Proofpoint is a global leader in human- and agent-centric cybersecurity, dedicated to safeguarding the digital world. The SPAM Data Engineer will be part of a team responsible for identifying and responding to spam, phishing, and malware attacks, while also contributing to the development of new detection methods and tools.
Responsibilities:
- Member of a creative, enthusiastic, and geographically distributed team (in a 24/7/365 "follow the sun" model) that is responsible for identifying, parameterizing, and responding quickly to spam/Phishing/Malware/BEC (Email Fraud) attacks levied against some of the world's largest organizations
- Analyze misclassified email messages, URLs, and attachments (spam, malware, phishing, and legitimate) to make updates to detection technologies and correct their classifications
- Perform deep analyses of email headers, structures, and attachments to identify novel threat features, and develop new rules/methods to detect them
- Research into new trends and creation of pro-active detection to stop new threats before they start
- Contribute to the development of new tools and automation to aid in front line analysis, and to identify the latest threats
- Work with the team to come up with new and novel ways to detect threats
- Take on more complex customer false negative or false positive cases escalated by other analysts in the team that require more in-depth investigation and analysis
- Work on internal escalation tickets created by field teams for customers experiencing more complex or systemic recurring issues that have not been solved through usual means, collaborating with other engineering teams where necessary to find the best solutions
- On-call work - that means responding to high priority alerts sent by our threat monitoring system, and periodic monitoring of essential systems. You would be expected to be on call at times during your shift
- Help us define the landscape, prevalence, and evolution of messaging abuse, threats, and attacks by participating in future requirements definition discussions of our products
Requirements:
- Strong analytical and creative problem-solving skills
- Proficient oral and written communications skills
- Collaborates well in a team environment
- Able to communicate complex technical concepts to customers in an accessible manner
- Familiarity with using the Linux command line, and tools for manipulating and extracting content from text files
- Good knowledge of regular expressions
- Familiarity with how mail delivery works, including SMTP
- General curiosity about the headers and structure of email messages
- Willingness to interact with customers through our web-based ticketing system to help resolve their issues
- Ability to work independently but also to collaborate with worldwide, remote teams
- Positive, friendly attitude that enjoys problem solving
- BSc or equivalent in IT related subject, or equivalent technical experience
- Experience in a data science or similar role (a plus)
- Experience with signature-based detections such as Clam, Yara, or similar an advantage
- Familiarity with a scripting language such as Python or Perl an advantage (a Big Plus)