SOC Analyst

21 minutes ago
Full-time
Junior
Cybersecurity
BeyondTrust

BeyondTrust

BeyondTrust is a global cyber security company specializing in identity and access security solutions, trusted by over 4,000 customers worldwide.

Professional Services
1K-5K
Founded 1985
$49M raised

Description

  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms.
  • Investigate alerts to determine scope, severity, and escalation needs.
  • Use AI-assisted tools to accelerate triage, enrichment, and analysis.
  • Classify, document, and track alerts through ticketing and case management systems.
  • Participate in or lead incident response engagements from detection through remediation.
  • Perform evidence collection, forensic analysis, root cause determination, and stakeholder communication.
  • Conduct investigations using SIEM, EDR, CSPM, identity, cloud, and network log sources.
  • Execute incident response runbooks across identity, endpoint, cloud, and email workflows.
  • Contribute to detection rule design, implementation, and tuning.
  • Translate threat intelligence into actionable detection content and help maintain MITRE ATT&CK coverage.
  • Contribute to AI and automation improvements across detection, triage, and response workflows.
  • Maintain operational notes, handoff documentation, runbooks, and SOPs.
  • Track operational metrics such as MTTD, MTTR, MTTC, and false positive rate.
  • Participate in on-call rotation, tabletop exercises, purple team activities, and post-incident reviews.

Requirements

  • 2+ years of experience in a SOC, security operations, or incident response role.
  • Understanding of MITRE ATT&CK, network protocols, and endpoint behavior.
  • Experience with at least one SIEM platform and writing search or detection queries.
  • Familiarity with EDR platforms and cloud environments, with IaaS preferred.
  • Comfort using AI systems such as LLM-based assistants, copilots, or AI-driven analysis tools.
  • Strong written communication skills for technical and non-technical audiences.
  • Experience leading or co-leading complex incident response engagements is preferred.
  • Experience with identity and access management platforms and CSPM tools is preferred.
  • Scripting and automation experience with Python, PowerShell, or equivalent is preferred.
  • Familiarity with SOAR platforms or orchestration tools is preferred.
  • Experience with AI agent architectures, LLM-based automation pipelines, or prompt engineering is preferred.
  • Experience building threat intelligence programs or detection-as-code pipelines is preferred.
  • Understanding of the privileged access management landscape and related threat actors is preferred.
  • Track record of adopting emerging technologies in a production security environment is preferred.

Benefits

  • Flexible work culture focused on trust and continual learning.
  • Opportunity to work in a global cybersecurity SaaS company.
  • Collaborative team environment with threat hunters, incident responders, and detection engineers.
  • Chance to work with AI-augmented security operations and emerging automation tools.
  • Meaningful work protecting enterprise infrastructure and customer environments.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Operations Engineer

Mesh 51-200 financial services

Mesh is hiring a Security Ops Engineer to design, operate, and respond to security controls across its infrastructure and systems as it builds payments infrastructure for the next era of the global economy.

AWS Azure Datadog Docker GCP Kubernetes Network Security Python SIEM Splunk
6 minutes ago

Security analyst

Gravity Payments 51-250 Diversified Financial Services

Gravity Payments is seeking a Security Analyst to protect and improve security operations across cloud, endpoint, identity, SaaS, and corporate environments.

AWS JIRA Linux macOS Network Security Penetration Testing PowerShell Python Shell Scripting SIEM
6 minutes ago

Cybersecurity Analyst II

CareDx 251-1K Pharmaceuticals

CareDx is hiring a Cybersecurity Analyst II to support security operations for its information systems, AI security program, and compliance environment.

CrowdStrike HIPAA SIEM
51 minutes ago

Danish Speaking Cybersecurity Customer Experts - Work In Athens, Greece

Mercier Consultancy Professional Services

Mercier Consultancy Group is hiring a Danish Speaking Cybersecurity Customer Expert in Athens, Greece, to support users of cybersecurity software and help them resolve digital security issues.

CRM Cybersecurity
51 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers