BeyondTrust logo

BeyondTrust

Cyber Defense Engineer

Region RestrictedNew this week

Remote work allowed only within certain countries or regions.

Employer listed it 2 days ago · Added 2 days ago

First listed 2 days ago.

Salary

Not stated

Location

Timezone

US East

Contract

Full-time

Experience

Mid

Category

Software

This employer didn't state pay. Jobs like this usually pay around $160k–$250k a year, a typical range taken from 595 mid-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Region Restricted

Remote work is allowed, but only for candidates based in Canada, United States, United Kingdom.

What the employer says

  • Source listing states candidate location: "Remote Canada | Remote United States, Remote Manchester, UK"

What Nomaders makes of it

  • Applications outside the listed area are usually rejected
  • Timezone overlap with the listed area is often expected

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

BeyondTrust is a global leader in privileged access management. Our products provide remote access and privileged control capabilities that are deployed across thousands of enterprise environments worldwide. That makes us a high-value target. Nation-state actors, ransomware operators, and sophisticated threat groups actively target companies like ours—not just to compromise our corporate environment, but to reach the customers who trust our software to protect their most sensitive systems. A compromise of BeyondTrust is a compromise of the privileged access layer inside our customers’ networks. We take that responsibility seriously.

As a Cyber Defense Engineer on our Cyber Defense Operations team, you will serve as a front-line defender responsible for protecting both BeyondTrust’s enterprise infrastructure and the integrity of the products our customers depend on. You will monitor, investigate, and respond to security events in an environment where the stakes are real and the adversaries are capable. You will work alongside experienced threat hunters, incident responders, and detection engineers in a collaborative team that values sharp analytical thinking over checkbox compliance.

This team is building toward an AI-augmented operating model. You will be expected to use AI-driven tools in your daily work and to contribute to how we integrate these capabilities into our detection, triage, and response workflows. We are not looking for people who are waiting to be told what to do—we are looking for people who want to build something.

What You’ll Do

Alert Triage & Monitoring

Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments.

Investigate alerts to determine scope, severity, and whether escalation is warranted.

Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.

Classify, document, and track alerts through the full lifecycle using ticketing and case management systems.

Incident Response & Investigation

Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.

Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data—spanning both corporate and product infrastructure.

Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows.

Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.

Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences.

Detection Engineering & Threat Intelligence

Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps.

Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors.

Help maintain and evolve detection coverage mapped to MITRE ATT&CK.

Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts.

AI Integration & Automation

Requirements

  • ·2+ years of experience in a SOC, security operations, or incident response role.
  • ·Understanding of common attack frameworks (MITRE ATT&CK), network protocols, and endpoint behavior.
  • ·Experience with at least one SIEM platform and familiarity with writing search or detection queries.
  • ·Familiarity with EDR platforms and cloud environments (IaaS preferred).
  • ·Comfort using AI systems (e.g., LLM-based assistants, copilots, or AI-driven analysis tools) as part of security workflows.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, region restricted, matches where you plan to live and work.
  2. 2Tailor your CV to the role at BeyondTrust, mentioning your remote working experience and working hours (US East).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 3d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $160k to $250k per year · You'll be taken to the employer's careers page.