ActiveJobs

Senior Endpoint Security Engineer

Procter & Gamble · MANILA NET PARK OFFICE

Full-timeOn-sitePosted 24 August 2026
Apply on Company Site →

Job description

Job Location MANILA NET PARK OFFICE Job Description At P&G, your career is built to scale with our iconic brands like Ariel®, Safeguard ®, Tide ®, Head & Shoulders®, Old Spice®, and Vicks®. Ready to join the team that powers our iconic brands? Here’s what you’ll be doing: Senior Endpoint Security Engineer to lead our next-generation endpoint threat modeling and endpoint security automation program. In this role, you will be the primary technical engineer responsible for shifting our security posture from reactive vulnerability patching to proactive, data-driven threat modeling and machine-speed defense. You will bridge the gap between deep endpoint telemetry, generative AI threat intelligence, and automated orchestration. By mapping complex multi-stage attack chains across Windows, macOS, Linux, and Cloud/OT host environments, you will design automated SOAR playbooks, virtual patching workflows, and behavioral detection rules that neutralize advanced AI-driven exploits before they materialize. You will also be the key automation engineer that will eliminate operational toil, drive endpoint security and SOC team efficiency, and build a cyber-resilient organization. Key Responsibilities: Proactive & Continuous Threat Modeling & Detection Engineering: Architect living, data-driven threat models and dynamic attack path diagrams by integrating live asset graphs, identity trust boundaries, deep endpoint telemetry (EDR/XDR), and Generative AI threat intelligence across Windows, macOS, Linux, and Cloud/OT fleets; use these models alongside frameworks like MITRE ATT&CK to author high-fidelity behavioral detection rules (CrowdStrike Query Language (CQL), Sigma, and YARA to block multi-stage exploit), automated virtual patching workflows, and machine-speed mitigation controls that neutralize zero-days and advanced AI-driven exploits before physical patches are deployed. AI & Predictive Threat Intelligence Integration: Operationalize cutting-edge AI threat intelligence (e.g., Claude/Glasswing research, ExPRT.ai, LLM-generated exploit models) to anticipate emergent adversary playbooks and automatically prioritize reachable, weaponized vulnerabilities. Configuration Drift & Attack Surface Reduction (ASR): Maintain proactive posture control across cross-platform endpoints by enforcing CIS benchmarks, host-based isolation, device control policies, and automated OS security drift remediation. Cross-Functional Collaboration and Continuous Improvement: Partner closely with Business Technical teams, DevOps, Infrastructure, and Security Engineering to integrate endpoint threat models into IT and OT operations without disrupting business productivity.GenAI & Tool Integration: Continually evaluate and integrate emerging GenAI security capabilities and modern APIs to keep the endpoint automation platform ahead of evolving threats Machine-Speed Response & SOAR Automation: Design, test, and deploy automated containment playbooks using SOAR platforms (e.g., Falcon Fusion, Torq, XSOAR) to improve Mean Time to Containment (TTC) for critical systems. Streamline Operations, SOC & Endpoint Efficiency: Architect and implement end-to-end endpoint SecOps automation to eliminate repetitive, high-volume manual tasks, drastically reducing alert fatigue and operational toil and build automated enrichment, triage, and context-gathering pipelines to empower SOC analysts to make faster decisions and focus on high-value threat hunting. Job Qualifications 1. Hands-On Automation & SecOps Engineering SOAR & Orchestration: Proven technical experience building, testing, and maintaining automated playbooks and containment workflows using SOAR platforms (e.g., Falcon Fusion, Torq, Palo Alto XSOAR). Scripting & API Integration: Strong hands-on proficiency with Python, PowerShell, or Bash to interact with RESTful APIs, automate endpoint pipelines, and eliminate manual SecOps toil. SecOps Optimization: Practical ability to build automated triage, context-gathering, and enrichment tools that lower MTTR/MTTD and reduce alert fatigue for SOC analysts. 2. Endpoint Telemetry & Detection Engineering Multi-OS Internals: Deep engineering familiarity with OS security mechanisms and telemetry parsing across Windows, macOS, Linux, and Cloud/OT host environments. Virtual Patching & Host Defense: Direct experience implementing automated virtual patching, host-based isolation, and policy controls to block zero-day exploits ahead of vendor patches. Rule Authoring & Query Languages: Expert-level skills authoring, testing, and tuning behavioral detection rules using query languages such as CQL (CrowdStrike Query Language), Sigma, YARA, or SPL. 3. Applied Threat Modeling, Posture Control, AI and Predictive TI Integration Technical Threat Modeling: Practical skill in mapping multi-stage attack chains (using MITRE ATT&CK) and building data-driven attack path maps from live asset graphs and EDR/XDR telemetry. Hardening & Drift Remediation: Direct experience implementing CIS Benchmarks, Attack Surface Reduction (ASR) policies, and automated configuration drift fixes across host fleets. AI and Predictive TI Integration: Operationalize cutting-edge AI threat intelligence (e.g., Claude/Glasswing research, ExPRT.ai, LLM-generated exploit models) to anticipate emergent adversary playbooks and automatically prioritize reachable, weaponized vulnerabilities. 4. Technical Cross-Collaboration Cross-Functional Partnership: Strong collaborative working style with hands-on experience pairing directly with Business Technical teams, DevOps, System Administrators, and SOC analysts to roll out endpoint automation without breaking operational workflows. 5. Technical Experience Professional Background: 3+ years of hands-on experience in Endpoint Security, Detection Engineering, SOC Automation, or Systems Operations across multiple OS domains. AI Use: Proficient in leveraging Generative AI tools to enhance cyber defense capabilities and overall endpoint security posture Education & Certifications (Preferred): Bachelor’s degree in Computer Science, Cybersecurity, or equivalent technical experience; practical certifications like SANS/GIAC (GCIH, GCED), CrowdStrike (CCFR/CCFA), or Python/Automation credentials. Scale your career with P&G We provide avenues to scale your expertise and technological proficiency. As an experienced hire, you are empowered to scale your impact and go beyond being a developer with opportunities to lead, guide, and collaborate on transformative projects that power our brands. We are committed to scale your personal growth alongside the company’s success. Here’s what’s on the table: Performance bonus (STAR program) that rewards managers in light with business results achieved. Thrive at work and your personal life through our flexible work schedule with available work from home arrangements. Your well-being is non-negotiable and supported by health insurance, fitness support, and an Employee Assistance Program. Learn more about what’s in store for you at https://www.pgcareers.com/ph/en/benefits. About us We produce globally recognized brands and we grow the best business leaders in the industry. With a portfolio of trusted brands as diverse as ours, it is paramount our leaders are able to lead with courage the vast array of brands, categories and functions. We serve consumers around the world with one of the strongest portfolios of trusted, quality, leadership brands, including Always®, Ariel®, Gillette®, Head & Shoulders®, Herbal Essences®, Oral-B®, Pampers®, Pantene®, Tampax® and more. Our community includes operations in approximately 70 countries worldwide. Visit http://www.pg.com to know more. We are an equal opportunity employer and value diversity at our company. We do not discriminate against individuals on the basis of race, color, gender, age, national origin, religion, sexual orientation, gender identity or expression, marital status, citizenship, disability, HIV/AIDS status, or any other le

Verified and listed by ActiveJobs. Applications are made directly on Procter & Gamble's own career page — we never sit in the middle.