Position Title: Proofpoint Email Remediation Engineer
Project Overview - The organization operates a large-scale enterprise messaging environment supporting approximately 47,000 Office 365 and Exchange mailboxes across 12,000 users. The email ecosystem includes advanced security and hygiene controls leveraging tools such as Proofpoint TRAP (Threat Response Auto-Pull), Proofpoint on Demand (POD), and Microsoft O365 Security & Compliance capabilities.
The environment requires a balance between strong email security controls and business continuity, ensuring that malicious content is removed while legitimate communications are not disrupted. The organization also utilizes Splunk and related analytics platforms for advanced log analysis and threat investigation.
This role will provide operational and technical email security remediation support, focusing on identifying misclassified messages (false positives and false negatives), executing remediation actions, and optimizing email filtering effectiveness. The position will also support potential migration activities from TRAP to Cloud Threat Response (CTR).
Position Responsibilities
· Perform continuous monitoring and analysis of email alerts, reports, quarantined messages, and user-reported incidents to identify misclassified emails.
· Conduct detailed forensic review of email messages, including headers, body content, embedded links, and attachments, to determine security risk.
· Execute manual remediation actions:
o Remove malicious or suspicious emails using Proofpoint TRAP (or CTR)
o Release legitimate emails incorrectly quarantined using Proofpoint POD and O365 Security & Compliance tools
· Investigate and document false positives and false negatives, and escalate findings to email hygiene vendors via ticketing systems.
· Maintain accurate audit records and tracking of all remediation actions, incidents, and vendor interactions.
· Leverage log analysis tools (e.g., Splunk, Proofpoint SmartSearch) to support investigations and validate remediation decisions.
· Collaborate with internal stakeholders, end users, and external vendors to resolve email security issues and respond to requests.
· Perform incident and error log management, ensuring timely identification and resolution of issues.
· Provide actionable recommendations to improve email filtering accuracy, reduce risk exposure, and optimize operational processes.
· Produce daily operational reports, including:
o Number of messages removed and restored
o Vendor tickets opened/resolved
o Issues, risks, and mitigation strategies
o Status of recommendations and improvements
· Support migration activities from Proofpoint TRAP to CTR, including testing, validation, and issue resolution.
Position Requirements
Required Experience
· 6+ years of experience in enterprise email security, messaging operations, or malware remediation
· Proven experience supporting large-scale email environments (O365/Exchange)
Technical Knowledge
· Strong understanding of:
o Email architecture (SMTP, routing, MTAs)
o Email authentication protocols (SPF, DKIM, DMARC)
o Message filtering and security mechanisms
· Deep knowledge of email-based threat vectors, including:
o Phishing and spear phishing
o Malicious attachments and payload delivery
o URL-based attacks and ransomware
o Remote access trojans (RATs), stealers, and initial access techniques
Tools & Platforms
· Experience with email security and remediation tools such as:
o Microsoft O365 Security & Compliance Center
o Proofpoint TRAP, POD, CTR (or similar platforms)
· Experience with log analysis and search tools, including:
o Splunk
o Proofpoint SmartSearch / PPS
o Equivalent SIEM or analytics tools
Core Capabilities
· Ability to perform technical analysis of email messages, including headers, links, and attachments
· Experience executing manual remediation actions (message pull/release)
· Strong analytical and problem-solving skills in a security operations environment
· Effective communication skills, both written and verbal, with the ability to interact across technical teams, vendors, and business users
· Experience working with ticketing systems and incident tracking processes
___________________________________________________________________
No Phone calls Please
Please apply with your resume in a word file including all your contact details