Email Security and Social Engineering Analyst
Business Area: Information Security — Security Operations
Posting Type: Internal Applicants
Work Arrangement: On-site preferred (Memphis, New Orleans, other sites to be considered)
Summary
We are seeking an associate to join the Security Operations team as an Email Security Analyst. This role will help protect the organization, our associates, and our customers by managing email security controls and investigating suspicious messages. The analyst will work extensively in Proofpoint and Outlook, triage reported phishing emails, support incident response, and help improve how we detect and respond to email-based threats.
The ideal candidate brings a healthy sense of paranoia: someone who notices when details do not add up, verifies assumptions, follows evidence, and remains appropriately skeptical without losing sight of business context. Just as important, this associate must communicate clearly and calmly with technical teams, business partners, leaders, and end users.
Why Consider This Opportunity?
This position is a great opportunity to be on the front line of threats impacting our associates and customers. You will see firsthand—and help defend against—cybersecurity and social engineering threats while gaining hands-on experience with enterprise email security, phishing response, digital risk protection, threat analysis, incident response, and security operations. You will also partner with teams across the company to investigate issues, contain threats, and protect the organization.
Essential Duties and Responsibilities
· Use the Proofpoint Secure Email Gateway and related Proofpoint tools to review and manage email traffic, alerts, quarantines, and threat activity.
· Lead day-to-day phishing response by monitoring, triaging, investigating, containing, and documenting suspicious emails reported by associates and customers.
· Address ServiceNow tickets related to phishing, email security, email delivery, and other assigned security issues within established service-level expectations.
· Troubleshoot email delivery issues by reviewing message tracking, filtering decisions, quarantines, authentication results, policy routes, allow and block controls, and other relevant data.
· Analyze message headers, sender behavior, URLs, attachments, redirects, and message context to determine whether an email is legitimate, suspicious, or malicious.
· Investigate social engineering activity, including phishing, impersonation, business email compromise, credential theft, malicious links, and fraudulent requests.
· Support digital risk protection activities by identifying, reviewing, and escalating external threats such as brand impersonation, fraudulent domains, malicious websites, and other risks targeting the organization, its associates, or its customers.
· Perform Tier 1 phishing triage and escalate confirmed threats or complex investigations as appropriate.
· Use sandboxing, threat intelligence, endpoint, identity, and logging tools to validate findings and determine potential impact.
· Support email authentication and protection controls, including DMARC, SPF, DKIM, policy routes, and email firewall rules.
· Search for related messages, contain threats, remove malicious emails, and support affected-user response actions.
· Support incident response for compromised user accounts and devices, including evidence collection, scoping, containment, escalation, remediation coordination, and documentation.
· Work with Identity, Endpoint, Security Operations, and other response teams to protect affected users, reset or secure access, isolate devices when appropriate, and confirm that threats have been contained.
· Document investigations, evidence, decisions, and actions accurately and consistently.
· Communicate findings and recommended actions to associates in clear, professional, and timely language.
· Partner with Security Operations, Threat Management, Security Engineering, Messaging, Identity, and other teams during investigations and incidents.
· Identify recurring patterns, control gaps, and opportunities to improve phishing detection, email delivery support, digital risk protection, and incident response processes.
· Participate in an after-hours rotation or respond outside normal business hours when required.
· Perform other duties as assigned.
What Success Looks Like
· You are naturally curious and willing to investigate beyond the first obvious answer.
· You maintain a healthy sense of paranoia while making evidence-based, practical decisions.
· You can distinguish unusual activity from normal business behavior and know when to ask more questions.
· You communicate with empathy and confidence, especially when an associate may be worried about a suspicious message or possible compromise.
· You remain organized and accurate while managing a queue of time-sensitive work.
· You explain technical findings in plain language and tailor your message to the audience.
· You take ownership, follow through, and escalate promptly when risk or impact is unclear.
Qualifications
· Current associate in good standing with demonstrated reliability, sound judgment, and attention to detail.
· Strong written and verbal communication skills, including the ability to interact effectively with associates, leaders, technical teams, and external contacts.
· Ability to analyze incomplete or conflicting information, recognize patterns, and make well-reasoned decisions.
· Ability to follow procedures while adapting to new attack techniques and changing business conditions.
· Comfort handling sensitive information and maintaining confidentiality.
· Ability to manage competing priorities and work independently in a fast-paced environment.
· General proficiency with Microsoft Office and collaboration tools.
· Education and experience sufficient to perform the responsibilities of the role; relevant internal experience and transferable skills will be considered.
Preferred Experience
· Experience in Information Security, fraud, investigations, technology support, risk management, compliance, customer service, operations, or another role requiring careful review and sound judgment.
· Familiarity with phishing, business email compromise, social engineering, malware, or common email threats.
· Experience with Proofpoint, Microsoft 365 email security, Splunk, endpoint detection and response tools, ticketing systems, and/or security sandboxes.
· Understanding of email headers, URLs, domains, DNS, DMARC, SPF, or DKIM.
· Experience documenting investigations or communicating findings to non-technical audiences.
· Relevant security training or certifications, including Security+, CySA+, or Proofpoint certifications.
Supervisory Responsibilities
This position has no supervisory responsibilities.
Skills Required
- Current associate in good standing with demonstrated reliability, sound judgment, and attention to detail
- Strong written and verbal communication skills
- Ability to analyze incomplete or conflicting information, recognize patterns, and make well-reasoned decisions
- Ability to follow procedures while adapting to new attack techniques and changing business conditions
- Ability to handle sensitive information and maintain confidentiality
- Ability to manage competing priorities and work independently in a fast-paced environment
- General proficiency with Microsoft Office and collaboration tools
- Education and experience sufficient to perform the responsibilities of the role
- Experience in information security, fraud, investigations, technology support, risk management, compliance, customer service, operations, or a similar role
- Familiarity with phishing, business email compromise, social engineering, malware, or common email threats
- Experience with Proofpoint, Microsoft 365 email security, Splunk, endpoint detection and response tools, ticketing systems, or security sandboxes
- Understanding of email headers, URLs, domains, DNS, DMARC, SPF, or DKIM
- Experience documenting investigations or communicating findings to non-technical audiences
- Relevant security training or certifications, including Security+, CySA+, or Proofpoint certifications
First Horizon Bank Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about First Horizon Bank and has not been reviewed or approved by First Horizon Bank.
-
Retirement Support — Retirement offerings include a 401(k) plan with company matching contributions up to 6% of pre-tax income, alongside FSA/HSA options and a defined benefit pension plan. Stock purchase and equity programs (including options and RSUs) also add to longer-term wealth-building opportunities for eligible employees.
-
Parental & Family Support — Parental leave is available for childbirth, adoption, foster parenting, or surrogacy, and adoption reimbursement is included in the package. These family-building benefits broaden support beyond traditional maternity/paternity leave structures.
-
Wellbeing & Lifestyle Benefits — Wellbeing support includes an internal wellness program, an employee assistance program, and access to a digital wellness platform. Group life insurance and disability coverage (including no-cost options) strengthen financial protection and day-to-day support.
First Horizon Bank Insights
What We Do
When we opened our doors in 1864 on North Court Street in Memphis, we had a simple mission: to provide the best service to our customers, one opportunity at a time. In the 150 years that followed, our communities transformed and expanded. We’ve seen our business and banking in general grow and adapt to the changing needs of customers through the years. But one thing that will always remain constant is our commitment to financial integrity and to helping our customers take good care of their money.

.png)






