BeyondTrust logo

BeyondTrust

Cyber Defense Engineer

Work from home

Remote role where the employee must remain based in a particular country.

United Kingdom only

Employer listed it 2 days ago · Added 5 days ago

First listed 5 days ago and still open.

Salary

Not stated

Location

United Kingdom only

Timezone

GMT

Contract

Full-time

Experience

Mid

Category

Software

This employer didn't state pay. Jobs like this usually pay around $165k–$255k a year, a typical range taken from 595 mid-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Work from home

This is a remote role, but the employee must be based in United Kingdom. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Remote Manchester, UK"

What Nomaders makes of it

  • Residency required in United Kingdom
  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

BeyondTrust is a global leader in privileged access management. Our products provide remote access and privileged control capabilities that are deployed across thousands of enterprise environments worldwide. That makes us a high-value target. Nation-state actors, ransomware operators, and sophisticated threat groups actively target companies like ours—not just to compromise our corporate environment, but to reach the customers who trust our software to protect their most sensitive systems. A compromise of BeyondTrust is a compromise of the privileged access layer inside our customers’ networks. We take that responsibility seriously.

As a Cyber Defense Engineer on our Cyber Defense Operations team, you will serve as a front-line defender responsible for protecting both BeyondTrust’s enterprise infrastructure and the integrity of the products our customers depend on. You will monitor, investigate, and respond to security events in an environment where the stakes are real and the adversaries are capable. You will work alongside experienced threat hunters, incident responders, and detection engineers in a collaborative team that values sharp analytical thinking over checkbox compliance.

This team is building toward an AI-augmented operating model. You will be expected to use AI-driven tools in your daily work and to contribute to how we integrate these capabilities into our detection, triage, and response workflows. We are not looking for people who are waiting to be told what to do—we are looking for people who want to build something.

What You’ll Do

Alert Triage & Monitoring

Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments.

Investigate alerts to determine scope, severity, and whether escalation is warranted.

Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.

Classify, document, and track alerts through the full lifecycle using ticketing and case management systems.

Incident Response & Investigation

Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.

Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data—spanning both corporate and product infrastructure.

Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows.

Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.

Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences.

Detection Engineering & Threat Intelligence

Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps.

Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors.

Help maintain and evolve detection coverage mapped to MITRE ATT&CK.

Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts.

AI Integration & Automation

Requirements

  • ·2+ years of experience in a SOC, security operations, or incident response role.
  • ·Understanding of common attack frameworks (MITRE ATT&CK), network protocols, and endpoint behavior.
  • ·Experience with at least one SIEM platform and familiarity with writing search or detection queries.
  • ·Familiarity with EDR platforms and cloud environments (IaaS preferred).
  • ·Comfort using AI systems (e.g., LLM-based assistants, copilots, or AI-driven analysis tools) as part of security workflows.

Benefits

  • ·Competitive salary and pension with up to a 10% annual bonus
  • ·25 days’ holiday which increases with length of service
  • ·Competitive pension scheme
  • ·Three weeks' additional leave at seven years' service
  • ·Fully remote in the UK with up to 4 weeks per year under our Working Abroad policy (subject to approval)

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at BeyondTrust, mentioning your remote working experience and working hours (GMT).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $165k to $255k per year · You'll be taken to the employer's careers page.