SOC Analyst

2 weeks, 6 days ago
Full-time
Junior
Cybersecurity
BeyondTrust

BeyondTrust

BeyondTrust is a global cyber security company specializing in identity and access security solutions, trusted by over 4,000 customers worldwide.

Professional Services
1K-5K
Founded 1985
$49M raised

Description

  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms.
  • Investigate alerts to determine scope, severity, and escalation needs.
  • Use AI-assisted tools to accelerate triage, enrichment, and analysis.
  • Classify, document, and track alerts through ticketing and case management systems.
  • Participate in or lead incident response engagements from detection through remediation.
  • Perform evidence collection, forensic analysis, root cause determination, and stakeholder communication.
  • Conduct investigations using SIEM, EDR, CSPM, identity, cloud, and network log sources.
  • Execute incident response runbooks across identity, endpoint, cloud, and email workflows.
  • Contribute to detection rule design, implementation, and tuning.
  • Translate threat intelligence into actionable detection content and help maintain MITRE ATT&CK coverage.
  • Contribute to AI and automation improvements across detection, triage, and response workflows.
  • Maintain operational notes, handoff documentation, runbooks, and SOPs.
  • Track operational metrics such as MTTD, MTTR, MTTC, and false positive rate.
  • Participate in on-call rotation, tabletop exercises, purple team activities, and post-incident reviews.

Requirements

  • 2+ years of experience in a SOC, security operations, or incident response role.
  • Understanding of MITRE ATT&CK, network protocols, and endpoint behavior.
  • Experience with at least one SIEM platform and writing search or detection queries.
  • Familiarity with EDR platforms and cloud environments, with IaaS preferred.
  • Comfort using AI systems such as LLM-based assistants, copilots, or AI-driven analysis tools.
  • Strong written communication skills for technical and non-technical audiences.
  • Experience leading or co-leading complex incident response engagements is preferred.
  • Experience with identity and access management platforms and CSPM tools is preferred.
  • Scripting and automation experience with Python, PowerShell, or equivalent is preferred.
  • Familiarity with SOAR platforms or orchestration tools is preferred.
  • Experience with AI agent architectures, LLM-based automation pipelines, or prompt engineering is preferred.
  • Experience building threat intelligence programs or detection-as-code pipelines is preferred.
  • Understanding of the privileged access management landscape and related threat actors is preferred.
  • Track record of adopting emerging technologies in a production security environment is preferred.

Benefits

  • Flexible work culture focused on trust and continual learning.
  • Opportunity to work in a global cybersecurity SaaS company.
  • Collaborative team environment with threat hunters, incident responders, and detection engineers.
  • Chance to work with AI-augmented security operations and emerging automation tools.
  • Meaningful work protecting enterprise infrastructure and customer environments.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Scientist

Figma 1K-5K Internet Software & Services

Figma is hiring a Security Scientist to use security expertise and data analysis to reduce risks, improve detection and response, and strengthen the safety of its products, platform, and IT systems.

Apache Spark Presto Python R Snowflake SQL
2 hours, 4 minutes ago

Senior TPRM Analyst

EVOCS 1-10 Internet Software & Services

EVOCS is hiring two remote Senior TPRM Analysts to lead complex third-party risk assessments, advise leadership on vendor exposures, and strengthen the company’s technology risk management program.

Cybersecurity Penetration Testing
1 day, 2 hours ago

TPRM Analyst

EVOCS 1-10 Internet Software & Services

EVOCS is hiring four remote TPRM Analysts to execute third-party security assessments, maintain accurate risk records, and drive vendor remediation activities to closure.

Cybersecurity Penetration Testing
1 day, 2 hours ago

Senior Security Assurance Engineer

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Security Compliance professional to operate its technology compliance program across corporate, security, engineering, and third-party systems, unifying controls and evidence for regulatory, contractual, and security assurance needs.

DevSecOps GitLab
2 days, 1 hour ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers