Key Tasks & Responsibilities:
Operate and manage enterprise email security controls leveraging the Microsoft 365 security product suite, with primary focus on Microsoft Defender for Office 365 (MDO) and Exchange Online Protection (EOP).
Perform email security investigations and threat analysis involving phishing, malware, spam, credential‑harvesting, and Business Email Compromise (BEC) incidents.
Analyze email headers, message traces, URLs, and attachment metadata to identify attack techniques, threat origin, and user impact.
Execute email detonation and analysis using sandboxing and detonation capabilities for suspicious attachments and URLs to determine malicious behavior.
Support email forensics activities when required, including evidence collection, timeline reconstruction, and impact assessment for major incidents.
Design, implement, and maintain email security guardrails such as anti‑phishing policies, safe links, safe attachments, impersonation protection, and domain protection rules.
Review and fine‑tune email security policies and detections to improve efficacy and reduce false positives while maintaining business productivity.
Support remediation actions including mailbox clean‑ups, URL and attachment blocking, account protection, and policy enforcement.
Collaborate with CSOC analysts, Incident Managers, Identity, and Endpoint teams during multi‑vector security incidents.
Participate in post‑incident reviews and root‑cause analysis (RCA) to improve email detection and response capabilities.
Maintain clear documentation, investigation notes, and response actions aligned with CSOC processes and audit requirements.
Provide technical guidance and escalation support to L1/L2 SOC analysts on email security investigations and tooling.
Support compliance, audit, and regulatory requests related to email security controls and incidents.
Key Skills:
Strong operational experience with Microsoft Defender for Office 365 (MDO) and Exchange Online Protection (EOP) for threat detection and response.
Ability to investigate emails using Threat Explorer, Campaign Views, message trace, and automated investigation features in M365.
Understanding of Safe Attachments, Safe Links, anti‑phishing, impersonation protection, and domain protection policies.
Hands‑on skills in analyzing malware, phishing, credential‑harvesting, BEC, and mass email flooding campaigns.
Ability to read and interpret email headers, sender reputation, authentication results, and mail‑flow indicators.
Strong working knowledge of SPF, DKIM, and DMARC for email authentication, alignment, enforcement, and troubleshooting.
Experience with email attachment and URL detonation / sandboxing to observe execution behavior and confirm malicious intent.
Solid understanding of CSOC operating models, including alert triage, investigation, escalation, and closure workflows.
Experience working with Incident Managers, L2/L3 analysts, and cross‑domain teams (Endpoint, Identity, Network).
Ability to document investigations clearly in ticketing / case‑management systems, including evidence, actions taken, and lessons learned.
Participation in post‑incident reviews (RCA/PIR) and implementation of improvement actions.
Excellent communication, stakeholder management, and crisis leadership skills.
Ability to translate technical risks into business-impact narratives for executives.
Experience in escalation management and cross-functional coordination.
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field
8 –12 years of overall cybersecurity experience with strong focus on e-mail security
Preferred Certifications:
SC‑200 – Microsoft Security Operations Analyst
Microsoft Security certifications related to Defender for Office 365 / Defender XDR
CISSP / CISM (foundational or in‑progress)
GIAC certifications related to incident response or email security (e.g., GCIH)

