Senior SOC Analyst — AI-Driven Incident Response

BeyondTrust

United States

On-site

USD 90,000 - 130,000

Full time

9 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

BeyondTrust seeks a security operations professional to triage alerts, conduct incident investigations, and drive detection engineering and AI-assisted automation. You will work across SIEM, EDR, CSPM, and cloud sources, leading IR efforts, documenting findings, and maturing playbooks.

Strong communication and a background in privileged access security are preferred. The role emphasizes hands-on response, threat intelligence translation, and collaboration with engineering to improve data quality

Qualifications

  • 2+ years of experience in a SOC, security operations, or incident response role.

Responsibilities

  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments.
  • Investigate alerts to determine scope, severity, and whether escalation is warranted.
  • Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.
  • Classify, document, and track alerts through the full lifecycle using ticketing and case management systems.
  • Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.
  • Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data—spanning both corporate and product infrastructure.
  • Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows.
  • Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.
  • Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences.
  • Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps.
  • Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors.
  • Help maintain and evolve detection coverage mapped to MITRE ATT&CK.
  • Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts.
  • Use AI-driven tools for alert triage, enrichment, and investigation as a standard part of daily operations.
  • Contribute to the evaluation, integration, and optimization of AI and automation capabilities across the team’s workflows.
  • Assist in designing prompts, agent workflows, or LLM-based pipelines that augment analyst capabilities and reduce manual effort.
  • Partner with engineering teams to improve log ingestion, data quality, and tool integrations.
  • Maintain daily operational notes and shift handoff documentation.
  • Contribute to and refine IR runbooks, playbooks, and standard operating procedures.
  • Participate in on-call rotation for after-hours incident escalation.
  • Track and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify improvement opportunities.
  • Participate in tabletop exercises, purple team activities, and post-incident reviews.

Skills

SOC experience
MITRE ATT&CK familiarity
SIEM experience
EDR familiarity
AI system comfort
Clear writing

Tools

SIEM platform
EDR
SOAR platforms

Job description

BeyondTrust seeks a security operations professional to triage alerts, conduct incident investigations, and drive detection engineering and AI-assisted automation. You will work across SIEM, EDR, CSPM, and cloud sources, leading IR efforts, documenting findings, and maturing playbooks.

Strong communication and a background in privileged access security are preferred. The role emphasizes hands-on response, threat intelligence translation, and collaboration with engineering to improve data quality

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Senior SOC Analyst
Senior SOC Analyst

Soni • Philadelphia

On-site
USD 90,000 - 120,000
Senior AI-Driven SOC Engineer: Lead Incidents & Automations
Senior AI-Driven SOC Engineer: Lead Incidents & Automations

Optimum • Bethpage (NY)

On-site
USD 100,000 - 165,000
Senior SOC Analyst: AI-Driven IR & Threat Hunting
Senior SOC Analyst: AI-Driven IR & Threat Hunting

General Dynamics Information Technology • Bossier City (LA)

On-site
USD 70,000 - 110,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
SOC Analyst: Incident Response & Threat Hunter
SOC Analyst: Incident Response & Threat Hunter

Inforcer • Cerritos (CA)

On-site
USD 90,000 - 130,000
Sr SOC Analyst- Remote
Sr SOC Analyst- Remote

BeyondTrust • United States

On-site
USD 90,000 - 130,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

Cyberdata Technologies, Inc. • Herndon (VA)

On-site
USD 80,000 - 120,000
Senior SOC Analyst - Incident Response & Threat Hunting
Senior SOC Analyst - Incident Response & Threat Hunting

Alteryx • United States

Remote
USD 139,000 - 151,000
Benefits and compensation package
Bonus or commission potential