Cyber Defense Engineer

BeyondTrust, Inc.

United States

Remote

USD 87,000 - 134,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Bupa healthcare
Parental leave
Employee Assistance Programme
Learning budgets
AI skills development
Holiday entitlement 25 days
Annual bonus up to 10%
Pension plan

Job summary

BeyondTrust is seeking a Security Operations Engineer to defend enterprise infrastructure and a widely deployed privileged access management product used by thousands of organizations. You will monitor, investigate, and respond to security events within a Cyber Defense Operations team.

You will design and tune detection rules, translate threat intel into content, and contribute to AI-driven triage and investigation workflows.

Qualifications

  • Hands-on experience in security operations or incident response across SIEM, EDR, and cloud-native log sources.
  • Strong analytical thinking with the ability to produce clear, decision-ready incident documentation.
  • Scripting and automation skills in Python, PowerShell, or equivalent applied to security workflows.
  • Familiarity with identity and access management platforms and cloud security posture management tools.

Responsibilities

  • Triage and investigate alerts across SIEM, EDR, and CSPM platforms covering corporate and product environments.
  • Participate in or lead incident response from detection through remediation, including forensic analysis, evidence handling, and post-incident reporting.
  • Design, tune, and maintain detection rules mapped to MITRE ATT&CK, reducing false positives and closing coverage gaps.
  • Translate threat intelligence from CVE advisories, CISA alerts, and vendor bulletins into actionable detection content.
  • Use and help shape AI-driven tools for triage, enrichment, and investigation workflows.
  • Collaborate with threat hunting peers to validate detection logic through hypothesis-driven hunts.

Skills

Security operations
Incident response
Python
PowerShell
AI-driven workflows
IAM platforms
Cloud security posture management

Tools

SIEM
EDR
CSPM

Job description

Role overview

This role defends both enterprise infrastructure and the integrity of a widely deployed privileged access management product used by thousands of organizations. As part of a Cyber Defense Operations team, the engineer monitors, investigates, and responds to security events while contributing to detection engineering in an AI-augmented operating model.

Responsibilities
  • Triage and investigate alerts across SIEM, EDR, and CSPM platforms covering corporate and product environments
  • Participate in or lead incident response from detection through remediation, including forensic analysis, evidence handling, and post-incident reporting
  • Design, tune, and maintain detection rules mapped to MITRE ATT&CK, reducing false positives and closing coverage gaps
  • Translate threat intelligence from CVE advisories, CISA alerts, and vendor bulletins into actionable detection content
  • Use and help shape AI-driven tools for triage, enrichment, and investigation workflows
  • Collaborate with threat hunting peers to validate detection logic through hypothesis-driven hunts
Requirements
  • Hands-on experience in security operations or incident response across SIEM, EDR, and cloud-native log sources
  • Strong analytical thinking with the ability to produce clear, decision-ready incident documentation
  • Scripting and automation skills in Python, PowerShell, or equivalent applied to security workflows
  • Familiarity with identity and access management platforms and cloud security posture management tools
Nice to have
  • Experience with SOAR platforms for automated response and enrichment
  • Background designing or implementing AI agent architectures, LLM-based pipelines, or prompt engineering for security use cases
  • Experience building or contributing to threat intelligence programs or detection-as-code pipelines
  • Understanding of the privileged access management landscape and the threat actors that target it
Benefits and work setup
  • Competitive salary with pension and up to a 10% annual bonus
  • 25 days of holiday plus additional leave at length-of-service milestones
  • Bupa private healthcare for employee and family
  • Medicash benefit covering optical and dental care
  • Life insurance at 4x salary and income protection
  • Paid parental leave with enhanced maternity leave
  • Employee Assistance Programme
  • Fully remote in the UK with up to 4 weeks per year of working abroad, subject to approval
  • Learning budgets including Pluralsight and LinkedIn Learning
  • Investment in AI skills development
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Security Operations
Director of Security Operations

backblaze • United States

Remote
USD 205,000 - 230,000
RSU grants for full-time employees
ESP P program
401K plan
+5
Staff Security Engineer
Staff Security Engineer

Primerai • United States

Remote
USD 175,000 - 235,000
Remote work
Comprehensive benefits
401(k) with match
+4
Staff CSIRT Analyst
Staff CSIRT Analyst

Hidden Jobs • United States

Remote
USD 180,000 - 240,000
Remote US-wide
Generous paid time off
Medical, dental & vision benefits
+4
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

samsara • United States

Hybrid
USD 150,000 - 190,000
Professional development stipend
Comprehensive health coverage
Parental leave plans
Cyber Defense Platforms Staff Engineer
Cyber Defense Platforms Staff Engineer

Scorpion Therapeutics • Cambridge (MA)

On-site
USD 170,000 - 230,000
Security Engineer
Security Engineer

five9 • United States

Hybrid
USD 66,000 - 175,000
Equity
Performance bonus
Remote work
+1
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
Applied Cyber, Email Security (Detection Engineering)
Applied Cyber, Email Security (Detection Engineering)

Wilco • United States

On-site
USD 120,000 - 180,000
Flexible PTO
Health benefits
Parental leave
+1
Threat Intelligence and Detection Engineer
Threat Intelligence and Detection Engineer

Insane Cyber • San Antonio (TX)

On-site
USD 90,000 - 120,000
Competitive Base Salary
Equity offering subject to board approval
Comprehensive medical/dental/vision/life insurance plan
+2
Lead Cyber Security Engineer
Lead Cyber Security Engineer

capitalbank • United States

Remote
USD 115,000 - 125,000
Medical insurance
Dental insurance
Vision insurance
+2