--- title: 'Sr SOC Analyst at BeyondTrust' canonical: 'https://feeny.ai/job/sr-soc-analyst-beyondtrust-manchester-kbx3bghaqep2' type: 'job' last_seen: '2026-09-11' --- # Sr SOC Analyst at BeyondTrust - **Company:** BeyondTrust - **Location:** Manchester, United Kingdom - **Work type:** remote - **Posted:** 2026-04-21 - **Last confirmed live:** 2026-09-11 - **Apply:** https://job-boards.greenhouse.io/beyondtrust/jobs/7742635 ## Job description BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio. Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself. ## The Role BeyondTrust is a global leader in privileged access management. Our products provide remote access and privileged control capabilities that are deployed across thousands of enterprise environments worldwide. That makes us a high-value target. Nation-state actors, ransomware operators, and sophisticated threat groups actively target companies like ours—not just to compromise our corporate environment, but to reach the customers who trust our software to protect their most sensitive systems. A compromise of BeyondTrust is a compromise of the privileged access layer inside our customers’ networks. We take that responsibility seriously. As a SOC Analyst on our Cyber Defense Operations team, you will serve as a front-line defender responsible for protecting both BeyondTrust’s enterprise infrastructure and the integrity of the products our customers depend on. You will monitor, investigate, and respond to security events in an environment where the stakes are real and the adversaries are capable. You will work alongside experienced threat hunters, incident responders, and detection engineers in a collaborative team that values sharp analytical thinking over checkbox compliance. This team is building toward an AI-augmented operating model. You will be expected to use AI-driven tools in your daily work and to contribute to how we integrate these capabilities into our detection, triage, and response workflows. We are not looking for people who are waiting to be told what to do—we are looking for people who want to build something. ## What You’ll Do Alert Triage & Monitoring - Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments. - Investigate alerts to determine scope, severity, and whether escalation is warranted. - Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect. - Classify, document, and track alerts through the full lifecycle using ticketing and case management systems. Incident Response & Investigation - Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication. - Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data—spanning both corporate and product infrastructure. - Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows. - Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures. - Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences. Detection Engineering & Threat Intelligence - Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps. - Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors. - Help maintain and evolve detection coverage mapped to MITRE ATT&CK. - Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts. AI Integration & Automation - Use AI-driven tools for alert triage, enrichment, and investigation as a standard part of daily operations. - Contribute to the evaluation, integration, and optimization of AI and automation capabilities across the team’s workflows. - Assist in designing prompts, agent workflows, or LLM-based pipelines that augment analyst capabilities and reduce manual effort. - Partner with engineering teams to improve log ingestion, data quality, and tool integrations. Operational Excellence - Maintain daily operational notes and shift handoff documentation. - Contribute to and refine IR runbooks, playbooks, and standard operating procedures. - Participate in on-call rotation for after-hours incident escalation. - Track and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify improvement opportunities. - Participate in tabletop exercises, purple team activities, and post-incident reviews. ## What You’ll Bring - 2+ years of experience in a SOC, security operations, or incident response role. - Understanding of common attack frameworks (MITRE ATT&CK), network protocols, and endpoint behavior. - Experience with at least one SIEM platform and familiarity with writing search or detection queries. - Familiarity with EDR platforms and cloud environments (IaaS preferred). - Comfort using AI systems (e.g., LLM-based assistants, copilots, or AI-driven analysis tools) as part of security workflows. - Strong written communication skills; able to document findings clearly and concisely for both technical and non-technical audiences. ## Nice To Have - Experience leading or co-leading complex incident response engagements from triage through remediation. - Experience with identity and access management platforms and cloud security posture management tools. - Scripting and automation skills (Python, PowerShell, or equivalent) applied to security workflows. - Familiarity with SOAR platforms or orchestration tools for automated response and enrichment. - Experience designing or implementing AI agent architectures, LLM-based automation pipelines, or prompt engineering for security use cases. - Experience building or contributing to threat intelligence programs or detection-as-code pipelines. - Understanding of the privileged access management landscape and the threat actors that target it. - Track record of evaluating and adopting emerging technologies in a production security environment. ## What We Offer - Competitive salary and pension with up to a 10% annual bonus - 25 days’ holiday which increases with length of service - Competitive pension scheme - Three weeks' additional leave at seven years' service - Fully remote in the UK with up to 4 weeks per year under our Working Abroad policy (subject to approval) - Bupa Private Healthcare for you and family - Medicash Benefit (including opticians and dental cover) - Life insurance at 4x salary and income protection - Paid parental leave and enhanced maternity leave - Employee Assistance Programme - Opportunity to co-invest and become a BeyondTrust shareholder - Investment in AI skills, with Claude Code and Copilot centres of excellence - Pluralsight and LinkedIn Learning licenses Better Together Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected. We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together. ## About Us BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders. BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners. Learn more at [www.beyondtrust.com](http://www.beyondtrust.com/). ## #LI-DF1 ## About BeyondTrust ## Company Overview - **One-liner**: BeyondTrust provides a unified identity and access security platform that protects identities, remediates threats, and delivers dynamic access across human, non-human, and AI identities. - **Entity Type**: Private (backed by private equity; no public ticker) - **Headquarters**: Not publicly available in provided sources (global company with offices in the US, Canada, UK, Germany, Netherlands, Switzerland, India, Indonesia, Philippines, Australia, and more) - **Founded**: Not publicly available (roots trace to earlier companies; current entity formed through mergers and acquisitions) - **Founders**: Not publicly available ## Core Business - **Primary industry**: Cybersecurity – Identity and Access Security (Privileged Access Management, Identity Threat Detection and Response, Secrets Management, Cloud Infrastructure Entitlement Management, Secure Remote Access) - **Target customers**: B2B, primarily large enterprises (75% of the Fortune 100 are customers), also government, mid-market, and SMBs - **Mission**: "Fight every day to secure identities, intelligently remediate threats, and deliver dynamic access to empower and protect organizations around the world." Vision: "A world where all identities and access are protected from cyber threats." ## Products & Services - **BeyondTrust Pathfinder Platform**: Unified platform that integrates PAM, ITDR, Secrets Management, CIEM, and Secure Remote Access. Enforces least privilege, zero standing privilege, just-in-time access, and discovers hidden privilege paths. - **Endpoint Privilege Management**: Removes local admin rights and enforces least privilege on endpoints. - **Password Safe**: Enterprise password and secrets vault with rotation and just-in-time access. - **Secure Remote Access**: Zero-trust remote support and vendor access (including Remote Support), with session management and credential vaulting. - **Identity Security Insights**: Analytics and reporting on identity risk. - **AI Analysis & AI Chat**: AI-powered threat detection and conversational interface for incident response. - **Entitle**: Cloud infrastructure entitlement management (CIEM) for multi-cloud environments. - **MCP Integration**: Integration with Model Context Protocol for controlling AI agent privileges. ## Market Standing - **Valuation/Market Cap**: Not publicly available (private company) - **Key Metric**: Not disclosed; recognized as a Leader in the Gartner Magic Quadrant for PAM (7 years in a row), Forrester Wave Leader for PIM, KuppingerCole Leader for ITDR, and GigaOm Leader for CIEM. - **Notable Investors/Partners**: Private equity owned (Francisco Partners and others per general knowledge, not explicitly in provided sources). Key partners include ServiceNow (integration with service desk workflows). - **Growth Signals**: 75% of the Fortune 100 are customers; continuously hiring across 45+ open positions globally; named Inc. Best Workplaces 2023, Nova Scotia's Top Employer 2022, Best Workplaces in Tech UK 2022. ## Competitive Advantages - **Unified Pathfinder Platform**: Single platform covering all identity security use cases (human, non-human, AI) rather than disconnected tools. - **True Privilege™ Technology**: Maps actual identity attack paths (lateral movement, shadow access, inherited entitlements) to uncover hidden Paths to Privilege. - **Analyst Validation**: Consistently ranked as a Leader by Gartner, Forrester, KuppingerCole, and GigaOm. - **AI Governance**: First-to-market governance for AI agent identities across multiple cloud and SaaS environments (AWS, Azure, Google, OpenAI, Salesforce, ServiceNow). - **Zero Standing Privilege**: Automates just-in-time access and auto-revokes privileges to reduce attack surface. ## Strategic Focus - **Convergence of Identity Security**: Moving beyond siloed PAM to a connected, privilege-centric identity security strategy. - **AI Identity Governance**: Enforcing privilege controls on rapidly growing AI agents and non-human identities. - **Cloud and OT Expansion**: Protecting identities across cloud, SaaS, and operational technology environments. - **Integrating with Service Management**: Streamlining workflows through integrations with ServiceNow and other IT service management tools. - **Customer Experience**: Maintaining industry-leading customer satisfaction scores through exceptional support and customer success. ## Why Work Here - **Remote-First Culture**: Most roles are fully remote with flexible work arrangements; offices exist in multiple countries. - **Award-Winning Workplace**: Recognized by Inc., Nova Scotia's Top Employer, and Best Workplaces in Tech UK. - **Core Values**: Teamwork, Integrity, Humility, Passion, Accountability, Results. Emphasis on continuous learning and growth, with training resources and career development programs. - **Diversity & Inclusion**: BeyondTrust Resource Groups (BTRGs) for affinity groups, community building, and educational events. - **Transparency**: Monthly all-hands town halls where executives share business priorities and success metrics. - **Community Impact**: BeyondGiving program supports employee-led sponsorships and global fundraising. - **Benefits**: Competitive benefits package (details not fully disclosed but includes development tools). - **Recruitment Authenticity**: The company warns about recruitment fraud, indicating a high focus on candidate safety. ## Sources 1. [beyondtrust.com - Company Overview](https://www.beyondtrust.com/company/overview) 2. [beyondtrust.com - Employee Life](https://www.beyondtrust.com/company/overview/employee-life) 3. [beyondtrust.com - Careers](https://www.beyondtrust.com/company/overview/careers) 4. [beyondtrust.com - Homepage](https://www.beyondtrust.com/) 5. [greenhouse.io - Current Openings](http://job-boards.greenhouse.io/beyondtrust) ## Other roles at BeyondTrust - [Business Development Representative](https://feeny.ai/job/business-development-representative-beyondtrust-atlanta-g1rrkmkvpfmt) — Atlanta, GA - [Business Development Representative](https://feeny.ai/job/business-development-representative-beyondtrust-atlanta-07vccj4438pw) — Atlanta, GA - [Solutions Engineer](https://feeny.ai/job/solutions-engineer-beyondtrust-calgary-fpfkcc49bhxg) — Calgary, Canada / British Columbia, Canada - [Sr SOC Analyst](https://feeny.ai/job/sr-soc-analyst-beyondtrust-canada-united-states-qc3k8g7rxgm7) — Canada / United States - [Business Development Representative - Italian Speaking](https://feeny.ai/job/business-development-representative-italian-speaking-beyondtrust-manchester-2v2ngd0y06en) — Manchester, United Kingdom - [Cloud Engineer](https://feeny.ai/job/cloud-engineer-beyondtrust-canada-united-states-2m0xr4bg9e73) — Canada / United States - [Sr Software Development Engineer](https://feeny.ai/job/sr-software-development-engineer-beyondtrust-canada-united-states-spqedr4s2t1a) — Canada / United States - [Business Development Representative](https://feeny.ai/job/business-development-representative-beyondtrust-manchester-hvta3veashjk) — Manchester, United Kingdom - [Account Executive II - Riyadh (Saudi National)](https://feeny.ai/job/account-executive-ii-riyadh-saudi-national-beyondtrust-riyadh-fvbs1avsw66x) — Riyadh, Saudi Arabia - [Customer Retention Executive](https://feeny.ai/job/customer-retention-executive-beyondtrust-united-states-us-east-coast-hfpkxt9pc784) — United States / US East Coast