Overview
Staff Security Research Engineer at Proofpoint. Join a global team focused on tracking threat actors, malware, phishing, and TTPs with innovative software to detect and prevent threats for Proofpoint customers.
Your day-to-day
- Design and develop software using a variety of languages, primarily Python, with little external guidance, while providing technical leadership to guide other software engineers on the team
- Some skill in modifying existing web-based UI for internal tools to maintain and extend the sandbox submission and report UI for Proofpoint threat researchers
- Some work requires skill in writing C or C++ for low level interactions with the OS
- Develop and maintain web browser interaction capabilities using Chrome web driver
- Analyze and reverse engineer JavaScript that fingerprints web browser artifacts to identify sandbox web browsers or instrumentation, and innovate solutions to defeat those checks
- Familiarity with analyzing web front-end and the Document Object Model (DOM)
- Develop and maintain software for processing network traffic, including TLS decryption and processing PCAP files
- Work closely with threat analysts and detection engineers who research threat actors and write detection rules which run on the systems you develop
- As needed, create new detection languages and systems that allow threat researchers to develop detection rules
- Add features to existing threat detection languages to allow greater flexibility by threat researchers to automate interactions with websites and detect threat patterns
- Make use of AI Large Language Models as appropriate to enhance threat detection pipelines, produce samples to test evasion countermeasures, and make sound decisions about when applying AI is a benefit vs. a detriment to achieving goals
- Design and develop automation pipelines to turn manual tasks into automated scripts
- Stay abreast of a constantly evolving threat landscape
- Understand the latest tactics, techniques, and procedures used by threat actors to bypass detection environments, especially URL sandbox fingerprinting / detection / evasion techniques used by threat actors
- As needed, provide expert assistance and support to threat researchers and analysts as they analyze phishing websites, threat detection evasion techniques, and security research or red team demonstrations of new evasion techniques
- As needed to support sandbox countermeasure development, reverse engineering malware executable files for Windows (note primary malware reverse engineering responsibilities rest on other job roles and are not expected regularly for this role)
- Apply critical thinking skills to identify the most efficient and effective way to mitigate threats and evasions
- Work effectively as part of a remote team using chat, video chat and conference calls
- Work with other engineering teams, defining requirements, for continuous improvement of critical detection capabilities
What You Bring To The Team
As a Security Research Engineer on Proofpoints Threat Research team, youll be part of an amazing, collaborative, industry-leading team focused on tracking threat actors, malware, phishing, and TTPs and responding to the quickly changing threat landscape with innovative software that detects and prevents threats from reaching Proofpoint customers.
A passion for threat research and a well-rounded yet deep understanding of the security threat landscape and actor TTPs, especially understanding how to develop countermeasures for threat actor evasions and sandbox detection techniquesAbility to write production-grade, reliable Python code with instrumentation that supports observability and monitoring of performance and errors is requiredExperience developing software using Docker containers is requiredExperience developing web browser automation is requiredExperience analyzing network traffic for threat detection and a solid understanding of TLS, HTTP, and other network protocols used by malware is requiredWilling and able to work independently and collaboratively as part of a distributed team of industry-leading security researchersAbility to perform the above in a fully remote work environmentThe following skills and experience are nice to have, but candidates lacking them should still apply
Experience with C and C++ is a plusExperience developing Windows API hooks and knowing how to research undocumented Windows API internal functions is a plusExperience writing malware behavior signaturesSome experience analyzing malware using a debugger, and willingness to learn is a plusExperience with statically reverse engineering malware using IDA Pro, Ghidra, Binary Ninja, or other reverse engineering tools is a plus, although being an expert is not requiredAbility to accurately interpret the forensic output of dynamic analysis (sandbox) environmentsExperience with a variety of publicly-available malware sandboxes (for example Cuckoo, Joe Sandbox, Any Run, Triage, etc.)Additional Information
Travel 1% - 10% (flexible) mainly for team collaboration or security conferencesLocation Canada (Remote), US (Remote), Argentina (Remote), UK (Remote), Ireland (Remote), Germany (Remote), France (Remote), Switzerland (Remote)Must be able to work during business hours local to your time-zoneWhy Proofpoint
As a customer focused and driven-to-win organization with leading edge products, there are many exciting reasons to join the Proofpoint team. We believe in hiring the best the brightest and cultivating a culture of collaboration and appreciation. As we continue to grow and expand globally, we understand that hiring the right people and developing great teams is key to our success. We are a multi-national company with locations in many countries, with each location contributing to Proofpoints amazing culture. Why Proofpoint? At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons youll love working with us.
Competitive compensationComprehensive benefitsLearning & Development We are committed to the growth and development of our team members, offering a range of programs including leadership and professional development workshops, stretch project assignments, and mentoring opportunities to help employees reach their full potential.Flexible work environment [Remote options, hybrid schedules, flexible hours, etc.]Annual wellness and community outreach daysAlways on recognition for your contributionsGlobal collaboration and networking opportunitiesOur Culture
Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone. If you need accommodation during the application or interview process, please reach out to accessibility@. How to Apply Interested? Submit your application here https / / . We cant wait to hear from you!
Consistent with Proofpoint values and applicable law, we provide a pay transparency notice. Compensation reflects the cost of labor across several U.S. geographic markets, with ranges based on location. The actual offer will be based on the individual candidate. Base Pay Ranges include : SF Bay Area / NYC Metro Area, other U.S. locations, and all other cities. This role may be eligible for variable compensation and / or equity. We offer a comprehensive benefits package including flexible time off and a well-being program.
#J-18808-Ljbffr