hirq
← All jobs

Sutherland

Lead - SME (Email Abuse)

Hyderabad, TS, IN · On-site · Full-time

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

CybersecuritySIEM
At Sutherland we are a group of energetic and driven individuals. If you are looking to build a fulfilling career and are confident you have the skills and experience to help us succeed, we want to work with you! Role Summary: The Subject Matter Expert (SME) – Mail Operations will serve as a technical and operational expert supporting email operations, spam/abuse mitigation, and Trust & Safety workflows. The role will be responsible for handling complex and escalated cases, providing subject matter guidance to analysts, monitoring emerging email abuse trends, and supporting operational excellence in a 24x7 environment. Key Responsibilities: - Act as the Subject Matter Expert for email operations, spam, phishing, spoofing, abuse, and related Trust & Safety workflows. - Provide real-time guidance and support to analysts in handling complex, high-risk, and escalated email abuse cases. - Review complex cases and ensure decisions are aligned with defined policies, procedures, and security protocols. - Monitor trends related to spam, phishing, spoofing, malware, account abuse, and other forms of email-based threats, and identify emerging patterns. - Support incident investigations, root cause analysis (RCA), and corrective/preventive actions for operational and quality issues. - Conduct regular knowledge-sharing, coaching, calibration, and refresher sessions for analysts to improve process understanding and decision accuracy. - Support Team Leaders and Operations Managers with quality, productivity, SLA, and operational performance insights. - Leverage Splunk and other relevant tools to monitor operational trends, investigate incidents, track KPIs, and generate actionable insights. - Demonstrate a strong understanding of SPF, DKIM, DMARC, SMTP, email headers, and email infrastructure to support investigations and troubleshooting. - Identify process gaps and recommend process improvements, automation opportunities, and workflow optimizations. - Support the development and maintenance of SOPs, process documentation, knowledge articles, and troubleshooting guides. - Participate in calibration sessions and quality reviews to drive consistency and accuracy across the team. - Partner with cross-functional teams, including Trust & Safety, Security, Engineering, Product, Quality, and Operations, to resolve complex issues and improve workflows. - Support new-hire training, nesting, upskilling, and ongoing capability-building for the operations team. - Stay current on evolving email threats, abuse patterns, authentication standards, and industry best practices, and translate relevant insights into operational improvements. - Support 24x7 operations, including shift-based activities, escalations, and critical incident management as required. - 4+ years of experience in email operations, Trust & Safety, email security, SOC, cybersecurity operations, or a related domain. - Strong understanding of SMTP, SPF, DKIM, DMARC, email headers, DNS, and email infrastructure. - Hands-on experience with Splunk, including dashboard usage, log analysis, monitoring, and investigation. - Strong knowledge of spam, phishing, spoofing, malicious emails, email abuse, and threat vectors. - Demonstrated experience handling complex investigations, escalations, and incident analysis. - Strong analytical and problem-solving skills with the ability to identify patterns and determine appropriate actions. - Experience conducting RCA, trend analysis, quality reviews, and process improvement initiatives. - Strong communication and stakeholder-management skills, with the ability to explain technical concepts to both technical and non-technical audiences. - Ability to work independently, make sound decisions, and provide real-time operational guidance in a fast-paced environment. - Experience working in a 24x7 operational setup is preferred. - Preferred Skills: - Experience in email security, cybersecurity, Trust & Safety, or abuse prevention. - Knowledge of SIEM tools, threat intelligence, log analysis, and security monitoring. - Familiarity with automation, scripting, or data-analysis tools. - Experience working with large-scale email platforms or cloud-based email environments. - Relevant certifications in cybersecurity, email security, or cloud technologies would be an advantage.