IT Security C&T

Sr.Email Security Engineer-L3

IT Security C&T  •  Amman, JO (Hybrid)  •  4 months ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

IT Security C&T is an innovative, fast-growing security consulting and training company. Our management team combined with our consultants and engineers work together to deliver comprehensive security solutions to our customers around the MENA region.

IT Security C&T is continuously expanding its team of qualified professionals for a wide range of opportunities. Interested candidates are required to apply via our Career webpage on our website (www.itsecurityct.com)

The L3 Email Security Engineer is responsible for the advanced design, tuning, and operation of the bank’s secure email gateway and email threat protection stack. This role focuses on preventing phishing, business email compromise, malware, and data loss via email. It also owns the integration of email gateways with DLP, classification, and SIEM.

Primary technology scope is:

  • Cisco Secure Email or ESA or IronPort
  • FireEye or Trellix Email Security appliance EX
  • Forcepoint Email Security Gateway
  • Trend Micro ScanMail for Exchange or equivalent

The engineer acts as the final escalation point for email security incidents, leads incident response, and drives continuous improvement in detection efficacy and false positive control. Email is currently the top attack vector in most organizations. which is supported by vendors such as Trellix and Forcepoint that highlight email as a primary entry point for ransomware and targeted attacks.

Key Responsibilities

1. Advanced Support and Escalation Management

  • Serve as the ultimate escalation point for incidents involving spam, phishing, malware, malicious URLs or attachments, spoofing, and BEC style attacks.
  • Lead investigations where malicious or suspicious email has reached users. including message tracking, header analysis, sandbox results, and coordination with SOC.
  • Coordinate rapid containment actions. such as mail claw back, quarantine tuning, or temporary blocks on senders and domains.

2. Policy Design, Configuration and Tuning

  • Design and maintain email security policies on Cisco ESA. Forcepoint Email Security. Trellix or FireEye EX. and Trend Micro ScanMail to balance security with user experience.
  • Configure anti spam, reputation filters, outbreak filters, sandboxing, URL rewriting or filtering, and attachment scanning or blocking policies.
  • Tune policies based on false positive or false negative feedback, threat intel, and SOC data. with clear approval workflows.
  • Maintain TLS encryption policies for inbound and outbound email and coordinate certificate management with PKI and messaging teams.

3. Email Authentication and Trust Controls

  • Implement and maintain SPF, DKIM, and DMARC policies in collaboration with DNS and messaging teams to reduce spoofing and domain abuse.
  • Review authentication failures and adjust alignment policies while protecting legitimate business flows.

4. Email DLP and Data Protection Integration

  • Work closely with Data Protection and DLP engineers to integrate Forcepoint DLP and classification or DRM policies on email channels. ensuring sensitive data is detected and controlled.
  • Support design and tuning of DLP policies for PII, financial data, and other regulated data types in line with SAMA CSF and NCA ECC requirements.
  • Manage workflows for DLP incidents, exceptions, and business approvals.

5. Incident Response, Threat Hunting and Reporting

  • Lead response during major email-based incidents, such as large phishing campaigns or malware outbreaks.
  • Run targeted searches or threat hunting across email logs to identify additional impacted users or campaigns.
  • Produce detailed RCAs and management reports for high impact email incidents.
  • Provide regular metrics. spam or phishing blocks, malware detections, BEC attempts, and false positive rates.

6. Governance, Compliance and ITIL

  • Execute changes through change management with impact assessment, back out plans, and testing.
  • Ensure email security configurations and monitoring comply with SAMA CSF, NCA ECC, and internal policies for secure communications, data protection, and logging.
  • Maintain audit ready evidence. policy exports, configuration baselines, test results, incident records, and approvals.

7. Collaboration and Stakeholder Engagement

  • Work with messaging and collaboration teams for routing, hybrid cloud mail, and migration projects.
  • Coordinate with L3 Network Security Engineer when issues cross layers such as TLS handshakes, DNS, or connectivity.
  • Align with SOC, SIEM, and threat intel teams to improve detection logic and response playbooks.
  • Engage with the Security Compliance Officer to produce evidence for audits and regulatory reviews.

Tooling Scope

Must have deep hands on experience in at least two, and working knowledge of all

  • Cisco Secure Email or ESA or IronPort. secure email gateway and advanced threat protection.
  • Forcepoint Email Security Gateway. including anti phishing, sandboxing, and DLP capabilities.
  • Trellix or FireEye Email Security EX or Email MPS. advanced sandboxing, URL and attachment analysis.
  • Trend Micro ScanMail for Exchange.

Good to have

  • Integration experience with Forcepoint DLP, Fortra Titus, Seclore, and SIEM platforms.

Qualifications

Required Qualifications

  • Bachelor’s degree in computer science, Information Security, or related field.
  • Minimum 7 years in cybersecurity or messaging security, with at least 4 years dedicated to secure email gateway and email threat protection platforms in large enterprises.
  • Strong understanding of SMTP, MIME, TLS for email, DNS, authentication standards such as SPF, DKIM, DMARC, and common email attack techniques.

Desired Skills and Certifications

  • Vendor certifications for at least one secure email platform. for example Cisco Email Security, Forcepoint Email Security, Trellix or FireEye Email Security, Trend Micro ScanMail or similar.
  • ITIL Foundation or practical experience with Change or Incident Management.
  • CISSP, CCSP, or similar certifications are a plus.

Additional Information

Job Location:KSA

IT Security C&T

About IT Security C&T

IT Security C&T was incorporated in March 2011 with the vision to be the leading information security and technology risk management resource center in the Middle East and North African Region. We are specialized in the delivery of affordable high-end information security and technology risk management services that are hard to find within the region at the same cost.

Our team is formed by leading specialists in their field, with experience track records of 10 - 20 years serving at key locations within the MENA region and around the world. The mission is to use this accumulated experience, knowledge, and skills, to develop highly trained bilingual consultants and trainers who are able to deliver world-class services to clients within the region.

We provide information security consulting services that range from information security and risk management strategy development to technical penetration testing and digital forensics services aimed to enable customers at various verticals to understand business and technology threats and apply appropriate controls all within a framework of industry best practices based on international standards like ISO 27000, COBIT, and ISO 20000. See Consulting for more information.

The Information security training services are aimed to provide customers with the necessary skills and knowledge to apply information security best practices within their organizations and to allow IT professionals to develop a career path in information security and risk management. See Training for more information.

The information security solutions we provide are specialized integrated solutions that address customer’s complex requirement and provides the organization with state of the art information security controls to mitigate the enterprise risk. We partner with leading vendors and provide customized solutions to meet the increasing demand of our customers to holistically address their security risks. See Solutions for more information.

Industry
IT & Software
Company Size
51-200 employees
Headquarters
Amman, JO
Year Founded
2011
Social Media