yoinka

Senior Endpoint Security Engineer

Procter & Gamble

MANILA NET PARK OFFICESenior
Sign in to applyVerified 3h ago
Location
MANILA NET PARK OFFICE
Work model
On-Site
Level
Senior
Posted
Aug 24, 2026

Skills

CybersecurityGenAILLMLinuxPythonRESTShell

About this role

Job Location MANILA NET PARK OFFICE Job Description At P&G, your career is built to scale with our iconic brands like Ariel ® , Safeguard ® , Tide ® , Head & Shoulders ® , Old Spice ® , and Vicks ®.   Ready to join the team that powers our iconic brands? Here’s what you’ll be doing: Senior Endpoint Security Engineer to lead our next-generation endpoint threat modeling and endpoint security automation program . In this role, you will be the primary technical engineer responsible for shifting our security posture from reactive vulnerability patching to proactive, data-driven threat modeling and machine-speed defense.   You will bridge the gap between deep endpoint telemetry, generative AI threat intelligence, and automated orchestration. By mapping complex multi-stage attack chains across Windows, macOS, Linux, and Cloud/OT host environments, you will design automated SOAR playbooks, virtual patching workflows, and behavioral detection rules that neutralize advanced AI-driven exploits before they materialize. You will also be the key automation engineer that will eliminate operational toil, drive endpoint security and SOC team efficiency, and build a cyber-resilient organization.

Key Responsibilities

Proactive & Continuous Threat Modeling & Detection Engineering: Architect living, data-driven threat models and dynamic attack path diagrams by integrating live asset graphs, identity trust boundaries, deep endpoint telemetry (EDR/XDR), and Generative AI threat intelligence across Windows, macOS, Linux, and Cloud/OT fleets; use these models alongside frameworks like MITRE ATT&CK to author high-fidelity behavioral detection rules (CrowdStrike Query Language (CQL), Sigma, and YARA to block multi-stage exploit), automated virtual patching workflows, and machine-speed mitigation controls that neutralize zero-days and advanced AI-driven exploits before physical patches are deployed. AI & Predictive Threat Intelligence Integration : Operationalize cutting-edge AI threat intelligence (e.g., Claude/Glasswing research, ExPRT.ai, LLM-generated exploit models) to anticipate emergent adversary playbooks and automatically prioritize reachable, weaponized vulnerabilities. Configuration Drift & Attack Surface Reduction (ASR) : Maintain proactive posture control across cross-platform endpoints by enforcing CIS benchmarks, host-based isolation, device control policies, and automated OS security drift remediation. Cross-Functional Collaboration and Continuous Improvement: Partner closely with Business Technical teams, DevOps, Infrastructure, and Security Engineering to integrate endpoint threat models into IT and OT operations without disrupting business productivity. GenAI & Tool Integration: Continually evaluate and integrate emerging GenAI security capabilities and modern APIs to keep the endpoint automation platform ahead of evolving threats Machine-Speed Response & SOAR Automation: Design, test, and deploy automated containment playbooks using SOAR platforms (e.g., Falcon Fusion, Torq, XSOAR) to improve Mean Time to Containment (TTC) for critical systems. Streamline Operations, SOC & Endpoint Efficiency: Architect and implement end-to-end endpoint SecOps automation to eliminate repetitive, high-volume manual tasks, drastically reducing alert fatigue and operational toil and build automated enrichment, triage, and context-gathering pipelines to empower SOC analysts to make faster decisions and focus on high-value threat hunting. Job Qualifications 1. Hands-On Automation & SecOps Engineering SOAR & Orchestration: Proven technical experience building, testing, and maintaining automated playbooks and containment workflows using SOAR platforms (e.g., Falcon Fusion, Torq, Palo Alto XSOAR ). Scripting & API Integration: Strong hands-on proficiency with Python, PowerShell, or Bash to interact with RESTful APIs, automate endpoint pipelines, and eliminate manual SecOps toil. SecOps Optimization: Practical ability to build automated triage,

Listing verified 3h ago. Applications go through the company's official careers site.

← Back to Yoinka

Senior Endpoint Security Engineer at Procter & Gamble, MANILA NET PARK OFFICE | Yoinka