Deskripsi Pekerjaan
Are you a cybersecurity professional passionate about protecting critical public infrastructure? Synapxe is seeking a highly skilled Lead Engineer for Phishing Analysis to join our Cyber Security Office. In this pivotal role, you will be at the forefront of defending our Public Healthcare sector against sophisticated email-based threats.
As the Lead Engineer, you will design and implement advanced controls to monitor, analyze, and neutralize complex phishing campaigns. You will act as a subject matter expert, leveraging gateway data to derive actionable intelligence that protects our network and stakeholders. Your work will directly contribute to building a resilient security posture and fostering a culture of cybersecurity awareness across the organization.
We are looking for a proactive problem-solver who excels in technical analysis and is dedicated to staying one step ahead of threat actors. If you are ready to make a meaningful impact on national healthcare security, we invite you to join our dynamic team.
Tanggung Jawab
- Architect and maintain robust security controls to detect and block malicious email campaigns.
- Conduct deep-dive analysis into phishing emails and gateway logs to identify emerging threat patterns.
- Develop and automate incident response workflows for neutralized threats to minimize mean time to remediation.
- Collaborate with cross-functional IT teams to integrate threat intelligence into broader defensive strategies.
- Lead threat hunting initiatives to identify latent vulnerabilities within the enterprise messaging environment.
- Design and deliver phishing awareness programs to educate staff and reduce the organization's human attack surface.
- Prepare detailed incident reports and executive briefings regarding threat landscapes and security efficacy.
Kualifikasi
- Bachelor’s degree in Cybersecurity, Computer Science, or a related technical discipline.
- Minimum 5-7 years of experience in cybersecurity operations, specifically within email security or threat analysis.
- Deep understanding of SMTP, SPF, DKIM, DMARC, and cloud-based email security solutions (e.g., Microsoft 365 Defender, Proofpoint).
- Proficiency in scripting languages such as Python or PowerShell for security automation and data parsing.
- Experience in analyzing security logs via SIEM platforms (e.g., Splunk, ELK, or Sentinel).
- Strong knowledge of current threat actor TTPs (Tactics, Techniques, and Procedures) related to phishing.
- Relevant professional certifications such as GCIH, GCFA, CISSP, or equivalent are highly preferred.