Sr SOC Analyst- Remote

BeyondTrust

United States

On-site

USD 90,000 - 130,000

Full time

12 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

BeyondTrust seeks a security operations professional to triage alerts, conduct incident investigations, and drive detection engineering and AI-assisted automation. You will work across SIEM, EDR, CSPM, and cloud sources, leading IR efforts, documenting findings, and maturing playbooks.

Strong communication and a background in privileged access security are preferred. The role emphasizes hands-on response, threat intelligence translation, and collaboration with engineering to improve data quality

Qualifications

  • 2+ years of experience in a SOC, security operations, or incident response role.

Responsibilities

  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments.
  • Investigate alerts to determine scope, severity, and whether escalation is warranted.
  • Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.
  • Classify, document, and track alerts through the full lifecycle using ticketing and case management systems.
  • Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.
  • Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data—spanning both corporate and product infrastructure.
  • Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows.
  • Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.
  • Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences.
  • Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps.
  • Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors.
  • Help maintain and evolve detection coverage mapped to MITRE ATT&CK.
  • Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts.
  • Use AI-driven tools for alert triage, enrichment, and investigation as a standard part of daily operations.
  • Contribute to the evaluation, integration, and optimization of AI and automation capabilities across the team’s workflows.
  • Assist in designing prompts, agent workflows, or LLM-based pipelines that augment analyst capabilities and reduce manual effort.
  • Partner with engineering teams to improve log ingestion, data quality, and tool integrations.
  • Maintain daily operational notes and shift handoff documentation.
  • Contribute to and refine IR runbooks, playbooks, and standard operating procedures.
  • Participate in on-call rotation for after-hours incident escalation.
  • Track and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify improvement opportunities.
  • Participate in tabletop exercises, purple team activities, and post-incident reviews.

Skills

SOC experience
MITRE ATT&CK familiarity
SIEM experience
EDR familiarity
AI system comfort
Clear writing

Tools

SIEM platform
EDR
SOAR platforms

Job description

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.
Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

BeyondTrust is a global leader in privileged access management. Our products provide remote access and privileged control capabilities that are deployed across thousands of enterprise environments worldwide. That makes us a high-value target. Nation-state actors, ransomware operators, and sophisticated threat groups actively target companies like ours—not just to compromise our corporate environment, but to reach the customers who trust our software to protect their most sensitive systems. A compromise of BeyondTrust is a compromise of the privileged access layer inside our customers’ networks. We take that responsibility seriously.
What You’ll Do

Alert Triage & Monitoring

  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments.
  • Investigate alerts to determine scope, severity, and whether escalation is warranted.
  • Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.
  • Classify, document, and track alerts through the full lifecycle using ticketing and case management systems.

Incident Response & Investigation

  • Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.
  • Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data—spanning both corporate and product infrastructure.
  • Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows.
  • Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.
  • Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences.

Detection Engineering & Threat Intelligence

  • Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps.
  • Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors.
  • Help maintain and evolve detection coverage mapped to MITRE ATT&CK.
  • Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts.

AI Integration & Automation

  • Use AI-driven tools for alert triage, enrichment, and investigation as a standard part of daily operations.
  • Contribute to the evaluation, integration, and optimization of AI and automation capabilities across the team’s workflows.
  • Assist in designing prompts, agent workflows, or LLM-based pipelines that augment analyst capabilities and reduce manual effort.
  • Partner with engineering teams to improve log ingestion, data quality, and tool integrations.

Operational Excellence

  • Maintain daily operational notes and shift handoff documentation.
  • Contribute to and refine IR runbooks, playbooks, and standard operating procedures.
  • Participate in on-call rotation for after-hours incident escalation.
  • Track and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify improvement opportunities.
  • Participate in tabletop exercises, purple team activities, and post-incident reviews.

What You’ll Bring

  • 2+ years of experience in a SOC, security operations, or incident response role.
  • Understanding of common attack frameworks (MITRE ATT&CK), network protocols, and endpoint behavior.
  • Experience with at least one SIEM platform and familiarity with writing search or detection queries.
  • Familiarity with EDR platforms and cloud environments (IaaS preferred).
  • Comfort using AI systems (e.g., LLM-based assistants, copilots, or AI-driven analysis tools) as part of security workflows.
  • Strong written communication skills; able to document findings clearly and concisely for both technical and non-technical audiences.

Nice To Have

  • Experience leading or co-leading complex incident response engagements from triage through remediation.
  • Experience with identity and access management platforms and cloud security posture management tools.
  • Scripting and automation skills (Python, PowerShell, or equivalent) applied to security workflows.
  • Familiarity with SOAR platforms or orchestration tools for automated response and enrichment.
  • Experience designing or implementing AI agent architectures, LLM-based automation pipelines, or prompt engineering for security use cases.
  • Experience building or contributing to threat intelligence programs or detection-as-code pipelines.
  • Understanding of the privileged access management landscape and the threat actors that target it.
  • Track record of evaluating and adopting emerging technologies in a production security environment.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
About Us
BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
Learn more at www.beyondtrust.com.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Software Development Engineer- Remote
Staff Software Development Engineer- Remote

BeyondTrust • United States

On-site
USD 140,000 - 210,000
Sr Software Development Engineer- Remote at BeyondTrust
Sr Software Development Engineer- Remote at BeyondTrust

Feedinkoo • United States

Remote
USD 170,000 - 230,000
Staff Software Development Engineer
Staff Software Development Engineer

Worky • Toronto (OH)

On-site
USD 140,000 - 210,000
Partner Solutions Engineer
Partner Solutions Engineer

Socket.dev • United States

Remote
USD 90,000 - 130,000
Software Development Engineer- Remote
Software Development Engineer- Remote

BeyondTrust • United States

On-site
USD 120,000 - 180,000
Partner Solutions Engineer- Remote
Partner Solutions Engineer- Remote

BeyondTrust • United States

On-site
USD 110,000 - 170,000
Software Development Engineer
Software Development Engineer

Worky • Toronto (OH)

On-site
USD 120,000 - 160,000
Sr Director, Strategic Initiatives BeyondTrust Director 11h ago
Sr Director, Strategic Initiatives BeyondTrust Director 11h ago

Remote Genie • Northern (KY)

Hybrid
USD 150,000 - 210,000
Sr Staff Software Development Engineer
Sr Staff Software Development Engineer

Worky • Toronto (OH)

On-site
USD 160,000 - 200,000
Software Development Engineer
Software Development Engineer

BeyondTrust • United States

On-site
USD 120,000 - 160,000