Senior Endpoint Security Engineer

Posted 10 Days Ago
Be an Early Applicant
Hiring Remotely in Office, Machaze, Manica, MOZ
Remote
Senior level
AdTech • Beauty • Marketing Tech • Retail • Pharmaceutical
The Role
Lead endpoint threat modeling, detection engineering, and security automation across Windows, macOS, Linux, and Cloud/OT environments. Build behavioral detection rules, virtual patching workflows, configuration drift remediation, and SOAR containment playbooks. Integrate endpoint telemetry, asset graphs, generative AI threat intelligence, and APIs to prioritize vulnerabilities, reduce alert fatigue, accelerate response, and improve SOC efficiency. Collaborate with DevOps, infrastructure, business technology, system administration, and security teams.
Summary Generated by Built In

Job Location

MANILA NET PARK OFFICE

Job Description

At P&G, your career is built to scale with our iconic brands like Ariel®, Safeguard ®, Tide ®, Head & Shoulders®, Old Spice®, and Vicks®.
 

Ready to join the team that powers our iconic brands? Here’s what you’ll be doing:

Senior Endpoint Security Engineer to lead our next-generation endpoint threat modeling and endpoint security automation program. In this role, you will be the primary technical engineer responsible for shifting our security posture from reactive vulnerability patching to proactive, data-driven threat modeling and machine-speed defense.
 

You will bridge the gap between deep endpoint telemetry, generative AI threat intelligence, and automated orchestration. By mapping complex multi-stage attack chains across Windows, macOS, Linux, and Cloud/OT host environments, you will design automated SOAR playbooks, virtual patching workflows, and behavioral detection rules that neutralize advanced AI-driven exploits before they materialize. You will also be the key automation engineer that will eliminate operational toil, drive endpoint security and SOC team efficiency, and build a cyber-resilient organization.

Key Responsibilities:

  • Proactive & Continuous Threat Modeling & Detection Engineering: Architect living, data-driven threat models and dynamic attack path diagrams by integrating live asset graphs, identity trust boundaries, deep endpoint telemetry (EDR/XDR), and Generative AI threat intelligence across Windows, macOS, Linux, and Cloud/OT fleets; use these models alongside frameworks like MITRE ATT&CK to author high-fidelity behavioral detection rules (CrowdStrike Query Language (CQL), Sigma, and YARA to block multi-stage exploit), automated virtual patching workflows, and machine-speed mitigation controls that neutralize zero-days and advanced AI-driven exploits before physical patches are deployed.
  • AI & Predictive Threat Intelligence Integration: Operationalize cutting-edge AI threat intelligence (e.g., Claude/Glasswing research, ExPRT.ai, LLM-generated exploit models) to anticipate emergent adversary playbooks and automatically prioritize reachable, weaponized vulnerabilities.
  • Configuration Drift & Attack Surface Reduction (ASR): Maintain proactive posture control across cross-platform endpoints by enforcing CIS benchmarks, host-based isolation, device control policies, and automated OS security drift remediation.
  • Cross-Functional Collaboration and Continuous Improvement: Partner closely with Business Technical teams, DevOps, Infrastructure, and Security Engineering to integrate endpoint threat models into IT and OT operations without disrupting business productivity.GenAI & Tool Integration: Continually evaluate and integrate emerging GenAI security capabilities and modern APIs to keep the endpoint automation platform ahead of evolving threats
  • Machine-Speed Response & SOAR Automation: Design, test, and deploy automated containment playbooks using SOAR platforms (e.g., Falcon Fusion, Torq, XSOAR) to improve Mean Time to Containment (TTC) for critical systems.
  • Streamline Operations, SOC & Endpoint Efficiency: Architect and implement end-to-end endpoint SecOps automation to eliminate repetitive, high-volume manual tasks, drastically reducing alert fatigue and operational toil and build automated enrichment, triage, and context-gathering pipelines to empower SOC analysts to make faster decisions and focus on high-value threat hunting.

Job Qualifications

1. Hands-On Automation & SecOps Engineering

  • SOAR & Orchestration: Proven technical experience building, testing, and maintaining automated playbooks and containment workflows using SOAR platforms (e.g., Falcon Fusion, Torq, Palo Alto XSOAR).
  • Scripting & API Integration: Strong hands-on proficiency with Python, PowerShell, or Bash to interact with RESTful APIs, automate endpoint pipelines, and eliminate manual SecOps toil.
  • SecOps Optimization: Practical ability to build automated triage, context-gathering, and enrichment tools that lower MTTR/MTTD and reduce alert fatigue for SOC analysts.

2. Endpoint Telemetry & Detection Engineering

  • Multi-OS Internals: Deep engineering familiarity with OS security mechanisms and telemetry parsing across Windows, macOS, Linux, and Cloud/OT host environments.
  • Virtual Patching & Host Defense: Direct experience implementing automated virtual patching, host-based isolation, and policy controls to block zero-day exploits ahead of vendor patches.
  • Rule Authoring & Query Languages: Expert-level skills authoring, testing, and tuning behavioral detection rules using query languages such as CQL (CrowdStrike Query Language), Sigma, YARA, or SPL.

3. Applied Threat Modeling, Posture Control, AI and Predictive TI Integration

  • Technical Threat Modeling: Practical skill in mapping multi-stage attack chains (using MITRE ATT&CK) and building data-driven attack path maps from live asset graphs and EDR/XDR telemetry.
  • Hardening & Drift Remediation: Direct experience implementing CIS Benchmarks, Attack Surface Reduction (ASR) policies, and automated configuration drift fixes across host fleets.
  • AI and Predictive TI Integration: Operationalize cutting-edge AI threat intelligence (e.g., Claude/Glasswing research, ExPRT.ai, LLM-generated exploit models) to anticipate emergent adversary playbooks and automatically prioritize reachable, weaponized vulnerabilities.

4. Technical Cross-Collaboration

  • Cross-Functional Partnership: Strong collaborative working style with hands-on experience pairing directly with Business Technical teams, DevOps, System Administrators, and SOC analysts to roll out endpoint automation without breaking operational workflows.

5. Technical Experience

  • Professional Background: 3+ years of hands-on experience in Endpoint Security, Detection Engineering, SOC Automation, or Systems Operations across multiple OS domains.
  • AI Use: Proficient in leveraging Generative AI tools to enhance cyber defense capabilities and overall endpoint security posture
  • Education & Certifications (Preferred): Bachelor’s degree in Computer Science, Cybersecurity, or equivalent technical experience; practical certifications like SANS/GIAC (GCIH, GCED), CrowdStrike (CCFR/CCFA), or Python/Automation credentials.

Scale your career with P&G

We provide avenues to scale your expertise and technological proficiency.
 

As an experienced hire, you are empowered to scale your impact and go beyond being a developer with opportunities to lead, guide, and collaborate on transformative projects that power our brands.

We are committed to scale your personal growth alongside the company’s success. Here’s what’s on the table:

  • Performance bonus (STAR program) that rewards managers in light with business results achieved.
  • Thrive at work and your personal life through our flexible work schedule with available work from home arrangements.
  • Your well-being is non-negotiable and supported by health insurance, fitness support, and an Employee Assistance Program.
     

Learn more about what’s in store for you at https://www.pgcareers.com/ph/en/benefits.

About us

We produce globally recognized brands and we grow the best business leaders in the industry. With a portfolio of trusted brands as diverse as ours, it is paramount our leaders are able to lead with courage the vast array of brands, categories and functions. We serve consumers around the world with one of the strongest portfolios of trusted, quality, leadership brands, including Always®, Ariel®, Gillette®, Head & Shoulders®, Herbal Essences®, Oral-B®, Pampers®, Pantene®, Tampax® and more. Our community includes operations in approximately 70 countries worldwide.

Visit http://www.pg.com to know more.

We are an equal opportunity employer and value diversity at our company. We do not discriminate against individuals on the basis of race, color, gender, age, national origin, religion, sexual orientation, gender identity or expression, marital status, citizenship, disability, HIV/AIDS status, or any other legally protected factor.

Job Schedule

Full time

Job Number

R000156399

Job Segmentation

Experienced Professionals

Skills Required

  • 3+ years of hands-on experience in endpoint security, detection engineering, SOC automation, or systems operations across multiple operating system domains
  • Proven experience building, testing, and maintaining automated playbooks and containment workflows using SOAR platforms such as Falcon Fusion, Torq, or Palo Alto XSOAR
  • Strong hands-on proficiency with Python, PowerShell, or Bash
  • Experience integrating RESTful APIs and automating endpoint security pipelines
  • Ability to build automated triage, context-gathering, and enrichment tools for SOC operations
  • Deep familiarity with security mechanisms and telemetry parsing across Windows, macOS, Linux, and Cloud/OT environments
  • Experience implementing automated virtual patching, host-based isolation, and endpoint policy controls
  • Expertise authoring, testing, and tuning behavioral detection rules using CQL, Sigma, YARA, or SPL
  • Practical experience mapping multi-stage attack chains using MITRE ATT&CK and building data-driven attack path maps
  • Experience implementing CIS Benchmarks, Attack Surface Reduction policies, and automated configuration drift remediation
  • Ability to operationalize generative AI and predictive threat intelligence for cyber defense
  • Collaborative experience working with business technical teams, DevOps, system administrators, and SOC analysts
  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent technical experience
  • SANS/GIAC certifications such as GCIH or GCED
  • CrowdStrike certifications such as CCFR or CCFA
  • Python or automation credentials

Procter & Gamble Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Procter & Gamble and has not been reviewed or approved by Procter & Gamble.

  • Fair & Transparent Compensation Compensation is considered competitive and benchmarked against top industry peers, supported by formal pay‑equity audits and stated transparent principles. Feedback suggests pay is a strong draw, with raises described as attainable and benefits starting from day one of training.
  • Healthcare Strength Health coverage is broad and immediate, including medical, dental, vision, life and disability insurance, with mental‑health and telemedicine offerings expanded recently. This breadth and day‑one access contribute to a perception of reliable, comprehensive care.
  • Parental & Family Support Parental leave is inclusive under a global framework for all parents, with added recovery time for birth mothers. Adoption, fertility, childcare support and eldercare services further strengthen family support.

Procter & Gamble Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Cincinnati, OH
117,512 Employees

What We Do

Procter & Gamble Company is an American multi-national consumer goods corporation. P&G was founded over 180 years ago as a soap and candle company. Today, we’re the world’s largest consumer goods company and home to iconic, trusted brands, including Always®, Charmin®, Braun®, Fairy®, Febreze®, Gillette®, Head & Shoulders®, Oral B®, Pantene®, Pampers®, Tide®, and Vicks®. The design, development, growth and success of these products—and many more—is thanks to the innovative and insightful minds of our people. From Day 1, you’ll help make everyday life easier for our 5 billion consumers through billion dollar brands. With our large global footprint, there are many opportunities to work with P&G in multiple locations. We offer opportunities in approximately 70 countries and continually aim to attract, reward and advance the finest people in the world. As a "build from within"​ organization, we see 95% of our people start at an entry level and progress through the organization. Here, we want you to get your career off to a fast start. That's why we don't have any rotational development programs or gradual ramping-up periods: you’ll be able—and encouraged—to dive right in from day 1. Join us and help make life better through meaningful work that makes an impact from Day 1.

Similar Jobs

Invenergy Logo Invenergy

Senior PI Administrator

Greentech • Real Estate • Social Impact • Energy • Industrial • Solar • Renewable Energy
Remote or Hybrid
18 Locations
2500 Employees
125K-155K Annually

Auror Logo Auror

Senior Engineering Lead (Risk Detection)

Artificial Intelligence • Big Data • Retail • Security • Social Impact • Software • Business Intelligence
Remote or Hybrid
Office, Machaze, Manica, MOZ
212 Employees
143K-190K Annually

Compa Logo Compa

Software Engineer

Artificial Intelligence • HR Tech • Software • Business Intelligence
Remote or Hybrid
4 Locations
75 Employees
125K-180K Annually

CrowdStrike Logo CrowdStrike

Growth Development Representative (Hybrid)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
Office, Machaze, Manica, MOZ
11000 Employees

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account