1

Phishing Email Analyst Jobs (NOW HIRING)

Assists with security-related user reports, including phishing email analysis and response. Essential Functions: Customer Service Technical Support: Serve as the primary point of contact for ...

Assists with security-related user reports, including phishing email analysis and response. Essential Functions: Customer Service Technical Support: Serve as the primary point of contact for ...

Identify and triage benign, spam, exercise, and malicious phishing email. * Perform binary artifact ... Coordinate and collaborate with Department teams as needed to analyze and respond to events and ...

Phishing Analysts have a keen eye for detail and a natural ability to spot social engineering ... You will be responsible for reviewing suspicious emails, performing open-source research, and ...

Identify and triage benign, spam, exercise, and malicious phishing email. * Perform binary artifact ... Coordinate and collaborate with Department teams as needed to analyze and respond to events and ...

Identify and triage benign, spam, exercise, and malicious phishing email. * Perform binary artifact ... Coordinate and collaborate with Department teams as needed to analyze and respond to events and ...

Identify and triage benign, spam, exercise, and malicious phishing email. * Perform binary artifact ... Coordinate and collaborate with Department teams as needed to analyze and respond to events and ...

Identify and triage benign, spam, exercise, and malicious phishing email. * Perform binary artifact ... Coordinate and collaborate with Department teams as needed to analyze and respond to events and ...

next page

Showing results 1-20

Phishing Email Analyst information

See salary details

$31K

$73.3K

$130K

How much do phishing email analyst jobs pay per year?

As of Sep 14, 2026, the average yearly pay for phishing email analyst in the United States is $73,261.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,500.00 and $87,000.00 per year, depending on experience, location, and employer.

What is a phishing email analyst?

Phishing Email Analysts are cybersecurity professionals who specialize in identifying, analyzing, and responding to phishing emails. Their primary role is to detect suspicious emails, investigate their origins and intent, and help protect organizations from email-based cyber threats. They often collaborate with IT and security teams to develop strategies and training programs that minimize the risk of phishing attacks. By analyzing trends and reporting incidents, they contribute to enhancing the overall security posture of a company.

What skills and qualifications are needed to be a phishing email analyst?

To thrive as a Phishing Email Analyst, you need strong analytical skills, knowledge of cybersecurity principles, and experience with threat detection—often supported by degrees in IT or cybersecurity and relevant certifications. Familiarity with email security gateways, SIEM tools, and phishing simulation platforms is typically required. Attention to detail, critical thinking, and effective communication are vital soft skills in this role. These competencies enable accurate identification and response to phishing threats, helping protect organizations from cyberattacks.

What challenges do phishing email analysts face in identifying sophisticated phishing attempts?

Phishing Email Analysts often encounter challenges with increasingly sophisticated phishing campaigns that use advanced social engineering tactics and mimic legitimate communications. Attackers may employ tactics like domain spoofing, well-crafted language, and even personalized details to evade detection. Analysts must stay vigilant, continuously update their knowledge on emerging threats, and collaborate closely with IT security teams to refine detection protocols. Regular training and awareness of the latest phishing trends are essential to effectively differentiate between genuine and malicious emails.

What is the difference between Phishing Email Analyst vs Security Analyst?

AspectPhishing Email AnalystSecurity Analyst
CredentialsCertifications like CompTIA Security+, CEH often preferredCertifications like CISSP, Security+ common
Work EnvironmentFocus on email security, threat detection, and analysisBroader security responsibilities including network, system, and data protection
Employer & IndustryFinancial institutions, tech companies, cybersecurity firmsAll industries, including finance, healthcare, government
Search & Comparison IntentUnderstanding specific email threat rolesBroader cybersecurity roles and responsibilities

The Phishing Email Analyst specializes in identifying and mitigating email-based threats, focusing on phishing attacks and email security. In contrast, a Security Analyst has a broader scope, covering various security domains beyond email. Both roles require similar certifications and are vital in protecting organizational assets, but their focus areas differ significantly.

More about Phishing Email Analyst jobs

What cities are hiring for Phishing Email Analyst jobs?

Cities with the most Phishing Email Analyst job openings:

What states have the most Phishing Email Analyst jobs?

States with the most job openings for Phishing Email Analyst jobs include:

What are popular job titles related to Phishing Email Analyst jobs?

For Phishing Email Analyst jobs, the most frequently searched job titles are:

Infographic showing various Phishing Email Analyst job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 1% As Needed, 75% Full Time, 19% Part Time, and 4% Contract. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $73,261 per year, or $35.2 per hour.

Email Security and Social Engineering Analyst

Memphis, TN • On-site

Other

Posted 13 days ago


Key responsibilities

  • Use Proofpoint tools to review and manage email traffic, alerts, quarantines, and threat activity.

  • Lead day-to-day phishing response by monitoring, triaging, investigating, containing, and documenting suspicious emails.

  • Support incident response activities related to email security, including evidence collection, containment, escalation, and documentation.


Job description

Email Security and Social Engineering Analyst

Business Area: Information Security - Security Operations

Posting Type: Internal Applicants

Work Arrangement: On-site preferred (Memphis, New Orleans, other sites to be considered)

Summary

We are seeking an associate to join the Security Operations team as an Email Security Analyst. This role will help protect the organization, our associates, and our customers by managing email security controls and investigating suspicious messages. The analyst will work extensively in Proofpoint and Outlook, triage reported phishing emails, support incident response, and help improve how we detect and respond to email-based threats.

The ideal candidate brings a healthy sense of paranoia: someone who notices when details do not add up, verifies assumptions, follows evidence, and remains appropriately skeptical without losing sight of business context. Just as important, this associate must communicate clearly and calmly with technical teams, business partners, leaders, and end users.

Why Consider This Opportunity?

This position is a great opportunity to be on the front line of threats impacting our associates and customers. You will see firsthand—and help defend against—cybersecurity and social engineering threats while gaining hands‑on experience with enterprise email security, phishing response, digital risk protection, threat analysis, incident response, and security operations. You will also partner with teams across the company to investigate issues, contain threats, and protect the organization.

Essential Duties and Responsibilities
  • Use the Proofpoint Secure Email Gateway and related Proofpoint tools to review and manage email traffic, alerts, quarantines, and threat activity.
  • Lead day-to-day phishing response by monitoring, triaging, investigating, containing, and documenting suspicious emails reported by associates and customers.
  • Address ServiceNow tickets related to phishing, email security, email delivery, and other assigned security issues within established service-level expectations.
  • Troubleshoot email delivery issues by reviewing message tracking, filtering decisions, quarantines, authentication results, policy routes, allow and block controls, and other relevant data.
  • Analyze message headers, sender behavior, URLs, attachments, redirects, and message context to determine whether an email is legitimate, suspicious, or malicious.
  • Investigate social engineering activity, including phishing, impersonation, business email compromise, credential theft, malicious links, and fraudulent requests.
  • Support digital risk protection activities by identifying, reviewing, and escalating external threats such as brand impersonation, fraudulent domains, malicious websites, and other risks targeting the organization, its associates, or its customers.
  • Perform Tier 1 phishing triage and elevate confirmed threats or complex investigations as appropriate.
  • Use sandboxing, threat intelligence, endpoint, identity, and logging tools to validate findings and determine potential impact.
  • Support email authentication and protection controls, including DMARC, SPF, DKIM, policy routes, and email firewall rules.
  • Search for related messages, contain threats, remove malicious emails, and support affected-user response actions.
  • Support incident response for compromised user accounts and devices, including evidence collection, scoping, containment, escalation, remediation coordination, and documentation.
  • Work with Identity, Endpoint, Security Operations, and other response teams to protect affected users, reset or secure access, isolate devices when appropriate, and confirm that threats have been contained.
  • Document investigations, evidence, decisions, and actions accurately and consistently.
  • Communicate findings and recommended actions to associates in clear, professional, and timely language.
  • Partner with Security Operations, Threat Management, Security Engineering, Messaging, Identity, and other teams during investigations and incidents.
  • Identify recurring patterns, control gaps, and opportunities to improve phishing detection, email delivery support, digital risk protection, and incident response processes.
  • Participate in an after-hours rotation or respond outside normal business hours when required.
  • Perform other duties as assigned.
What Success Looks Like
  • You are naturally curious and willing to investigate beyond the first obvious answer.
  • You maintain a healthy sense of paranoia while making evidence-based, practical decisions.
  • You can distinguish unusual activity from normal business behavior and know when to ask more questions.
  • You communicate with empathy and confidence, especially when an associate may be worried about a suspicious message or possible compromise.
  • You remain organized and accurate while managing a queue of time-sensitive work.
  • You explain technical findings in plain language and tailor your message to the audience.
  • You take ownership, follow through, and elevate promptly when risk or impact is unclear.
Qualifications
  • Current associate in good standing with demonstrated reliability, sound judgment, and attention to detail.
  • Strong written and verbal communication skills, including the ability to interact effectively with associates, leaders, technical teams, and external contacts.
  • Ability to analyze incomplete or conflicting information, recognize patterns, and make well-reasoned decisions.
  • Ability to follow procedures while adapting to new attack techniques and changing business conditions.
  • Comfort handling sensitive information and maintaining confidentiality.
  • Ability to manage competing priorities and work independently in a fast-paced environment.
  • General proficiency with Microsoft Office and collaboration tools.
  • Education and experience sufficient to perform the responsibilities of the role; relevant internal experience and transferable skills will be considered.
Preferred Experience
  • Experience in Information Security, fraud, investigations, technology support, risk management, compliance, customer service, operations, or another role requiring careful review and sound judgment.
  • Familiarity with phishing, business email compromise, social engineering, malware, or common email threats.
  • Experience with Proofpoint, Microsoft 365 email security, Splunk, endpoint detection and response tools, ticketing systems, and/or security sandboxes.
  • Understanding of email headers, URLs, domains, DNS, DMARC, SPF, or DKIM.
  • Experience documenting investigations or communicating findings to non-technical audiences.
  • Relevant security training or certificates, including Security+, CySA+, or Proofpoint certifications.
Supervisory Responsibilities

This position has no supervisory responsibilities.

#J-18808-Ljbffr