
Remote opportunity at
BeyondTrustCyber Defense Engineer
BeyondTrust seeks a Cyber Defense Engineer to join its Cyber Defense Operations team on a remote basis. In this role, you will protect both enterprise infrastructure…
Career Tools
About This Role
BeyondTrust seeks a Cyber Defense Engineer to join its Cyber Defense Operations team on a remote basis. In this role, you will protect both enterprise infrastructure and customer-facing product environments from advanced threat groups, ransomware operators, and nation-state actors. The company specializes in identity security and privileged access management, providing software relied upon by thousands of global organizations, including a large portion of the Fortune 100. This position suits security…
Job Description
BeyondTrust seeks a Cyber Defense Engineer to join its Cyber Defense Operations team on a remote basis. In this role, you will protect both enterprise infrastructure and customer-facing product environments from advanced threat groups, ransomware operators, and nation-state actors. The company specializes in identity security and privileged access management, providing software relied upon by thousands of global organizations, including a large portion of the Fortune 100.
This position suits security professionals eager to combine traditional threat analysis with modern artificial intelligence tools. Daily work involves collaborating with threat hunters, detection engineers, and incident responders within an environment that incorporates AI-driven copilots and automation pipelines. Team members participate in ongoing operational duties, detection rule engineering, and after-hours on-call rotations.
Responsibilities
- Monitor, triage, and investigate security alerts across EDR, SIEM, and CSPM platforms
- Use AI-assisted enrichment tools to speed up analysis and manage alerts via ticketing systems
- Lead or participate in incident response lifecycle activities from detection to remediation and forensic analysis
- Execute incident response runbooks spanning cloud, identity, endpoint, and email workflows
- Create decision-ready post-incident reports and summaries for technical and leadership audiences
- Design, tune, and implement detection rules to decrease false positives and address coverage gaps
- Translate threat intelligence reports into actionable detection content mapped to the MITRE ATT&CK framework
- Utilize AI-driven systems and help design prompts or agent workflows for daily security operations
- Participate in an on-call rotation for after-hours incident escalation and track operational metrics
- Engage in tabletop exercises, purple team drills, and post-incident reviews
Requirements
- At least 4 years of experience working in a Security Operations Center, incident response, or security operations environment
- Familiarity with network protocols, endpoint behavior, and common attack frameworks like MITRE ATT&CK
- Practical background using at least one SIEM platform and writing search or detection queries
- Working knowledge of cloud environments and EDR platforms
- Comfort utilizing AI systems and LLM-based analysis tools within security workflows
- Strong written communication abilities for documenting technical findings clearly
Qualifications
- Prior experience leading complex incident response engagements from initial triage to final remediation
- Familiarity with cloud security posture management tools and identity and access management platforms
- Scripting and automation experience using PowerShell, Python, or equivalent languages
- Experience with SOAR platforms or automated response orchestration tools
- Background in designing AI agent architectures or prompt engineering for security applications
- Experience contributing to threat intelligence programs or detection-as-code pipelines
Core Skills
Benefits
- Competitive salary and pension scheme with up to a 10 percent annual bonus
- 25 days of holiday which increases based on length of service
- Three weeks of additional leave upon reaching seven years of service
- Fully remote work model in the UK with up to 4 weeks per year allowed under a Working Abroad policy
- Bupa Private Healthcare for you and your family
- Medicash Benefit providing dental and opticians cover
- Life insurance at 4x salary and income protection
- Paid parental leave and enhanced maternity leave
- Employee Assistance Programme
- Opportunity to co-invest and become a shareholder
- Access to learning platforms including Pluralsight and LinkedIn Learning
Frequently Asked Questions
Answers are based only on the employer’s listing; where it doesn’t say, neither do we.
What is the location and remote work policy for this role?
The position is fully remote in the UK, with up to four weeks per year permitted under a Working Abroad policy subject to approval.
What type of employment is this?
The posting specifies a full-time employment type.
What salary does this position offer?
The exact salary is not stated in the job posting, though it mentions a competitive salary and pension with up to a 10 percent annual bonus.
How many years of experience are required to apply?
Candidates must have four or more years of experience in a security operations, SOC, or incident response role.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.