Why This Role Stands Out
Advance your career in a remote Email Security Tier 2 Analyst role at TEKNEWGEN LLC, where you'll gain exposure to enterprise-level security challenges and collaborate with diverse teams. This position is ideal for a proactive individual with experience in email security technologies and a passion for protecting organizations from advanced threats. Apply today to join a dynamic environment focused on continuous learning and impactful contributions.
Quick Overview
Job Description
IT Email Security – Tier 2 Analyst
Location: REMOTE [No Second Jobs]
Visa Type: H1B1 / / Citizen / OPT’s – No Sponsorship
Contact: /
Contact Name: Sri
Position Summary
The IT Email Security Analyst – Tier 2 is responsible for monitoring, investigating, analyzing, and responding to advanced email security threats across the enterprise. This role serves as a Tier 2 escalation point for complex email security incidents involving phishing, business email compromise (BEC), malware, ransomware, spoofing, impersonation, malicious URLs, and email-based social engineering.
The ideal candidate will have hands-on experience with Check Point Harmony Email & Collaboration, enterprise email security technologies, Microsoft 365/Exchange Online, and email authentication standards including DMARC, SPF, and DKIM.
The analyst will collaborate closely with SOC, Incident Response, Threat Intelligence, Identity, Network, Messaging, and Security Engineering teams to strengthen email security controls and reduce the organization's exposure to email-based attacks.
Key Responsibilities
Tier 2 Email Security Operations
- Serve as a Tier 2 escalation point for complex email security alerts and incidents.
- Investigate suspicious and malicious emails escalated from Tier 1 SOC or Service Desk teams.
- Analyze phishing, malware, ransomware, BEC, credential harvesting, spoofing, and impersonation attacks.
- Investigate malicious URLs, attachments, sender infrastructure, domains, IP addresses, and email headers.
- Determine the scope, severity, and potential business impact of email security incidents.
- Conduct root-cause analysis and recommend appropriate containment and remediation actions.
- Escalate confirmed or high-impact incidents to Incident Response/Tier 3 teams.
- Provide technical guidance to Tier 1 analysts during complex email investigations.
Check Point Harmony Email & Collaboration
- Monitor and investigate email security events using Check Point Harmony Email & Collaboration.
- Configure, maintain, and tune email security policies and protection mechanisms.
- Investigate threats identified through anti-phishing, anti-malware, URL protection, attachment protection, and impersonation controls.
- Analyze security alerts and improve detection accuracy while minimizing false positives.
- Support email security policy configuration and enforcement.
- Investigate user-reported suspicious emails and determine whether messages are malicious, suspicious, or legitimate.
- Support remediation activities such as email quarantine, message removal, sender/domain blocking, and threat containment.
- Work with Check Point and internal security teams to troubleshoot platform-related issues and improve protection.
Email Security & Threat Detection
- Monitor email traffic for indicators of phishing, BEC, malware, credential theft, and social engineering.
- Analyze email headers, authentication results, sender reputation, URLs, attachments, and delivery paths.
- Investigate suspicious sender domains, lookalike domains, spoofed addresses, and executive impersonation.
- Identify malicious attachments and potentially harmful file types.
- Analyze links and redirect chains associated with phishing campaigns.
- Identify coordinated or widespread phishing campaigns targeting multiple employees.
- Develop and maintain email threat detection and response procedures.
DMARC / SPF / DKIM
- Monitor and analyze DMARC, SPF, and DKIM authentication results.
- Investigate DMARC failures and determine whether failures are caused by legitimate senders, configuration issues, spoofing, or malicious activity.
- Support implementation, monitoring, troubleshooting, and optimization of DMARC policies.
- Analyze DMARC aggregate and forensic reporting where available.
- Assist with SPF record configuration and troubleshooting.
- Validate DKIM signing and investigate DKIM authentication failures.
- Work with DNS, Messaging, Infrastructure, and Application teams to remediate email authentication issues.
- Support efforts to improve the organization's email authentication posture and reduce domain spoofing.
Phishing & Business Email Compromise
- Investigate suspected phishing and Business Email Compromise (BEC) incidents.
- Analyze compromised or suspicious accounts and associated email activity.
- Identify credential-harvesting attempts and malicious login links.
- Investigate suspicious mailbox rules, forwarding rules, and account activity when associated with email compromise.
- Determine whether an email campaign is targeted, opportunistic, or part of a broader threat campaign.
- Support account containment and remediation in coordination with Identity and Incident Response teams.
- Identify and block malicious domains, URLs, senders, and indicators as appropriate.
Microsoft 365 / Exchange Online Security
- Investigate email security events within Microsoft 365 and Exchange Online.
- Analyze message trace information and email delivery behavior.
- Investigate suspicious mailbox activity and forwarding configurations.
- Work with Microsoft Defender for Office 365 and related Microsoft security capabilities where applicable.
- Support email security policy management and troubleshooting.
- Collaborate with Messaging/Exchange administrators on email delivery and security issues.
Threat Intelligence & Security Analysis
- Leverage threat intelligence to investigate malicious domains, IP addresses, URLs, attachments, and sender infrastructure.
- Research emerging phishing campaigns and email-based attack techniques.
- Correlate email security events with endpoint, identity, SIEM, and network telemetry.
- Track indicators of compromise associated with active email campaigns.
- Map attack techniques to the MITRE ATT&CK framework where applicable.
- Translate emerging email threats into actionable detection and prevention improvements.
SIEM / SOC Integration
- Integrate and correlate email security telemetry with enterprise SIEM/SOC platforms.
- Develop or maintain detection rules for email-based threats.
- Investigate correlations between email activity and endpoint, identity, and network events.
- Support SOC dashboards, alerts, and reporting related to email security.
- Provide investigation data and indicators to Incident Response and Threat Intelligence teams.
Security Engineering & Continuous Improvement
- Tune email security policies to improve detection effectiveness and reduce false positives.
- Identify gaps in email security controls and recommend improvements.
- Develop and maintain email security runbooks, SOPs, playbooks, and knowledge articles.
- Identify opportunities for automation of repetitive email security processes.
- Participate in post-incident reviews and implement lessons learned.
- Support security awareness initiatives by providing technical insight into emerging phishing techniques.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent professional experience.
- 3–7+ years of experience in cybersecurity, SOC, email security, incident response, or security operations.
- Experience working in a Tier 2 SOC or security operations environment.
- Hands-on experience investigating email-based security threats.
- Strong understanding of phishing, BEC, spoofing, malware, malicious URLs, and email-based attacks.
- Strong knowledge of email headers and email authentication mechanisms.
- Experience with Microsoft 365 / Exchange Online security.
- Strong analytical and investigative skills.
- Ability to investigate security incidents independently and communicate findings clearly.
Preferred Technical Experience
- Check Point Harmony Email & Collaboration
- DMARC
- SPF
- DKIM
- Microsoft 365
- Exchange Online
- Microsoft Defender for Office 365
- Microsoft Sentinel
- SIEM platforms
- Email security gateways
- Anti-phishing technologies
- Threat Intelligence Platforms
- EDR/XDR
- DNS
- URL analysis
- Malware analysis
- Email header analysis
- ServiceNow or other ITSM platforms
- Security automation / SOAR
Preferred Certifications
- Check Point Security certifications
- Microsoft SC-200
- Microsoft SC-300
- CompTIA Security+
- CompTIA CySA+
- GIAC certifications
- CISSP
- CEH
- Other recognized cybersecurity or email-security certifications
Key Competencies
- Tier 2 SOC Operations
- Email Security
- Check Point Harmony
- Phishing Investigation
- Business Email Compromise
- DMARC
- SPF / DKIM
- Email Header Analysis
- Microsoft 365 Security
- Exchange Online
- Threat Intelligence
- Incident Response
- Malware Analysis
- URL Analysis
- SIEM Integration
- Security Monitoring
- Detection & Alert Tuning
- Root-Cause Analysis
- Security Incident Investigation
- Technical Documentation
Success Measures
The successful candidate will:
- Quickly and accurately investigate escalated email security incidents.
- Reduce organizational exposure to phishing, BEC, spoofing, and email-borne malware.
- Improve DMARC/SPF/DKIM effectiveness and email authentication.
- Optimize Check Point Harmony Email & Collaboration policies and detections.
- Reduce false positives while maintaining strong threat detection.
- Improve the speed and quality of phishing investigations.
- Identify emerging email threats and proactively strengthen security controls.
- Improve correlation between email, endpoint, identity, and SIEM security events.
- Provide high-quality technical analysis to SOC and Incident Response teams.
Ideal Candidate Profile
The ideal candidate is a hands-on Tier 2 Email Security Analyst who can go beyond basic alert triage and independently investigate sophisticated phishing, BEC, spoofing, and malware campaigns.
Strong Check Point Harmony Email & Collaboration experience is highly desirable, while practical experience with DMARC, SPF, DKIM, Microsoft 365, email header analysis, and phishing investigations is preferred.
The candidate should have an investigative mindset, strong attention to detail, and the ability to connect seemingly unrelated email, identity, endpoint, and network events to determine the full scope of a security incident.
Contact: /
Similar jobs
- VA
College to Corporate IT Internship - Risk & Security - Engineer (NC)
NewVanguard
Charlotte, North Carolina🇺🇸Hybrid5 minutes agoAgileAdministrative - HT
Microsoft Purview / DLP Security Engineer
NewHire Tech Services
United States🇺🇸Remote22 hours agoGDPRHIPAAPowerShell+2Technology - NG
2027 Systems Security Engineering Intern - Roy UT with Security Clearance
NewNorthrop Grumman
Roy, UT🇺🇸$23 - $29/hrHybrid22 hours agoAdministrative - IS
Information Security Analyst
NewINSPYR Solutions
United States🇺🇸$50 - $55/hrRemote22 hours agoAWSPenetration TestingTechnology - NG
Principal/Sr. Principal Cyber Protection Engineer (AHT) with Security Clearance
NewNorthrop Grumman
Rome, NY🇺🇸$103.6k - $155.4k/yrHybrid22 hours agoPythonPowerShellBash+15Technology - KT
Network & Systems Security Analyst
NewKforce Technology Staffing
Tampa, FL🇺🇸Hybrid22 hours agoLESSVMwareActive Directory+1Technology