Daimler Truck Banner Image contains multiple vehicles that represent each company

DTICI_Email Security Specialist – Level 3 (MDO)__T7_Principal Consultant

Key Tasks & Responsibilities: 

  • Operate and manage enterprise email security controls leveraging the Microsoft 365 security product suite, with primary focus on Microsoft Defender for Office 365 (MDO) and Exchange Online Protection (EOP).

  • Perform email security investigations and threat analysis involving phishing, malware, spam, credentialharvesting, and Business Email Compromise (BEC) incidents.

  • Analyze email headers, message traces, URLs, and attachment metadata to identify attack techniques, threat origin, and user impact.

  • Execute email detonation and analysis using sandboxing and detonation capabilities for suspicious attachments and URLs to determine malicious behavior.

  • Support email forensics activities when required, including evidence collection, timeline reconstruction, and impact assessment for major incidents.

  • Design, implement, and maintain email security guardrails such as antiphishing policies, safe links, safe attachments, impersonation protection, and domain protection rules.

  • Review and finetune email security policies and detections to improve efficacy and reduce false positives while maintaining business productivity.

  • Support remediation actions including mailbox cleanups, URL and attachment blocking, account protection, and policy enforcement.

  • Collaborate with CSOC analysts, Incident Managers, Identity, and Endpoint teams during multivector security incidents.

  • Participate in postincident reviews and rootcause analysis (RCA) to improve email detection and response capabilities.

  • Maintain clear documentation, investigation notes, and response actions aligned with CSOC processes and audit requirements.

  • Provide technical guidance and escalation support to L1/L2 SOC analysts on email security investigations and tooling.

  • Support compliance, audit, and regulatory requests related to email security controls and incidents.

 

Key Skills:

  • Strong operational experience with Microsoft Defender for Office 365 (MDO) and Exchange Online Protection (EOP) for threat detection and response.

  • Ability to investigate emails using Threat Explorer, Campaign Views, message trace, and automated investigation features in M365.

  • Understanding of Safe Attachments, Safe Links, antiphishing, impersonation protection, and domain protection policies.

  • Handson skills in analyzing malware, phishing, credentialharvesting, BEC, and mass email flooding campaigns.

  • Ability to read and interpret email headers, sender reputation, authentication results, and mailflow indicators.

  • Strong working knowledge of SPF, DKIM, and DMARC for email authentication, alignment, enforcement, and troubleshooting.

  • Experience with email attachment and URL detonation / sandboxing to observe execution behavior and confirm malicious intent.

  • Solid understanding of CSOC operating models, including alert triage, investigation, escalation, and closure workflows.

  • Experience working with Incident Managers, L2/L3 analysts, and crossdomain teams (Endpoint, Identity, Network).

  • Ability to document investigations clearly in ticketing / casemanagement systems, including evidence, actions taken, and lessons learned. 

  • Participation in postincident reviews (RCA/PIR) and implementation of improvement actions.

  • Excellent communication, stakeholder management, and crisis leadership skills.

  • Ability to translate technical risks into business-impact narratives for executives.

  • Experience in escalation management and cross-functional coordination.

Key Tasks & Responsibilities: 

  • Operate and manage enterprise email security controls leveraging the Microsoft 365 security product suite, with primary focus on Microsoft Defender for Office 365 (MDO) and Exchange Online Protection (EOP).

  • Perform email security investigations and threat analysis involving phishing, malware, spam, credentialharvesting, and Business Email Compromise (BEC) incidents.

  • Analyze email headers, message traces, URLs, and attachment metadata to identify attack techniques, threat origin, and user impact.

  • Execute email detonation and analysis using sandboxing and detonation capabilities for suspicious attachments and URLs to determine malicious behavior.

  • Support email forensics activities when required, including evidence collection, timeline reconstruction, and impact assessment for major incidents.

  • Design, implement, and maintain email security guardrails such as antiphishing policies, safe links, safe attachments, impersonation protection, and domain protection rules.

  • Review and finetune email security policies and detections to improve efficacy and reduce false positives while maintaining business productivity.

  • Support remediation actions including mailbox cleanups, URL and attachment blocking, account protection, and policy enforcement.

  • Collaborate with CSOC analysts, Incident Managers, Identity, and Endpoint teams during multivector security incidents.

  • Participate in postincident reviews and rootcause analysis (RCA) to improve email detection and response capabilities.

  • Maintain clear documentation, investigation notes, and response actions aligned with CSOC processes and audit requirements.

  • Provide technical guidance and escalation support to L1/L2 SOC analysts on email security investigations and tooling.

  • Support compliance, audit, and regulatory requests related to email security controls and incidents.

 

Key Skills:

  • Strong operational experience with Microsoft Defender for Office 365 (MDO) and Exchange Online Protection (EOP) for threat detection and response.

  • Ability to investigate emails using Threat Explorer, Campaign Views, message trace, and automated investigation features in M365.

  • Understanding of Safe Attachments, Safe Links, antiphishing, impersonation protection, and domain protection policies.

  • Handson skills in analyzing malware, phishing, credentialharvesting, BEC, and mass email flooding campaigns.

  • Ability to read and interpret email headers, sender reputation, authentication results, and mailflow indicators.

  • Strong working knowledge of SPF, DKIM, and DMARC for email authentication, alignment, enforcement, and troubleshooting.

  • Experience with email attachment and URL detonation / sandboxing to observe execution behavior and confirm malicious intent.

  • Solid understanding of CSOC operating models, including alert triage, investigation, escalation, and closure workflows.

  • Experience working with Incident Managers, L2/L3 analysts, and crossdomain teams (Endpoint, Identity, Network).

  • Ability to document investigations clearly in ticketing / casemanagement systems, including evidence, actions taken, and lessons learned. 

  • Participation in postincident reviews (RCA/PIR) and implementation of improvement actions.

  • Excellent communication, stakeholder management, and crisis leadership skills.

  • Ability to translate technical risks into business-impact narratives for executives.

  • Experience in escalation management and cross-functional coordination.

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field

  • 8 –12 years of overall cybersecurity experience with strong focus on e-mail security

  • Preferred Certifications:

    • SC200  Microsoft Security Operations Analyst

    • Microsoft Security certifications related to Defender for Office 365 / Defender XDR

    • CISSP / CISM (foundational or inprogress)

    • GIAC certifications related to incident response or email security (e.g., GCIH)

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field

  • 8 –12 years of overall cybersecurity experience with strong focus on e-mail security

  • Preferred Certifications:

    • SC200  Microsoft Security Operations Analyst

    • Microsoft Security certifications related to Defender for Office 365 / Defender XDR

    • CISSP / CISM (foundational or inprogress)

    • GIAC certifications related to incident response or email security (e.g., GCIH)

At Daimler Truck, we promote diversity and foster an inclusive corporate culture. We value the individual strengths of our employees, as these lead to the best team performance and thus to the success of our company. Inclusion and Equal opportunities are important to us – regardless of where you come from and who you are. We look forward to receiving applications from people of all cultures and genders, parents, people with disabilities and people from the LGBTIQ+ community.
At Daimler Truck, we promote diversity and foster an inclusive corporate culture. We value the individual strengths of our employees, as these lead to the best team performance and thus to the success of our company. Inclusion and Equal opportunities are important to us – regardless of where you come from and who you are. We look forward to receiving applications from people of all cultures and genders, parents, people with disabilities and people from the LGBTIQ+ community.
DAIMLER TRUCK CAREER FACEBOOK DAIMLER TRUCK CAREER INSTAGRAM