4 дня назад
Senior Endpoint Security Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Endpoint Security Engineer (AI): Leading next-generation endpoint threat modeling and security automation across Windows, macOS, Linux, and Cloud/OT environments with an accent on detection engineering, predictive threat intelligence, and machine-speed defense. Focus on designing SOAR playbooks, virtual patching workflows, behavioral detection rules, and automated SecOps pipelines to counter advanced exploits and reduce operational toil.
Location: Manila Net Park Office, Manila, Philippines; flexible work schedule with available work-from-home arrangements.
Company
Procter & Gamble produces globally recognized consumer brands and operates in approximately 70 countries.
What you will do
- Lead next-generation endpoint threat modeling and detection engineering across Windows, macOS, Linux, and Cloud/OT environments.
- Integrate endpoint telemetry, asset graphs, identity trust boundaries, EDR/XDR data, and generative AI threat intelligence to map multi-stage attack chains.
- Author behavioral detection rules using CQL, Sigma, YARA, or SPL, and build virtual patching and machine-speed mitigation controls.
- Design, test, and deploy automated containment playbooks with Falcon Fusion, Torq, or Palo Alto XSOAR.
- Implement endpoint SecOps automation for enrichment, triage, context gathering, and alert-fatigue reduction.
- Partner with Business Technical teams, DevOps, infrastructure, system administrators, and SOC analysts to improve endpoint security without disrupting operations.
Requirements
- 3+ years of hands-on experience in endpoint security, detection engineering, SOC automation, or systems operations across multiple operating-system domains.
- Proven experience building and maintaining SOAR playbooks and containment workflows.
- Strong proficiency with Python, PowerShell, or Bash and RESTful API integration.
- Deep familiarity with Windows, macOS, Linux, and Cloud/OT security mechanisms and telemetry.
- Experience with virtual patching, host-based isolation, CIS Benchmarks, Attack Surface Reduction policies, and configuration-drift remediation.
- Practical threat-modeling experience with MITRE ATT&CK, EDR/XDR telemetry, and AI-assisted cyber defense.
Nice to have
- Bachelor’s degree in Computer Science, Cybersecurity, or equivalent technical experience.
- SANS/GIAC, CrowdStrike, or Python/automation certifications.
Culture & Benefits
- Full-time position with opportunities to lead, guide, and collaborate on large-scale security initiatives.
- Flexible work schedule with available work-from-home arrangements.
- Performance bonus through the STAR program.
- Health insurance, fitness support, and an Employee Assistance Program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →