Cyber Defense Analyst- Remote

Remote Full-time
BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

BeyondTrust is a global leader in privileged access management. Our products provide remote access and privileged control capabilities that are deployed across thousands of enterprise environments worldwide. That makes us a high-value target.

Nation-state actors, ransomware operators, and sophisticated threat groups actively target companies like ours—not just to compromise our corporate environment, but to reach the customers who trust our software to protect their most sensitive systems. A compromise of BeyondTrust is a compromise of the privileged access layer inside our customers’ networks. We take that responsibility seriously.

As a SOC Analyst on our Cyber Defense Operations team, you will serve as a front-line defender responsible for protecting both BeyondTrust’s enterprise infrastructure and the integrity of the products our customers depend on. You will monitor, investigate, and respond to security events in an environment where the stakes are real and the adversaries are capable. You will work alongside experienced threat hunters, incident responders, and detection engineers in a collaborative team that values sharp analytical thinking over checkbox compliance.

This team is building toward an AI-augmented operating model. You will be expected to use AI-driven tools in your daily work and to contribute to how we integrate these capabilities into our detection, triage, and response workflows. We are not looking for people who are waiting to be told what to do—we are looking for people who want to build something.

What You’ll Do

Alert Triage & Monitoring
• Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments.
• Investigate alerts to determine scope, severity, and whether escalation is warranted.
• Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.
• Classify, document, and track alerts through the full lifecycle using ticketing and case management systems.

Incident Response & Investigation
• Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.
• Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data—spanning both corporate and product infrastructure.
• Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows.
• Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.
• Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences.

Detection Engineering & Threat Intelligence
• Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps.
• Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors.
• Help maintain and evolve detection coverage mapped to MITRE ATT&CK.
• Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts.

AI Integration & Automation
• Use AI-driven tools for alert triage, enrichment, and investigation as a standard part of daily operations.
• Contribute to the evaluation, integration, and optimization of AI and automation capabilities across the team’s workflows.
• Assist in designing prompts, agent workflows, or LLM-based pipelines that augment analyst capabilities and reduce manual effort.
• Partner with engineering teams to improve log ingestion, data quality, and tool integrations.

Operational Excellence
• Maintain daily operational notes and shift handoff documentation.
• Contribute to and refine IR runbooks, playbooks, and standard operating procedures.
• Participate in on-call rotation for after-hours incident escalation.
• Track and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify improvement opportunities.
• Participate in tabletop exercis
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

**Experienced Full Stack Customer Support Representative – Remote Chat Jobs at arenaflex**

Remote Full-time

Clinical Research Associate, Full Service

Remote Full-time

[Remote] Software Engineer - Generative AI

Remote Full-time

Join Today: Baker and Packager Associate

Remote Full-time

Fully Remote Representative - Entry Level

Remote Full-time

Senior Director/Director Operations, VirtuOx

Remote Full-time

Applied Scientist - Deep Learning (Fully remote, U.S. Only)

Remote Full-time

Commercial Inside Sales Client Advisors

Remote Full-time

Part-Time In-Person Academic Tutor

Remote Full-time

Store Support

Remote Full-time
← Back to Home