368,910open jobs
9,449companies
47,822added this week
Browse all
Salary
$104k – $237k per year (Estimated)
Location
Remote/Hybrid (Tel Aviv, Israel)
Seniority
Senior · 2+ years exp
Overview
Company
Impact
Profile match
BeyondTrust is a cybersecurity software company headquartered in Atlanta, Georgia, and founded in 2006. The organization provides a platform for privileged access management, identity security, and secure remote access to protect organizations from data breaches and internal threats. It operates globally across various sectors, serving thousands of customers including government agencies and large enterprises under the ownership of Francisco Partners.

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

BeyondTrust is a global leader in privileged access management. Our products provide remote access and privileged control capabilities that are deployed across thousands of enterprise environments worldwide. That makes us a high-value target. Nation-state actors, ransomware operators, and sophisticated threat groups actively target companies like ours-not just to compromise our corporate environment, but to reach the customers who trust our software to protect their most sensitive systems. A compromise of BeyondTrust is a compromise of the privileged access layer inside our customers’ networks. We take that responsibility seriously.

As a SOC Analyst on our Cyber Defense Operations team, you will serve as a front-line defender responsible for protecting both BeyondTrust’s enterprise infrastructure and the integrity of the products our customers depend on. You will monitor, investigate, and respond to security events in an environment where the stakes are real and the adversaries are capable. You will work alongside experienced threat hunters, incident responders, and detection engineers in a collaborative team that values sharp analytical thinking over checkbox compliance.

This team is building toward an AI-augmented operating model. You will be expected to use AI-driven tools in your daily work and to contribute to how we integrate these capabilities into our detection, triage, and response workflows. We are not looking for people who are waiting to be told what to do-we are looking for people who want to build something.

What You’ll Do

Alert Triage & Monitoring 

  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments.
  • Investigate alerts to determine scope, severity, and whether escalation is warranted.
  • Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.
  • Classify, document, and track alerts through the full lifecycle using ticketing and case management systems.

Incident Response & Investigation 

  • Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.
  • Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data-spanning both corporate and product infrastructure.
  • Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows.
  • Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.
  • Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences.

Detection Engineering & Threat Intelligence 

  • Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps.
  • Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors.
  • Help maintain and evolve detection coverage mapped to MITRE ATT&CK.
  • Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts.

AI Integration & Automation 

  • Use AI-driven tools for alert triage, enrichment, and investigation as a standard part of daily operations.
  • Contribute to the evaluation, integration, and optimization of AI and automation capabilities across the team’s workflows.
  • Assist in designing prompts, agent workflows, or LLM-based pipelines that augment analyst capabilities and reduce manual effort.
  • Partner with engineering teams to improve log ingestion, data quality, and tool integrations.

Operational Excellence 

  • Maintain daily operational notes and shift handoff documentation.
  • Contribute to and refine IR runbooks, playbooks, and standard operating procedures.
  • Participate in on-call rotation for after-hours incident escalation.
  • Track and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify improvement opportunities.
  • Participate in tabletop exercises, purple team activities, and post-incident reviews. 

What You’ll Bring

  • 2+ years of experience in a SOC, security operations, or incident response role.
  • Understanding of common attack frameworks (MITRE ATT&CK), network protocols, and endpoint behavior.
  • Experience with at least one SIEM platform and familiarity with writing search or detection queries.
  • Familiarity with EDR platforms and cloud environments (IaaS preferred).
  • Comfort using AI systems (e.g., LLM-based assistants, copilots, or AI-driven analysis tools) as part of security workflows.
  • Strong written communication skills; able to document findings clearly and concisely for both technical and non-technical audiences.

Nice To Have

  • Experience leading or co-leading complex incident response engagements from triage through remediation.
  • Experience with identity and access management platforms and cloud security posture management tools.
  • Scripting and automation skills (Python, PowerShell, or equivalent) applied to security workflows.
  • Familiarity with SOAR platforms or orchestration tools for automated response and enrichment.
  • Experience designing or implementing AI agent architectures, LLM-based automation pipelines, or prompt engineering for security use cases.
  • Experience building or contributing to threat intelligence programs or detection-as-code pipelines.
  • Understanding of the privileged access management landscape and the threat actors that target it.
  • Track record of evaluating and adopting emerging technologies in a production security environment.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at www.beyondtrust.com

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,910 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Tel Aviv
$170k – $220k per year • Equity 1–2.8% • In office • Full-Time • 3+ years exp • San Francisco
Python
SQL
Python
Django
AI/ML
AI Agents
Context Engineering
LLM
LLM Evaluation
RAG
Apply
In office • Internship • Master's Degree • Austin
C++
Python
C++
PyTorch C++
AI/ML
AI Agents
CUDA
CUDA Toolkit
LLM
NCCL
PyTorch
TensorRT
TensorRT-LLM
Triton
vLLM
Apply
$54k – $128k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Mexico City
C#
JavaScript
Python
TypeScript
C#
ASP.NET Core
Python
FastAPI
Databases
PostgreSQL
AI/ML
AI Agents
Anthropic
Embeddings
Function Calling
LLM
LLM Guardrails
Model Context Protocol
OpenAI
Semantic Search
Semantic Search
Frontend
Angular
React.js
DevOps
AWS
Azure
CI/CD
GitHub
GitHub Actions
Vector
Vercel
Apply
$18k – $45k per year (Estimated) • Remote/Hybrid • Moscow
AI/ML
CUDA
CUDA Toolkit
cuDNN
LLM
NVLink
Ollama
PyTorch
TensorRT
vLLM
DevOps
Docker
Windows Server
Apply
$173k – $314k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • San Francisco
Apex
JavaScript
Node JS
Python
SQL
TypeScript
Apex
Lightning Web Components
AI/ML
Agentforce
AI Agents
Claude
Claude Code
Copilot
Cursor
LLM
RAG
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub
Grafana
gRPC
Kubernetes
New Relic
Prometheus
Splunk
Marketing
Salesforce
QA
Cypress
JMeter
k6
Locust
Playwright
Postman
Rest-Assured
Selenium
Apply
Cloud Engineer 3 days ago
$66k – $179k per year (Estimated) • Remote • 3+ years exp • Bachelor's Degree
PowerShell
Python
AI/ML
Claude
Claude Code
Copilot
DevOps
AWS
Azure
CI/CD
Datadog
GCP
Git
GitHub Actions
Prometheus
Terraform
Amazon CloudWatch
GitHub
IAM
Cybersecurity
BeyondTrust
FedRAMP
ISO 27001
NIST CSF
SOC 2
Apply
$100k – $195k per year (Estimated) • Remote
C#
Go
JavaScript
TypeScript
AI/ML
AI Agents
Claude
Claude Code
Frontend
Angular
React.js
Vue.js
DevOps
AWS
CI/CD
CloudFormation
Terraform
IAM
Cybersecurity
BeyondTrust
Microsoft Entra ID
Apply
$94k – $176k per year (Estimated) • Remote • 7+ years exp • Bachelor's Degree • New York
Cybersecurity
BeyondTrust
Apply
$78k – $176k per year (Estimated) • Remote
Java
TypeScript
JavaScript
Java
Spring Boot
AI/ML
Claude
Claude Code
Copilot
Frontend
Angular
Mobile
JUnit
DevOps
AWS
Azure
Git
Cybersecurity
BeyondTrust
Apply
SOC Analyst 12 days ago
$54k – $138k per year (Estimated) • Remote • 2+ years exp
PowerShell
Python
AI/ML
AI Agents
LLM
Prompt Engineering
Cybersecurity
BeyondTrust
Apply
Product Manager 1 day ago
$91k – $210k per year (Estimated) • In office • 4+ years exp • Tel Aviv
AI/ML
LLM
Apply
$68k – $224k per year (Estimated) • Remote/Hybrid • 7+ years exp • Bachelor's Degree • Tel Aviv
JavaScript
Frontend
React.js
Apply
$159k – $348k per year (Estimated) • In office • Tel Aviv
AI/ML
AI Agents
Human-in-the-Loop
LLM Guardrails
Model Context Protocol
RAG
DevOps
CI/CD
Kubernetes
Cybersecurity
Least Privilege
Apply
$65k – $156k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Tel Aviv
C++
DevOps
Platform Engineering
RTOS
Apply
Equity • Remote/Hybrid • Part-Time • Bachelor's Degree • Tel Aviv
Python
SQL
AI/ML
AI Agents
Marketing
Salesforce
Apply
See all jobs
This is one of many
368,910 more open roles from verified company boards, updated every day.