Pg

Senior Endpoint Security Engineer

MANILA NET PARK OFFICEFull timeSeniorPosted 3 days ago
Apply on Pg →

Sign in to see who you know at Pg.

Job LocationMANILA NET PARK OFFICEJob DescriptionAt P&G, your career is built to scale with our iconic brands like Ariel®, Safeguard ®, Tide ®, Head & Shoulders®, Old Spice®, and Vicks®. Ready to join the team that powers our iconic brands? Here’s what you’ll be doing:Senior Endpoint Security Engineer to lead our next-generation endpoint threat modeling and endpoint security automation program. In this role, you will be the primary technical engineer responsible for shifting our security posture from reactive vulnerability patching to proactive, data-driven threat modeling and machine-speed defense. You will bridge the gap between deep endpoint telemetry, generative AI threat intelligence, and automated orchestration. By mapping complex multi-stage attack chains across Windows, macOS, Linux, and Cloud/OT host environments, you will design automated SOAR playbooks, virtual patching workflows, and behavioral detection rules that neutralize advanced AI-driven exploits before they materialize. You will also be the key automation engineer that will eliminate operational toil, drive endpoint security and SOC team efficiency, and build a cyber-resilient organization.Key Responsibilities:Proactive & Continuous Threat Modeling & Detection Engineering: Architect living, data-driven threat models and dynamic attack path diagrams by integrating live asset graphs, identity trust boundaries, deep endpoint telemetry (EDR/XDR), and Generative AI threat intelligence across Windows, macOS, Linux, and Cloud/OT fleets; use these models alongside frameworks like MITRE ATT&CK to author high-fidelity behavioral detection rules (CrowdStrike Query Language (CQL), Sigma, and YARA to block multi-stage exploit), automated virtual patching workflows, and machine-speed mitigation controls that neutralize zero-days and advanced AI-driven exploits before physical patches are deployed.AI & Predictive Threat Intelligence Integration: Operationalize cutting-edge AI threat intelligence (e.g., Claude/Glasswing research, ExPRT.ai, LLM-generated exploit models) to anticipate emergent adversary playbooks and automatically prioritize reachable, weaponized vulnerabilities.Configuration Drift & Attack Surface Reduction (ASR): Maintain proactive posture control across cross-platform endpoints by enforcing CIS benchmarks, host-based isolation, device control policies, and automated OS security drift remediation.Cross-Functional Collaboration and Continuous Improvement: Partner closely with Business Technical teams, DevOps, Infrastructure, and Security Engineering to integrate endpoint threat models into IT and OT operations without disrupting business productivity.GenAI & Tool Integration: Continually evaluate and integrate emerging GenAI security capabilities and modern APIs to keep the endpoint automation platform ahead of evolving threatsMachine-Speed Response & SOAR Automation: Design, test, and deploy automated containment playbooks usin...