You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC ... Threat Hunting, Modeling, and Detection Engineering * Proactively hunt for hidden threats across ...
You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC ... Threat Hunting, Modeling, and Detection Engineering * Proactively hunt for hidden threats across ...
You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC ... Threat Hunting, Modeling, and Detection Engineering * Proactively hunt for hidden threats across ...
You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC ... Threat Hunting, Modeling, and Detection Engineering * Proactively hunt for hidden threats across ...
You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC ... Threat Hunting, Modeling, and Detection Engineering * Proactively hunt for hidden threats across ...
You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC ... Threat Hunting, Modeling, and Detection Engineering * Proactively hunt for hidden threats across ...
Maintain ticket management and DevOps activity tracking to ensure accurate work intake ... Threat detection development in Microsoft Sentinel and Defender platforms sing KQL. * Align ...
Maintain ticket management and DevOps activity tracking to ensure accurate work intake ... Threat detection development in Microsoft Sentinel and Defender platforms sing KQL. * Align ...
Security Operations Engineer
Lehi, UT · On-site
You will report to the Senior Security Operations Manager and work closely with Cloud Platform ... Architect Detection, Deception, & Automation: Build advanced detection queries in Splunk and deploy ...
Security Operations Engineer
Lehi, UT · On-site
You will report to the Senior Security Operations Manager and work closely with Cloud Platform ... Architect Detection, Deception, & Automation: Build advanced detection queries in Splunk and deploy ...
Senior Application Security Engineer
South Jordan, UT · Remote
$109K - $149K/yr
Senior Application Security Engineer Canopy, South Jordan, UT About Us Canopy is a fast-growing ... Experience building or operating detection engineering programs (honeytokens, canary credentials ...
Senior Application Security Engineer
South Jordan, UT · Remote
$109K - $149K/yr
Senior Application Security Engineer Canopy, South Jordan, UT About Us Canopy is a fast-growing ... Experience building or operating detection engineering programs (honeytokens, canary credentials ...
Senior Application Security Engineer
South Jordan, UT · Remote
$109K - $149K/yr
Senior Application Security Engineer Canopy, South Jordan, UT About Us Canopy is a fast-growing ... Experience building or operating detection engineering programs (honeytokens, canary credentials ...
Senior Application Security Engineer
South Jordan, UT · Remote
$109K - $149K/yr
Senior Application Security Engineer Canopy, South Jordan, UT About Us Canopy is a fast-growing ... Experience building or operating detection engineering programs (honeytokens, canary credentials ...
Senior Application Security Engineer
South Jordan, UT · Remote
$109K - $149K/yr
Senior Application Security Engineer Canopy, South Jordan, UT About Us Canopy is a fast-growing ... Experience building or operating detection engineering programs (honeytokens, canary credentials ...
Quick apply
Senior Application Security Engineer
South Jordan, UT · Remote
$109K - $149K/yr
Senior Application Security Engineer Canopy, South Jordan, UT About Us Canopy is a fast-growing ... Experience building or operating detection engineering programs (honeytokens, canary credentials ...
Senior Software Engineer, Actimize
$109K - $144K/yr
Senior Software Engineer - Fraud Detection Platform About the Role We are looking for a Lead Software Engineer to maintain and evolve the web applications that power our fraud detection platform. The ...
Senior Software Engineer, Actimize
$109K - $144K/yr
Senior Software Engineer - Fraud Detection Platform About the Role We are looking for a Lead Software Engineer to maintain and evolve the web applications that power our fraud detection platform. The ...
Sr. Observability Engineer
Lehi, UT · On-site
As a Senior Observability Engineer, you build and operate an observability control plane ... You scaffold baselines, score coverage, and turn every real incident into the detection the ...
Sr. Observability Engineer
Lehi, UT · On-site
As a Senior Observability Engineer, you build and operate an observability control plane ... You scaffold baselines, score coverage, and turn every real incident into the detection the ...
Security Operations Engineer
Lehi, UT · On-site
$120K - $180K/yr
You will report to the Senior Security Operations Manager and work closely with Cloud Platform ... Architect Detection, Deception, & Automation: Build advanced detection queries in Splunk and deploy ...
Security Operations Engineer
Lehi, UT · On-site
$120K - $180K/yr
You will report to the Senior Security Operations Manager and work closely with Cloud Platform ... Architect Detection, Deception, & Automation: Build advanced detection queries in Splunk and deploy ...
Senior SOC Engineer
$130K - $196K/yr
As a Senior SOC Engineer , you will lead advanced security monitoring and incident response efforts ... What You'll Do Perform advanced threat detection, analysis, and response across multiple platforms ...
Senior SOC Engineer
$130K - $196K/yr
As a Senior SOC Engineer , you will lead advanced security monitoring and incident response efforts ... What You'll Do Perform advanced threat detection, analysis, and response across multiple platforms ...
Senior Software Engineer, Actimize
Sandy, UT · On-site
$116K - $153K/yr
Senior Software Engineer - Fraud Detection Platform About the Role We are looking for a Lead Software Engineer to maintain and evolve the web applications that power our fraud detection platform. The ...
Senior Software Engineer, Actimize
Sandy, UT · On-site
$116K - $153K/yr
Senior Software Engineer - Fraud Detection Platform About the Role We are looking for a Lead Software Engineer to maintain and evolve the web applications that power our fraud detection platform. The ...
Senior Security Engineer
West Jordan, UT · On-site
$106K - $146K/yr
Position Summary NOVVA Data Centers is seeking a highly skilled Senior Security Engineer to lead ... Threat Detection * Security Engineering * Risk Management * Communication * Project Leadership
Senior Security Engineer
West Jordan, UT · On-site
$106K - $146K/yr
Position Summary NOVVA Data Centers is seeking a highly skilled Senior Security Engineer to lead ... Threat Detection * Security Engineering * Risk Management * Communication * Project Leadership
Senior Security Engineer
West Jordan, UT · On-site
$106K - $146K/yr
Position Summary NOVVA Data Centers is seeking a highly skilled Senior Security Engineer to lead ... Threat Detection * Security Engineering * Risk Management * Communication * Project Leadership
Senior Security Engineer
West Jordan, UT · On-site
$106K - $146K/yr
Position Summary NOVVA Data Centers is seeking a highly skilled Senior Security Engineer to lead ... Threat Detection * Security Engineering * Risk Management * Communication * Project Leadership
Senior Manufacturing Engineer
Ogden, UT · On-site
$130K - $150K/yr
Position Summary Odyssey is seeking an experienced Senior Manufacturing Engineer supporting the Air ... detection and avoidance techniques, and Diminishing Manufacturing Sources and obsolescence ...
Senior Manufacturing Engineer
Ogden, UT · On-site
$130K - $150K/yr
Position Summary Odyssey is seeking an experienced Senior Manufacturing Engineer supporting the Air ... detection and avoidance techniques, and Diminishing Manufacturing Sources and obsolescence ...
Senior Manufacturing Engineer
$89K - $121K/yr
Position Summary Odyssey is seeking an experienced Senior Manufacturing Engineer supporting the Air ... detection and avoidance techniques, and Diminishing Manufacturing Sources and obsolescence ...
Senior Manufacturing Engineer
$89K - $121K/yr
Position Summary Odyssey is seeking an experienced Senior Manufacturing Engineer supporting the Air ... detection and avoidance techniques, and Diminishing Manufacturing Sources and obsolescence ...
Senior Manufacturing Engineer
Ogden, UT · On-site
$89K - $121K/yr
Odyssey is seeking an experienced Senior Manufacturing Engineer supporting the Air Force Life Cycle ... detection and avoidance techniques, and Diminishing Manufacturing Sources and obsolescence ...
Senior Manufacturing Engineer
Ogden, UT · On-site
$89K - $121K/yr
Odyssey is seeking an experienced Senior Manufacturing Engineer supporting the Air Force Life Cycle ... detection and avoidance techniques, and Diminishing Manufacturing Sources and obsolescence ...
Senior Security Engineer
Hill Air Force Base, UT · Hybrid
$105K - $144K/yr
Contribute to incident detection and response, including developing detections, improving telemetry ... Engineer and implement security requirements for DoD cloud environments (AWS, Azure) in accordance ...
Senior Security Engineer
Hill Air Force Base, UT · Hybrid
$105K - $144K/yr
Contribute to incident detection and response, including developing detections, improving telemetry ... Engineer and implement security requirements for DoD cloud environments (AWS, Azure) in accordance ...
Within our Cloud Engineering, Data & Analytics practice, you will leverage your technical skills ... detection, settlement scalability, debit) for cloud-native scalability - Diagnose and resolve ...
Within our Cloud Engineering, Data & Analytics practice, you will leverage your technical skills ... detection, settlement scalability, debit) for cloud-native scalability - Diagnose and resolve ...
Senior Detection Engineer information
What is the difference between Senior Detection Engineer vs Security Analyst?
| Aspect | Senior Detection Engineer | Security Analyst |
|---|---|---|
| Required Credentials | Bachelor's in CS, Cybersecurity, or related; certifications like CISSP, GIAC | Bachelor's in CS, Cybersecurity, or related; certifications like CompTIA Security+ |
| Work Environment | Develops detection tools, analyzes security data, creates detection rules | Monitors security alerts, investigates incidents, reports findings |
| Employer & Industry Usage | Tech companies, financial institutions, cybersecurity firms | IT departments, government agencies, large enterprises |
While both roles focus on security, Senior Detection Engineers primarily develop and refine detection systems, whereas Security Analysts monitor and respond to security incidents. The Senior Detection Engineer role is more technical and development-oriented, while Security Analysts focus on incident response and analysis.
What are the key skills and qualifications needed to thrive as a senior detection engineer, and why are they important?
What is a senior detection engineer?
What are some common challenges a senior detection engineer faces when developing and tuning detection rules?
How much do detection engineers make?
- Weekend Remote Electrical Engineer
- Overnight Remote Electrical Engineering
- Electrical Engineer Renewable Energy
- Remote Proposal Engineer
- Electrical Engineer Manager
- Electrical Power Engineer
- Trainee Electrical Transformer Design Engineer
- Contract Electrical Engineering
- Senior Remote Electrical Engineer
- Remote Junior Electrical Engineer

Full-time
Posted 9 days ago
Proofpoint rating
9.7
Based on 7 frontline employees who took The Breakroom Quiz
1st of 116 rated security
Job description
Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people.
How We Work:
At Proofpoint you'll be part of a global team that breaks barriers to redefine cybersecurity guided by our BRAVE core values:
Bold in how we dream and innovate
Responsive to feedback, challenges and opportunities
Accountable for results and best in class outcomes
Visionary in future focused problem-solving
Exceptional in execution and impact
About Proofpoint
At Proofpoint, we protect organizations and individuals from today's most advanced cyber threats. Through innovative security technologies, threat intelligence, and a global team of security experts, we help customers defend against phishing, malware, account compromise, insider threats, and data loss.
Role Overview
We are seeking an experienced Senior Cyber Threat Defense - Security Operations Engineer to join our global security team in Draper, UT. This critical role sits within the Global Information Security Operation team and is responsible for investigating and responding to sophisticated security incidents across Proofpoint's global operations.
You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC), own complex investigations and technical decisions, participate in a scheduled on-call rotation, and set direction for detection, investigation, response, threat modeling, and security automation. The role also supports selected AI-enabled capabilities, including Agentic SOC workflows and AI Data Loss Prevention (AI DLP).
Key Responsibilities:
Incident Response and Escalation
- Own Level 3 escalation for high-severity and technically complex incidents within the global 24/7 SOC.
- Lead major investigations involving malware, ransomware, phishing, identity attacks, insider threats, cloud compromise, and advanced persistent threats.
- Set containment, eradication, recovery, remediation, and post-incident improvement strategy, balancing risk and business impact.
- Direct response across Security, IT, Cloud Engineering, Legal, Privacy, and business leaders, and communicate incident status and decisions to executives.
- Participate in a scheduled on-call rotation and provide after-hours support for critical security incidents, including nights, weekends, and holidays as required.
Threat Hunting, Modeling, and Detection Engineering
- Proactively hunt for hidden threats across endpoints, identities, networks, cloud environments, SaaS applications, and data repositories.
- Lead cross-functional threat modeling for new and existing systems, cloud services, and security workflows to identify abuse cases, attack paths, and control gaps.
- Use threat intelligence and behavioral analytics to identify suspicious activity and emerging attack patterns.
- Develop, test, tune, and maintain detection rules, correlations, hunting queries, and response use cases.
- Translate threat intelligence and MITRE ATT&CK techniques into actionable detection and hunting use cases.
Security Automation and Orchestration
- Define and implement automation strategy for alert enrichment, prioritization, triage, containment, notification, and remediation.
- Use SOAR platforms and security APIs to streamline repeatable incident-response activities.
- Develop scripts, integrations, and automation using Python, PowerShell, Bash, or similar languages.
- Optimize SIEM log ingestion, normalization, correlation, retention, and alerting.
Emerging Security Capabilities
- Support practical Agentic SOC use cases for alert triage, investigation enrichment, case documentation, and response under defined human oversight.
- Help operate AI DLP controls that reduce sensitive-data exposure through generative AI applications and copilots.
- Continuous Improvement
- Own root-cause analysis and drive improvements to security controls, telemetry, processes, and architecture.
- Partner with security architects and engineering leaders to set technical direction and evaluate detection and response technologies.
- Mentor engineers and analysts, establish investigation standards, and raise technical capability across the SOC.
Required Qualifications and Experience
- Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations.
- U.S. citizenship.
- Demonstrated experience leading major incidents and serving as the final technical escalation point for complex or high-severity security events.
- Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, and security monitoring.
- Experience investigating malware, phishing, identity attacks, cloud compromise, insider threats, data loss, and advanced persistent threats.
- Hands-on experience with SOAR platforms, APIs, and scripting languages such as Python, PowerShell, or Bash.
- Strong understanding of the MITRE ATT&CK framework, attacker tactics, techniques, and procedures, and the cyber kill chain.
- Experience applying threat modeling methods such as STRIDE, attack trees, or MITRE ATT&CK to enterprise or cloud systems.
- Experience creating or tuning detection rules, hunting queries, and response playbooks.
- Working knowledge of cloud security across AWS, Microsoft Azure, or Google Cloud Platform.
- Proven ability to own technical strategy, influence architecture and control decisions, and drive cross-functional security improvements.
- Strong executive communication, analytical, troubleshooting, and documentation skills, with the ability to make sound decisions during high-pressure incidents.
- Willingness and ability to participate in an on-call rotation and respond to critical incidents outside normal business hours, including nights, weekends, and holidays as required.
Preferred Qualifications
- Experience with Agentic SOC, AI-assisted investigation, or AI DLP capabilities.
- Experience with identity, cloud, or data detection and response technologies.
- Experience leading incident simulations, purple-team exercises, or adversary-emulation activities.
- Relevant certifications such as GCIH, GCFA, CISSP, CISM, OSCP, GIAC, or cloud-security certifications.
#LI-AN2
Why Proofpoint?
At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you'll love working with us:
- Competitive compensation
- Comprehensive benefits
- Career success on your terms
- Flexible work environment
- Annual wellness and community outreach days
- Always on recognition for your contributions
- Global collaboration and networking opportunities
Our Culture:
Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone.
We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to accessibility@proofpoint.com.
How to Apply
Interested? Submit your application along with any supporting information- we can't wait to hear from you!
Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and/or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.
Base Pay Ranges:
SF Bay Area, New York City Metro Area:
Base Pay Range: 136,200.00 - 214,005.00 USD
California (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska:
Base Pay Range: 112,700.00 - 177,100.00 USD
All other cities and states excluding those listed above:
Base Pay Range: 101,600.00 - 159,720.00 USD