IT 与编程
Cyber Defense Engineer(远程职位)
BeyondTrust
链接会跳转到原始招聘信息。Donator 不代收申请。
Telegram 上的最新职位
每一条新的远程职位,发布即推送。
@donator_jobs_zh
Cyber Defense Engineer:「IT 与编程」类别,完全远程
这条招聘信息来自 BeyondTrust,岗位是 Cyber Defense Engineer。职位属于「IT 与编程」类别,完全远程。公司不限制候选人的居住地,在任何地方都可以申请。
公司没有公布具体数字,这一项会在面试时谈定。对工作时间,招聘信息没有提出任何条件。
这个职位通过了自动核查:凡是要求外国工作许可、签证担保、特定国籍,或者必须居住在指定国家的招聘信息,都不会进入列表。
要点
- 公司
- BeyondTrust
- 类别
- IT 与编程
- 谁可以申请
- 来自世界任何国家
- 工作方式
- 完全远程
- 发布时间
- 2026年10月10日 (今天)
- 有效期
- 截至 2026年11月19日
- 来源
- We Work Remotely
新职位邮件提醒:IT 与编程
职位板每天更新数次。只有出现新的、已核查的职位时才会写信。不发垃圾邮件,也不需要注册账号。
已经订阅过了? 管理订阅设置
公司发布的职位描述
Headquarters: Remote Manchester, UK
BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.
Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.
The Role
BeyondTrust is a global leader in privileged access management. Our products provide remote access and privileged control capabilities that are deployed across thousands of enterprise environments worldwide. That makes us a high-value target. Nation-state actors, ransomware operators, and sophisticated threat groups actively target companies like ours-not just to compromise our corporate environment, but to reach the customers who trust our software to protect their most sensitive systems. A compromise of BeyondTrust is a compromise of the privileged access layer inside our customers’ networks. We take that responsibility seriously.
As a Cyber Defense Engineer on our Cyber Defense Operations team, you will serve as a front-line defender responsible for protecting both BeyondTrust’s enterprise infrastructure and the integrity of the products our customers depend on. You will monitor, investigate, and respond to security events in an environment where the stakes are real and the adversaries are capable. You will work alongside experienced threat hunters, incident responders, and detection engineers in a collaborative team that values sharp analytical thinking over checkbox compliance.
This team is building toward an AI-augmented operating model. You will be expected to use AI-driven tools in your daily work and to contribute to how we integrate these capabilities into our detection, triage, and response workflows. We are not looking for people who are waiting to be told what to do-we are looking for people who want to build something.
What You’ll Do
Alert Triage & Monitoring
* Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments.
* Investigate alerts to determine scope, severity, and whether escalation is warranted.
* Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.
* Classify, document, and track alerts through the full lifecycle using ticketing and case management systems.
Incident Response & Investigation
* Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.
* Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data-spanning both corporate and product infrastructure.
* Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows.
* Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.
* Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences.
Detection Engineering & Threat Intelligence
* Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps.
* Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors.
* Help maintain and evolve detection coverage mapped to MITRE ATT&CK.
* Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts.
AI Integration & Automation
* Use AI-driven tools for alert triage, enrichment, and investigation as a standard part of daily operations.
* Contribute to the evaluation, integration, and optimization of AI and automation capabilities across the team’s workflows.
* Assist in designing prompts, agent workflows, or LLM-based pipelines that augment analyst capabilities and reduce manual effort.
* Partner with engineering teams to improve log ingestion, data quality, and tool integrations.
Operational Excellence
* Maintain daily operational notes and shift handoff documentation.
* Contribute to and refine IR runbooks, playbooks, and standard operating procedures.
* Participate in on-call rotation for after-hours incident escalation.
* Track and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify improvement opportunities.
* Participate in tabletop exercises, purple team activities, and post-incident reviews.
What You’ll Bring
* 4+ years of experience in a SOC, security operations, or incident response role.
* Understanding of common attack frameworks (MITRE ATT&CK), network protocols, and endpoint behavior.
* Experience with at least one SIEM platform and familiarity with writing search or detection queries.
* Familiarity with EDR platforms and cloud environments (IaaS preferred).
* Comfort using AI systems (e.g., LLM-based assistants, copilots, or AI-driven analysis tools) as part of security workflows.
* Strong written communication skills; able to document findings clearly and concisely for both technical and non-technical audiences.
Nice To Have
* Experience leading or co-leading complex incident response engagements from triage through remediation.
* Experience with identity and access management platforms and cloud security posture management tools.
* Scripting and automation skills (Python, PowerShell, or equivalent) applied to security workflows.
* Familiarity with SOAR platforms or orchestration tools for automated response and enrichment.
* Experience designing or implementing AI agent architectures, LLM-based automation pipelines, or prompt engineering for security use cases.
* Experience building or contributing to threat intelligence programs or detection-as-code pipelines.
* Understanding of the privileged access management landscape and the threat actors that target it.
* Track record of evaluating and adopting emerging technologies in a production security environment.
What We Offer
* Competitive salary and pension with up to a 10% annual bonus
* 25 days’ holiday which increases with length of service
* Competitive pension scheme
* Three weeks' additional leave at seven years' service
* Fully remote in the UK with up to 4 weeks per year under our Working Abroad policy (subject to approval)
* Bupa Private Healthcare for you and family
* Medicash Benefit (including opticians and dental cover)
* Life insurance at 4x salary and income protection
* Paid parental leave and enhanced maternity leave
* Employee Assistance Programme
* Opportunity to co-invest and become a BeyondTrust shareholder
* Investment in AI skills, with Claude Code and Copilot centres of excellence
* Pluralsight and LinkedIn Learning licenses
Better Together
Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
About Us
BeyondTrust is the global identity security leader protecting Paths to Privilege™…
职位正文保留公司发布时的原文,因为投递的时候用的也是同一种语言。
关于这个职位的常见问题
我可以在自己居住的地方申请「Cyber Defense Engineer」这个职位吗?
可以。对于这个职位,BeyondTrust 接受来自世界任何国家的候选人,所以你不需要其他国家的工作许可。这条招聘信息通过了自动核查:如果雇主要求工作许可、签证担保,或者必须居住在某个特定国家,它就不会出现在本站。
标明的报酬是多少?
对于这个职位,BeyondTrust 没有公布报酬。多数远程招聘信息不给出具体数字,这件事会在面试时谈定。
怎么申请?
你通过发布在 We Work Remotely 上的原始招聘信息,直接向雇主提交申请。Donator 不代收申请,不收取佣金,也不保存简历。
这是什么类型的职位?
这是「IT 与编程」类别中的一个完全远程职位。混合办公的招聘信息,以及任何需要到办公室的职位,本站都不会发布。
适合这个职位的免费证书
这个领域里分量最重的几张免费证书。每一张都在发证方自己的页面上核实过。
Applied Skills (scenario-based credentials)
exam is free tooMicrosoft · ~1 h
Microsoft's only free verifiable credential: a lab task in 30-45 minutes, with no proctor, no ID check and no card. Retakes are allowed.
It has to be finished in one session; there is no save and resume.
strong brandOCI Foundations Associate
exam is free tooOracle · ~12 h
A rare case where the certification exam itself is free and needs no Pearson VUE: you sit it inside MyLearn. Take the 2026 track, not the 2025 one.
Oracle's pages load via JS; confirm the $0 on the final step of registration.
strong brandValid: 18-24 monthsCS50x: Introduction to Computer Science
certificateHarvard CS50 · ~100 h
Harvard's own branded certificate is free once you pass every problem set and the final project. The edX verified certificate is a separate paid product and is not needed.
strong brandCS50P: Programming with Python
certificateHarvard CS50 · ~60 h
Same mechanism as CS50x: at least 70% on every assignment plus a final project. The certificate does not expire.
strong brand
