Summary
Aegis AI Security is a team of former Google engineers building defensive platforms to combat adversarial AI attacks. The Email Security Analyst (AI Operations) will investigate phishing, business email compromise, and malware threats, support customer security teams, and collaborate with product and engineering to improve AI-driven detection capabilities.
Responsibilities
- You’ll investigate and reverse-engineer real-world email attacks
- Identify patterns and trends in attacker behavior and translate those insights into improvements for our detection systems
- Collaborate with engineering to shape how our AI agents adapt to emerging threats
- Investigate Threats: Analyze suspicious emails, attachments, and links to determine maliciousness and patterns of attack
- Customer Enablement: Act as a trusted security partner for our customers, helping them understand and improve their email security posture
- Data-Driven Insights: Generate reports and dashboards that highlight trends and drive actionable recommendations
- Improve Detection: Partner with product and engineering to refine detection logic and feed intelligence into our AI agents
- Playbook Development: Document and improve processes for investigation, escalation, and communication
- Threat Intelligence: Stay ahead of emerging email threat tactics and translate them into practical defenses
Skills
- 2-5+ years of hands-on experience in cybersecurity with a strong focus on Phishing, Social Engineering, and Email-borne malware
- Proven track record of operational excellence, from triaging alerts to managing complex investigations
- Strong analytical skills — able to connect dots across multiple incidents and uncover patterns in attacker behavior
- Comfort with reverse engineering and malware analysis, both static and dynamic
- Knowledge of attacker frameworks such as MITRE ATT&CK and modern phishing TTPs
- Email Security tools
- Sandboxing platforms and forensic tools
- Strong written communication skills — able to produce clear, concise reports for both internal teams and external audiences (e.g., customers, blog posts, industry publications)
- Familiarity with Google Workspace and Microsoft 365 security ecosystems
- Bonus: Basic scripting experience (Python, PowerShell) + SQL
Qualifications
Must Haves
- 2-5+ years of hands-on experience in cybersecurity with a strong focus on Phishing, Social Engineering, and Email-borne malware
- Proven track record of operational excellence, from triaging alerts to managing complex investigations
- Strong analytical skills — able to connect dots across multiple incidents and uncover patterns in attacker behavior
- Comfort with reverse engineering and malware analysis, both static and dynamic
- Knowledge of attacker frameworks such as MITRE ATT&CK and modern phishing TTPs
- Email Security tools
- Sandboxing platforms and forensic tools
- Strong written communication skills — able to produce clear, concise reports for both internal teams and external audiences (e.g., customers, blog posts, industry publications)
- Familiarity with Google Workspace and Microsoft 365 security ecosystems
Nice to Haves
- Bonus: Basic scripting experience (Python, PowerShell) + SQL
Benefits
- Flexible work environment
- Autonomy to own your decisions