the security threat landscape and actor TTPs, especially understanding how to develop countermeasures for threat actor evasions and sandbox detection techniques
- Ability to write production-grade, reliable Python code with instrumentation that supports observability and monitoring of performance and errors is required
- Experience developing software using Docker containers is required
- Experience developing web browser automation is required
- Experience analyzing network traffic for threat detection and a solid understanding of TLS, and other network protocols used by malware is required
- Willing and able to work independently and collaboratively as part of a distributed team of industry-leading security researchers
- Ability to perform the above in a fully remote work environment
- Experience with C and C++ is a plus
- Experience developing Windows API hooks and knowing how to research undocumented Windows API internal functions is a plus
- Experience writing malware behavior signatures
- Some experience analyzing malware using a debugger, and willingness to learn is a plus
- Experience with statically reverse engineering malware using IDA Pro, Ghidra, Binary Ninja, or other reverse engineering tools is a plus, although being an expert is not required
- Ability to accurately interpret the forensic output of dynamic analysis (sandbox) environments
- Experience with a variety of publicly-available malware sandboxes (for example Cuckoo, Joe Sandbox, Any Run, Triage, etc.)
- Travel 1% - 10% (flexible) mainly for team collaboration or security conferences
- Location Canada (Remote), US (Remote), Argentina (Remote), UK (Remote), Ireland (Remote), Germany (Remote), France (Remote), Switzerland (Remote)
- Must be able to work during business hours local to your time-zone
- Competitive compensation
- Comprehensive benefits
- Learning & Development We are committed to the growth and development of our team members, offering a range of programs including leadership and professional development workshops, stretch project assignments, and mentoring opportunities to help employees reach their full potential.
- Flexible work environment [Remote options, hybrid schedules, flexible hours, etc.].
- Annual wellness and community outreach days
- Always on recognition for your contributions
- Global collaboration and networking opportunities
Recommended Jobs
Post fellow of medicine environmental and public health sciences
Current UC employees must apply internally via SuccessFactors Next Lives at the University of Cincinnati Founded in 1819, the University of Cincinnati ranks among the nation’s best urban …
Now Hiring | Warehouse Worker | $21.50
Job Title Warehouse Associate Shift:2nd Shift Pay Rate:$21.50/hour Location: Cuyahoga Falls, Ohio Position Overview We are seeking a reliable and motivated Warehouse Associate to joi…
Software Engineer (Remote Ohio)
Software Engineer (Remote Ohio) Location Troy, OH : Company Description: Crown Equipment Corporation is a leading innovator in world-class forklift and material handling equipment and technology. Cr…
Mobile Operation Technician, Hoxworth Donor Services, Mobile Units
Current UC employees must apply internally via SuccessFactors You are invited to submit an application to be considered for one of multiple vacancies of the same position. Next Lives a…
Commercial Roofing Service Technician/ Helper
Job Description Job Description Are you a seasoned professional with a passion for customer service, quality, and safety? Join our team as a Commercial Service Technician/ Helper! We are seekin…
Urgent Care - Eastern Oregon - 3-day workweek - Loan Repayment
Join a critical access hospital with 80 employed physicians and 700 employees in La Grande, OR. Hospital is looking for an urgent care provider. Practice Details ~ Urgent Care is open 8A to 8P…
Data Entry Clerk
Job Description Job Description Job Description: We are seeking a detail-oriented and reliable Data Entry Clerk to join our team. In this role, you will be responsible for accurately entering,…
Full Time Urgent Care Physician Job Portsmouth, OH
You will enjoy working in this small Midwest town where the outdoor activities are endless, the cost of living is affordable, and the people are sincere and friendly. You will appreciate the peace of …
Production associate
Are you looking for a stable job with great benefits and pay? Consider becoming part of the Avient team! We know your time is valuable and you have a lot of job ads to review. Let us brea…
Certified Nurse Practitioner - Wound Care - Cleveland Ohio Akron
Certified Nurse Practitioner - Wound Care Specialty Reports To: Medical Director Wound Care Division Compensation: Highly competitive base salary ($115k-$125k+) ** We are open to paying a high…