Senior Cyber Defense Analyst

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of BeyondTrust

BeyondTrust

1001 - 5000 employees

Founded 1985

🔒 Cybersecurity

💰 Private Equity Round on 2021-05

Cybersecurity

BeyondTrust is a company that specializes in providing cybersecurity solutions. They focus on offering products and services that protect organizations from internal and external threats, and their solutions often involve privileged access management to secure and manage the identities and credentials of users accessing critical systems and data.

📋 Description

• Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments. • Investigate alerts to determine scope, severity, and whether escalation is warranted. • Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect. • Classify, document, and track alerts through the full lifecycle using ticketing and case management systems. • Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication. • Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data—spanning both corporate and product infrastructure. • Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows. • Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures. • Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences. • Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps. • Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors. • Help maintain and evolve detection coverage mapped to MITRE ATT&CK. • Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts. • Use AI-driven tools for alert triage, enrichment, and investigation as a standard part of daily operations. • Contribute to the evaluation, integration, and optimization of AI and automation capabilities across the team’s workflows. • Assist in designing prompts, agent workflows, or LLM-based pipelines that augment analyst capabilities and reduce manual effort. • Partner with engineering teams to improve log ingestion, data quality, and tool integrations. • Maintain daily operational notes and shift handoff documentation. • Contribute to and refine IR runbooks, playbooks, and standard operating procedures. • Participate in on-call rotation for after-hours incident escalation. • Track and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify improvement opportunities. • Participate in tabletop exercises, purple team activities, and post-incident reviews.

🎯 Requirements

• 2+ years of experience in a SOC, security operations, or incident response role. • Understanding of common attack frameworks (MITRE ATT&CK), network protocols, and endpoint behavior. • Experience with at least one SIEM platform and familiarity with writing search or detection queries. • Familiarity with EDR platforms and cloud environments (IaaS preferred). • Comfort using AI systems (e.g., LLM-based assistants, copilots, or AI-driven analysis tools) as part of security workflows. • Strong written communication skills; able to document findings clearly and concisely for both technical and non-technical audiences.

🏖️ Benefits

• Health insurance • Flexible work arrangements • Professional development opportunities • Remote work options

Apply Now

Similar Jobs

🕒 5 days ago

Enaex

5001 - 10000

Senior Energy Market Analyst in Energy Exemplar's APAC Solutions team. Engaging with clients for energy market modeling and technical sales support.

🕒 6 days ago

Gartner

10,000+ employees

🏢 Enterprise

Sr Principal Analyst at Gartner creating insights on Microsoft contract negotiations for global clients. Leading research, strategy development, and client engagement on software pricing and contracting issues.

🕒 June 25

Megaport

201 - 500

📡 Telecommunications

Senior Commercial Analyst managing commercial finance outcomes and strategic decision-making for Megaport, a leader in Network as a Service.

🕒 June 18

Sophos

1001 - 5000

🔒 Cybersecurity

☁️ SaaS

MDR Threat Analyst investigating cyber threats with enterprise systems at Sophos. Collaborating with analyst teams to ensure effective incident detection and response.

🇦🇺 Australia – Remote

💰 Post-IPO Equity on 2021-08

⏰ Full Time

🟡 Mid-level

🟠 Senior

🧐 Analyst

🕒 February 10

Teams Squared

11 - 50

🏢 Enterprise

🤝 B2B

Contract Analyst supporting contract compliance workflows within the construction sector. Reviewing contracts, extracting obligations, and ensuring data entry in compliance systems.