1

Security Phishing Engineer Jobs (NOW HIRING)

Lead security awareness and phishing simulation programs to build an organization-wide culture of ... Raise the security bar across the company by mentoring engineers and partners on secure practices ...

Cybersecurity Senior Engineer

Albany, NY · On-site

$114K - $156K/yr

... Engineer The Senior Cybersecurity Engineer is the organization's elite, tool-agnostic security ... Security, Phishing Simulation, Data Loss Prevention (DLP), Application Security (AppSec), and ...

This role will partner closely with Cybersecurity Engineering, Network, Cloud, Infrastructure ... Familiarity with enterprise email security, phishing protection, secure email gateways, and ...

Knowledge of phishing, general cyber security and Splunk. * Candidates need to have the ability to conduct searches in Splunk * Client is seeking a Senior Information Security Engineer in Threat ...

Engineer and support for both Endpoint and Email security platforms across Windows, macOS, and ... Investigate phishing, malware delivery, and email-based attacks, including analysis of headers ...

Security Awareness / Phishing Simulations * Okta MFA (Nice to Have) * 10+ years Security Engineering experience * Bachelor's degree required * CISSP / AZ-500 / Security+ / CISM / CCSP (Preferred)

... engineering team). In practice, we expect to grow the security team one hire at a time, so your ... phishing protection, and secure collaborative workflows. * Security Architecture as an Enabler

Direct the delivery of Security Awareness Training programs and security phishing campaigns to ... engineers, with a demonstrated ability to provide leadership, guidance, and motivation. * Strong ...

next page

Showing results 1-20

Security Phishing Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do security phishing engineer jobs pay per year?

As of Sep 10, 2026, the average yearly pay for security phishing engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What is a security phishing engineer?

Security Phishing Engineers are cybersecurity professionals who specialize in designing and executing simulated phishing attacks within an organization. Their main goal is to test and improve employees' awareness and response to phishing threats by mimicking real-world cyberattack scenarios. Through these controlled exercises, they help organizations identify vulnerabilities and educate staff on how to recognize and avoid malicious phishing attempts. This role is crucial for strengthening an organization's overall security posture.

What are the key skills and qualifications needed to thrive as a security phishing engineer, and why are they important?

To thrive as a Security Phishing Engineer, you need expertise in cybersecurity principles, threat analysis, and social engineering tactics, often backed by a degree in computer science or a related field. Familiarity with phishing simulation platforms, incident response tools, and certifications such as CEH or CISSP are commonly required. Strong analytical thinking, attention to detail, and effective communication skills are vital for identifying threats and educating teams. These competencies are crucial for proactively defending organizations against phishing attacks and fostering a culture of cybersecurity awareness.

How does a security phishing engineer typically collaborate with other departments to improve organizational security awareness?

A Security Phishing Engineer works closely with IT, Human Resources, and Compliance teams to design and execute simulated phishing campaigns and training initiatives. They coordinate with these departments to ensure that training materials are relevant, accessible, and tailored to the unique needs of various employee groups. Regular debrief sessions and data sharing help identify trends and areas for improvement, fostering a proactive security culture across the organization. Effective collaboration also ensures that feedback from different departments is incorporated into future security awareness strategies.

What is the difference between Security Phishing Engineer vs Security Analyst?

AspectSecurity Phishing EngineerSecurity Analyst
CertificationsCertified Ethical Hacker (CEH), CompTIA Security+CompTIA Security+, CISSP
Work EnvironmentFocus on phishing detection, email security, and user trainingBroader security monitoring, incident response, and risk assessment
Industry UsageTech companies, financial institutions, cybersecurity firmsAll industries, including government, healthcare, and finance

While both roles involve cybersecurity, a Security Phishing Engineer specializes in identifying and preventing phishing attacks through technical measures and user education. A Security Analyst has a broader scope, monitoring overall security posture, analyzing threats, and responding to incidents. The roles often overlap but differ mainly in focus and specific responsibilities.

What are popular job titles related to Security Phishing Engineer jobs?

For Security Phishing Engineer jobs, the most frequently searched job titles are:

Infographic showing various Security Phishing Engineer job openings in the United States as of September 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

Email Security and Social Engineering Analyst - First Horizon Bank

Memphis, TN • On-site

$80 - $100/hr

Other

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Email Security and Social Engineering Analyst

Business Area: Information Security — Security Operations Posting Type: Internal Applicants Work Arrangement: On-site preferred (Memphis, New Orleans, other sites to be considered)

Summary

We are seeking an associate to join the Security Operations team as an Email Security Analyst. This role will help protect the organization, our associates, and our customers by managing email security controls and investigating suspicious messages. The analyst will work extensively in Proofpoint and Outlook, triage reported phishing emails, support incident response, and help improve how we detect and respond to email-based threats.

The ideal candidate brings a healthy sense of paranoia: someone who notices when details do not add up, verifies assumptions, follows evidence, and remains appropriately skeptical without losing sight of business context. Just as important, this associate must communicate clearly and calmly with technical teams, business partners, leaders, and end users.

Why Consider This Opportunity?

This position is a great opportunity to be on the front line of threats impacting our associates and customers. You will see firsthand—and help defend against—cybersecurity and social engineering threats while gaining hands‑on experience with enterprise email security, phishing response, digital risk protection, threat analysis, incident response, and security operations. You will also partner with teams across the company to investigate issues, contain threats, and protect the organization.

Essential Duties and Responsibilities
  • Use the Proofpoint Secure Email Gateway and related Proofpoint tools to review and manage email traffic, alerts, quarantines, and threat activity.
  • Lead day‑to‑day phishing response by monitoring, triaging, investigating, containing, and documenting suspicious emails reported by associates and customers.
  • Address ServiceNow tickets related to phishing, email security, email delivery, and other assigned security issues within established service-level expectations.
  • Troubleshoot email delivery issues by reviewing message tracking, filtering decisions, quarantines, authentication results, policy routes, allow and block controls, and other relevant data.
  • Analyze message headers, sender behavior, URLs, attachments, redirects, and message context to determine whether an email is legitimate, suspicious, or malicious.
  • Investigate social engineering activity, including phishing, impersonation, business email compromise, credential theft, malicious links, and fraudulent requests.
  • Support digital risk protection activities by identifying, reviewing, and escalating external threats such as brand impersonation, fraudulent domains, malicious websites, and other risks targeting the organization, its associates, or its customers.
#J-18808-Ljbffr