Role Overview
The Anti-Phishing Specialist leads the organization’s efforts to detect, prevent, and
respond to phishing attacks and other email-based threats. This role is pivotal in
developing robust anti-phishing strategies, managing email security technologies,
responding to incidents, and educating users to enhance organizational resilience
against cyber threats.
Key Responsibilities
• Identify and facilitate takedown of phishing websites and rogue applications.
• Proactively address a broad spectrum of cyber threats including DDoS,
ransomware, business email compromise (BEC), spear phishing, whaling,
vishing, and other social engineering attacks.
• Monitor and analyze inbound emails to detect malicious content and
recommend rule adjustments to reduce email-borne threats.
• Design, implement, and maintain anti-phishing strategies, policies, and
procedures.
• Manage and optimize anti-phishing tools and platforms, including DMARC,
DKIM, SPF, and secure email gateways.
• Develop advanced detection rules and filters to counter evolving phishing
tactics.
• Lead phishing-related incident response efforts—containment, eradication,
recovery, and post-incident review.
• Deliver regular employee training and awareness programs on phishing
prevention.
• Collaborate with security teams to provide guidance on email security best
practices.
• Evaluate emerging anti-phishing technologies and recommend improvements.
• Stay abreast of current phishing trends, attack methods, and mitigation
techniques.
• Produce detailed reports on phishing incidents, metrics, and defensive
performance.
Qualifications
• Bachelor’s degree in Computer Science, Information Security, or a related
field.
• 5+ years of hands-on experience in anti-phishing, email security, or a similar
domain.
• Strong expertise in email protocols (SMTP, etc.) and security standards (DMARC,
DKIM, SPF).
• Proven experience with enterprise email security solutions (e.g., Proofpoint,
Mimecast, Ironscales).
• Deep understanding of phishing tactics, social engineering, and email-based
threat vectors.
• Strong analytical, problem-solving, and communication skills.
• Demonstrated leadership in mentoring or guiding security teams.
• Preferred certifications: CISSP, Certified Email Security Manager (CESM), or
equivalent.