Sr SOC Analyst

BeyondTrust
Canada, United States
Workplace: RemoteFull timeFunction: CybersecurityExperience: 2+ yearsSkills: ["Written communication","Analytical thinking"]

Serve as a front-line SOC analyst on the Cyber Defense Operations team, monitoring and triaging alerts across SIEM, EDR, and CSPM for both corporate and product environments. Investigate incidents from detection through remediation, perform evidence collection and forensic analysis, and produce decision-ready incident summaries. Help tune detections, translate threat intelligence into actionable detection content, and use AI-driven tools to accelerate triage, enrichment, and response while supporting ongoing runbooks and operational metrics.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
BeyondTrust
BeyondTrust
2 days ago

Sr SOC Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Serve as a front-line SOC analyst on the Cyber Defense Operations team, monitoring and triaging alerts across SIEM, EDR, and CSPM for both corporate and product environments. Investigate incidents from detection through remediation, perform evidence collection and forensic analysis, and produce decision-ready incident summaries. Help tune detections, translate threat intelligence into actionable detection content, and use AI-driven tools to accelerate triage, enrichment, and response while supporting ongoing runbooks and operational metrics.
Location: Canada, United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Monitor and triage security alerts across SIEM, EDR, and CSPM for corporate and product environments.
  • •Investigate and respond to incidents, including evidence collection, forensic analysis, root-cause determination, and stakeholder communication.
  • •Contribute to detection engineering by tuning detection rules to reduce false positives and close coverage gaps.
  • •Translate threat intelligence (e.g., CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content.
  • •Use AI-driven tools for alert triage, enrichment, and investigation, and participate in ongoing runbooks, playbooks, and on-call escalation.

Key Requirements

  • •2+ years of experience in a SOC, security operations, or incident response role.
  • •Understanding of MITRE ATT&CK, network protocols, and endpoint behavior.
  • •Experience with at least one SIEM platform and familiarity with writing search or detection queries.
  • •Familiarity with EDR platforms and cloud environments (IaaS preferred).
  • •Comfort using AI systems (e.g., LLM-based assistants/copilots) as part of security workflows.
Experience:2+ yearsSecurity operationsIncident responseSOC
Skills:Written communicationAnalytical thinking
Tech Stack:SIEMEDRCSPMTicketingCase managementIdentity provider logsCloud audit trailsNetwork flow dataMITRE ATT&CKAILLMAI-driven triagePythonPowerShellSOARCVECISA

Company Brief

BeyondTrust
Provides privileged access management, vulnerability management, and secure remote access solutions to help organizations protect credentials, manage privileges, and secure endpoints across on-premises and cloud environments.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Phoenix, United States
WebsiteLinkedIn