companyIT Security C&T logo

Senior Email Security Engineer - Level 3

On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Mid to Senior

Qualifications

Required QualificationsBachelor’s degree in Computer Science, Information Security, or a related field. At least 7 years of experience in cybersecurity or messaging security, with a minimum of 4 years focused on secure email gateway and email threat protection platforms within large enterprises. In-depth knowledge of SMTP, MIME, TLS for email, DNS, authentication standards like SPF, DKIM, DMARC, and common email attack methodologies. Preferred Skills and CertificationsVendor certifications for at least one secure email platform, such as Cisco Email Security, Forcepoint Email Security, Trellix or FireEye Email Security, Trend Micro ScanMail, or similar. ITIL Foundation certification or practical experience with Change or Incident Management. CISSP, CCSP, or similar credentials are advantageous.

About the job

The Senior Level 3 Email Security Engineer plays a crucial role in the advanced design, optimization, and management of the bank’s secure email gateway and email threat protection systems. This position is pivotal in thwarting phishing attempts, business email compromise, malware intrusions, and data loss through email. The engineer will also oversee the integration of email gateways with Data Loss Prevention (DLP), classification systems, and Security Information and Event Management (SIEM) solutions.

Key Technologies Include:

  • Cisco Secure Email, ESA, or IronPort
  • FireEye or Trellix Email Security Appliance EX
  • Forcepoint Email Security Gateway
  • Trend Micro ScanMail for Exchange or equivalent

The engineer will serve as the ultimate escalation point for email security incidents, lead incident response efforts, and drive continuous enhancements in detection efficacy and management of false positives. Email remains the primary attack vector for many organizations, as supported by vendors like Trellix and Forcepoint that emphasize email as a key entry point for ransomware and targeted attacks.

Core Responsibilities

  1. Advanced Support and Escalation Management
    • Act as the final escalation point for incidents related to spam, phishing, malware, malicious URLs or attachments, spoofing, and business email compromise attacks.
    • Lead investigations into incidents where malicious or suspicious emails have reached users, including message tracking, header analysis, sandbox results, and coordination with the Security Operations Center (SOC).
    • Coordinate rapid containment actions such as email clawback, quarantine adjustments, or temporary blocks on senders and domains.
  2. Policy Design, Configuration, and Tuning
    • Develop and maintain email security policies on platforms such as Cisco ESA, Forcepoint Email Security, Trellix or FireEye EX, and Trend Micro ScanMail, ensuring a balance between security and user experience.
    • Configure anti-spam measures, reputation filters, outbreak filters, sandboxing, URL rewriting or filtering, and attachment scanning or blocking policies.
    • Refine policies based on feedback related to false positives or negatives, threat intelligence, and SOC data, following clear approval workflows.
    • Oversee TLS encryption policies for both inbound and outbound emails and coordinate certificate management with PKI and messaging teams.
  3. Email Authentication and Trust Controls
    • Establish and maintain SPF, DKIM, and DMARC policies in collaboration with DNS and messaging teams to mitigate spoofing and domain abuse.
    • Review authentication failures and modify alignment policies while safeguarding legitimate business communications.
  4. Email DLP and Data Protection Integration
    • Collaborate closely with Data Protection and DLP engineers to integrate Forcepoint DLP and classification or DRM policies on email channels, ensuring sensitive data is identified and managed appropriately.
    • Assist in the design and tuning of DLP policies for Personally Identifiable Information (PII), financial data, and other regulated data types, in alignment with SAMA CSF and NCA requirements.

About IT Security C&T

IT Security C&T is a dynamic and rapidly expanding security consulting and training firm. Our dedicated management team, alongside our consultants and engineers, collaborates to provide comprehensive security solutions to clients throughout the MENA region. We are consistently enhancing our team of qualified professionals and offer a variety of exciting opportunities. Interested candidates are encouraged to apply through our Career webpage at www.itsecurityct.com.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.