About the job
The Senior Level 3 Email Security Engineer plays a crucial role in the advanced design, optimization, and management of the bank’s secure email gateway and email threat protection systems. This position is pivotal in thwarting phishing attempts, business email compromise, malware intrusions, and data loss through email. The engineer will also oversee the integration of email gateways with Data Loss Prevention (DLP), classification systems, and Security Information and Event Management (SIEM) solutions.
Key Technologies Include:
- Cisco Secure Email, ESA, or IronPort
- FireEye or Trellix Email Security Appliance EX
- Forcepoint Email Security Gateway
- Trend Micro ScanMail for Exchange or equivalent
The engineer will serve as the ultimate escalation point for email security incidents, lead incident response efforts, and drive continuous enhancements in detection efficacy and management of false positives. Email remains the primary attack vector for many organizations, as supported by vendors like Trellix and Forcepoint that emphasize email as a key entry point for ransomware and targeted attacks.
Core Responsibilities
- Advanced Support and Escalation Management
- Act as the final escalation point for incidents related to spam, phishing, malware, malicious URLs or attachments, spoofing, and business email compromise attacks.
- Lead investigations into incidents where malicious or suspicious emails have reached users, including message tracking, header analysis, sandbox results, and coordination with the Security Operations Center (SOC).
- Coordinate rapid containment actions such as email clawback, quarantine adjustments, or temporary blocks on senders and domains.
- Policy Design, Configuration, and Tuning
- Develop and maintain email security policies on platforms such as Cisco ESA, Forcepoint Email Security, Trellix or FireEye EX, and Trend Micro ScanMail, ensuring a balance between security and user experience.
- Configure anti-spam measures, reputation filters, outbreak filters, sandboxing, URL rewriting or filtering, and attachment scanning or blocking policies.
- Refine policies based on feedback related to false positives or negatives, threat intelligence, and SOC data, following clear approval workflows.
- Oversee TLS encryption policies for both inbound and outbound emails and coordinate certificate management with PKI and messaging teams.
- Email Authentication and Trust Controls
- Establish and maintain SPF, DKIM, and DMARC policies in collaboration with DNS and messaging teams to mitigate spoofing and domain abuse.
- Review authentication failures and modify alignment policies while safeguarding legitimate business communications.
- Email DLP and Data Protection Integration
- Collaborate closely with Data Protection and DLP engineers to integrate Forcepoint DLP and classification or DRM policies on email channels, ensuring sensitive data is identified and managed appropriately.
- Assist in the design and tuning of DLP policies for Personally Identifiable Information (PII), financial data, and other regulated data types, in alignment with SAMA CSF and NCA requirements.

