Full-Time
Cloud-native, multi-tenant cybersecurity workflow automation platform
No salary listed
Denver, CO, USA
Remote
See people who can refer or advise you
Torq operates a cloud-native, multi-tenant hyperautomation platform for cybersecurity. It helps organizations build and deploy complex workflows that automate security operations and responses, emphasizing faster ROI than traditional SOAR tools. The platform connects to every app, system, and environment (cloud, on‑premise, and hybrid) and works with any CLI, platform, or scripting language, going beyond APIs. Key features include case management, collaboration, automated alert prioritization, triage, autonomous operations, and validation with red-teaming. Torq aims to provide visibility and control across all environments and processes, enabling proactive security gap detection and faster response times. Its goal is to simplify and speed up security workflows, delivering measurable improvements in execution speed and security posture for customers in sectors like finance and gaming.
Company Size
201-500
Company Stage
Series D
Total Funding
$330M
Headquarters
Denver, Colorado
Founded
2020
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Life Insurance
Disability Insurance
Stock Options
401(k) Company Match
401(k) Retirement Plan
Professional Development Budget
Hybrid Work Options
Phone/Internet Stipend
Torq named a leading innovator in SACR 2026 AI SOC Market Report. By Rick Bosworth, Sr. Director of Product Marketing July 31, 2026 Get a personalized demo. See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster. Software Analyst Cyber Research (SACR) just published its 2026 AI SOC Market Report, offering an independent assessment of vendors competing in what has rapidly become the most consequential category in enterprise security. Torq features prominently, and the report's framing is worth unpacking because it illuminates what makes the AI SOC category hard to evaluate and why Torq's approach is consequential. Torq's AI SOC: from alert triage through remediation. SACR's most pointed observation about Torq is definitional. The firm writes: "Torq is best understood less as a conventional SOAR vendor with AI features and more as an AI SOC operating layer that can ingest alerts, classify triage outcomes, construct cases, assign work to Socrates, and route remediation through deterministic or agentic workflows depending on the use case." That distinction matters. Much of what gets marketed as AI SOC today amounts to copilot functionality that surfaces recommendations and draft summaries, and stops at basic triage that simply moves the bottleneck down the SOC line by an increment. SACR cuts through that framing: "Torq is trying to own high-volume alert triage and response closure, not simply accelerate analyst review." Owning closure requires a different architecture than assisting analysts. It requires accurate alert classification at scale, a context layer deep enough to support trustworthy, autonomous verdicts, case management that carries investigations forward, and response automation that can act, not just advise. But let's circle back and dwell a bit on the first phase: autonomous alert triage. Auto Triage: context is the differentiator. Torq Auto Triage classifies incoming alerts as false positive, benign, or malicious, enriches them with threat intelligence and business context, and routes them accordingly, all before a human analyst is involved. True positives become cases automatically. False positives are fed back into the per-tenant AI model. SACR called out the quality of Torq's context layer directly: "Torq is not treating alerts as isolated artifacts. It is building a context pipeline around entities, access history, business role, device state, SaaS activity, and related evidence before determining whether an alert should be closed, escalated, or remediated." Three underlying capabilities power that context pipeline. * Torq Reflex is a per-tenant ML model trained continuously on your team's confirmed verdicts. * Torq Recall retrieves the most relevant prior cases from your environment's history and applies an LLM to determine how those precedents apply to the current alert. * Torq Context Graph provides the unified substrate both depend on: a continuously updated map of identities, assets, networks, policies, and analyst decisions, normalized across your entire security stack. The results speak volumes. On average, large enterprises achieve a mean time to triage (MTTT) of 1 minute, a 60x improvement over manual triage. A global biotech titan cites a 97% reduction in noise entering the SOC; imagine how much better their security analysts can focus. A well-known financial services enterprise achieved 99% faster threat triage after deploying Torq. Case Management: the operating unit. When Auto Triage surfaces a true positive, it flows directly into Torq Case Management, where analysts inherit the full verdict, enrichment context, and proposed next steps. They do not reconstruct context from scratch. From within the case interface, analysts collaborate with Torq Socrates(TM), trigger automated response actions, and track investigation continuity across shift handoffs. Each confirmed verdict and analyst correction flows back into Reflex as a training signal, compounding accuracy over time. This is the mechanism behind what SACR identifies as Torq's stronger-than-expected investigation story: the platform captures and encodes analyst judgment, rather than relying on individual expertise to repeat the same reasoning shift after shift. The machine clears the noise. The analysts focus on the highest priority items. Socrates: reasoning and orchestration. Torq Socrates is the agentic reasoning and orchestration layer at the center of the platform. It can be used interactively by analysts, embedded in investigation templates, or assigned cases autonomously. Once on a case, Socrates plans investigations, delegates tasks to specialized Torq HyperAgents(TM), and coordinates response actions across the security stack. SACR characterizes Socrates as "the reasoning and planning layer that decides how much work should be agentic, how much should be deterministic, and where the human should approve or intervene." As SACR notes, "autonomy is a dial, not a binary switch," and Torq's model lets security organizations operationalize that dial gradually: starting with triage and recommendation, moving into human-approved action, and eventually automating higher-confidence alert classes. One Torq customer on PeerSpot describes the cumulative impact: Torq handles a large volume of their alerts autonomously, fundamentally changing the burden placed on their security team. Hyperautomation: execution depth. Torq Hyperautomation is the execution layer that connects AI decisions to real action, supporting both agentic and deterministic workflows across the full security stack. SACR identifies this automation heritage as a structural advantage: "Compared with AI SOC point solutions, Torq's advantage is the ability to connect AI decisioning to actual workflow execution." That advantage compounds. The same platform that classifies an alert, builds the case, and assigns it to Socrates is the platform that executes containment and remediation at machine speed. Customers have measured a 94% reduction in mean time to respond (MTTR), a metric that requires the full chain, not just faster triage at the front end. What SACR's assessment means for buyers. SACR closes its Torq vendor profile with a synthesis that applies beyond Torq specifically: "Autonomous SOC value will be measured by closed-loop operating capability rather than AI summarization." Verdict quality matters. But a verdict quality that does not connect to case construction, investigation, response, and organizational learning is an incomplete story. Torq's architecture is designed around that full loop.
Torq unveils SOC Brain, a self-learning layer for its AI SOC platform. Security hyperautomation platform company Torq Ltd. today introduced Torq SOC Brain, a new layer of its artificial intelligence security operations center platform that trains on a customer's own investigation history and analyst decisions instead of treating every alert as a fresh problem. Torq said most autonomous investigation tools retrieve similar past cases and pass them to a large language model at the point of decision. Its argument is that retrieval is not learning. SOC Brain is built to reason from precedent, absorb the way a given security operations center weighs evidence and revise its judgment after every closed investigation. Three capabilities sit underneath it. Torq Recall pulls up relevant historical cases using deterministic matching on observables such as IP addresses, file hashes, URLs and hostnames, then ranks them by relevance and works out how earlier analyst decisions should bear on the verdict at hand. It reads analyst notes, identifies conflicting precedent and adjusts confidence according to how strong the evidence is. Analysts do not have to tag cases or write rules for any of it to work. Torq Reflex trains dedicated models on a team's confirmed verdicts and its corrections. Reflex matches analyst-corrected verdicts 85% of the time immediately. Alerts it is confident about are automated. The rest are escalated to a human. Torq Retrospect deals with the cold start. It imports resolved incidents from a customer's existing security tools before deployment so Recall and Reflex have organizational history to draw on from the first alert rather than months later. Every customer gets a private SOC Brain. Torq does not pool customer data, share model parameters or train one customer's models on another's incidents, and the company said that isolation is a property of the architecture rather than a setting an administrator switches on. Torq said decisions are explainable and auditable, with automation gated by confidence thresholds and human oversight. Torq positions that as an answer to the governance and transparency demands security leaders are under, including emerging requirements such as the European Union's AI Act. "Every cybersecurity vendor claims their AI is self-learning, but virtually none are," said Ofer Smadari, co-founder and chief executive of Torq. "What the majority do is simply pass cases and hand them to an LLM at the point of decision. That's nothing more than executing based on memory. Self-learning means reaching new conclusions from that history, and that's much harder to build." Smadari added that the payoff for analysts is fewer repetitive reviews and more consistent decisions, with growing confidence that the platform "is making decisions the same way their security team would." The release caps an active year for the company. Torq acquired application security startup Jit.io Ltd. in May to add context graphs to the platform, and in January it raised $140 million at a $1.2 billion valuation in a Series D round led by Merlin Ventures Ltd. that valued it at $1.2 billion. Torq will demo SOC Brain at its booth at Black Hat USA in Las Vegas Aug. 3-6. Image: Torq. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from its Marketplace portal page and links. About SiliconANGLE Media SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
Torq & Criminal IP launch actionable threat intelligence for autonomous SOC operations. Post Views: 6 Torq and Criminal IP have formed a strategic alliance to enhance threat intelligence capabilities for security operations centers (SOCs) by integrating Criminal IP's threat intelligence platform with Torq's AI-powered SOC solution. Collaboration between Torq and Criminal IP. A strategic alliance between Torq and Criminal IP has been established to advance threat intelligence capabilities for security operations centers (SOCs). This partnership integrates Criminal IP's threat intelligence platform with Torq's AI-powered SOC solution, enabling organizations to automate threat assessment and response processes. The collaboration aims to address the growing challenge of managing high volumes of security alerts by providing real-time, actionable insights without disrupting existing workflows. "Criminal IP's platform is designed to transform raw threat data into actionable intelligence at scale," stated Byungtak Kang, CEO of Criminal IP. "By combining our capabilities with Torq's AI SOC, we enable automated decision-making that reduces response times and minimizes manual intervention." "Criminal IP represents a forward-thinking approach to threat intelligence, aligning with our vision for AI-driven security operations. This integration strengthens our ability to deliver rapid, context-rich responses to evolving threats." - Eldad Livni, CINO and co-founder of Torq Integration and operational workflow. The solution operates by routing incoming indicators to Criminal IP's intelligence services, which provide detailed assessments. These findings are then analyzed by the Torq AI SOC Platform to determine the severity of the threat and the appropriate mitigation strategy. The integration allows the Torq AI SOC Platform to automatically analyze indicators of compromise, such as IP addresses, domains, and internet-facing assets, by leveraging Criminal IP's extensive threat intelligence database. This process generates immediate verdicts on the risk level of each indicator, including whether it is malicious, suspicious, or anonymized. Key features of the integration. * Real-time IP and domain risk evaluation * Detection of malicious or phishing domains * Assessment of exposed assets and associated vulnerabilities * Identification of privacy threats, such as VPN usage or hosting infrastructure * Comprehensive reports on internet-facing assets and service banners Use cases for the integrated system. Use cases for the integrated system include automated enrichment of threat indicators before analyst review, immediate containment of confirmed threats, and pre-populated case files with contextual data for investigation. The partnership is available for deployment on the Torq AI SOC Platform, offering enterprises a unified approach to threat management. Conclusion. Criminal IP, developed by AI SPERA, specializes in aggregating and contextualizing threat data from global internet scans. Its services cover malicious indicators, vulnerabilities, and attacker behaviors, aiming to improve organizational visibility and response efficiency. Torq's AI SOC Platform focuses on accelerating threat triage, investigation, and remediation through artificial intelligence. The collaboration underscores the growing reliance on AI and automation to address the complexity of modern cybersecurity challenges. By combining real-time threat intelligence with intelligent response mechanisms, the partnership seeks to enhance resilience against an expanding threat landscape.
Britive joins Torq AMP Alliance program to accelerate agentic SecOps. Jun 25, 2026, 12:00 ET Torq AMP Drives Agentic AI Innovation Through Deep Integration and Innovation Capabilities, GTM Collaboration, and Disruptive Joint Marketing for Britive's Runtime Privileged Access Management LOS ANGELES, June 25, 2026 /PRNewswire/ - Britive, the cloud-native platform redefining privileged access management (PAM) to secure human, agentic AI, and non-human identities at runtime, today announced it has joined the expanding Torq AMP alliance program, designed to drive agentic AI innovation. Building on a multi-year technology partnership, Britive was selected for its leading just-in-time, runtime privileged access platform that governs human identities, machine identities, and agentic AI workloads, and seamlessly integrates with the Torq AI SOC Platform to empower customers and their SOC/Incident Response teams. The expanded relationship formalizes what joint customers have relied on in production, with automated privilege enforcement tied directly to SOC investigation and response workflows. Torq AMP is unlike any other partner program in the history of cybersecurity. It exists in stark contrast to partner programs stuck in the distant past, built on elitist tiering systems, pay-to-play participation, and excessive bureaucracy. With Torq AMP, partners such as Britive can easily leverage Torq's AI SOC platform and agentic AI capabilities to create unique, high-value solutions that integrate across mutual customers' security stacks and ISV ecosystems. Torq AMP delivers builder-focused, not engineering-focused, integrations that elevate the value of partner offerings and go far beyond the static, pre-defined integrations of typical tech alliances. It's all about driving mutual growth, adoption, and buzz for all participants. Torq AMP provides these exclusive benefits to Britive: * Integrated Solution Creation: Build innovative, joint AI-driven SecOps solutions quickly and easily at scale, without heavy engineering efforts * Deep Torq Sales Engagement: Joint field marketing events, collaborative prospecting, and integrated presence in Torq demo environments * Strategic GTM Collaboration: Collaborative sales enablement, team training, channel packaging, ROI analysis, and reporting * Disruptive Marketing Activation: Integration highlighted within the Torq platform, on Torq's website, in customer and prospect emails, and across social posts, messaging, and custom swag "Britive and Torq have been delivering value together for our joint customers for years, and joining the AMP Alliance is the natural next step as Torq establishes itself as the AI SOC platform of record," said Art Poghosyan, CEO, Britive. "The threat landscape has expanded well beyond human user credentials. Machine identities and agentic AI workloads now represent the fastest-growing and least-governed privilege surface in the enterprise. The joint solution we bring to market with Torq addresses all three planes together. Now our customers get automated, runtime enforcement at the moment of need, regardless of what type of identity is making the access request." "We have seen firsthand how identity-related risk plays out in SOC investigations. Privilege abuse through human accounts, unmanaged machine identities, and now ungoverned agentic AI permissions are consistently the path of least resistance for attackers," said Nauman Mustafa, CSO and VP of Platform and Ecosystem Strategy, Britive. "This renewed partnership with Torq takes the integration we have refined in the field and brings it fully into the agentic AI era. Torq's AI SOC drives investigation and response at machine speed across all three identity planes. Britive ensures that every access decision, whether it originates from a human operator, a machine workload, or an AI agent, is governed, time-bound, and auditable. That combination closes a gap that no other joint solution in the market addresses today." "Torq AMP partners include some of the most prestigious and cutting-edge cybersecurity companies in the world, and we are excited to welcome Britive to the fold," said Eldad Livni, CINO and Co-Founder, Torq. "Britive is an example of an innovative vendor that delivers solutions with maximum impact as we realize the potential of the AI SOC, together. And that means joint offerings that combine cutting-edge threat intelligence drawing from the deepest data pools with blazing fast AI-driven response, remediation, and mitigation. Together, Torq and Britive will protect organizations from the ever-expanding spectrum of threats they're confronted with every second of every day." About Britive Britive is the cloud-native runtime privileged access management platform built for the speed and scale of modern multi-cloud environments. Britive enables enterprises to eliminate standing privilege across cloud infrastructure, SaaS applications, machine identities, and agentic AI workloads through just-in-time access, runtime privilege controls, and continuous governance. Trusted by leading organizations across financial services, healthcare, and technology, Britive reduces identity-based risk across human, machine, and agentic identity planes without slowing down development or operations. Learn more at britive.com. About Torq Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution. The platform analyzes your risk context to identify your biggest threats. Global leaders like PepsiCo, Procter & Gamble, Siemens, Telefónica, and Virgin Atlantic trust Torq to power the next generation of Agentic SOC operations. SOURCE Britive
ANY.RUN announces integration with Torq to scale SOC triage and response with agentic AI. DUBAI, DUBAI, UNITED ARAB EMIRATES, June 25, 2026 /EINPresswire.com/ - ANY.RUN has announced a new integration with Torq, the the established agentic security operations leader, enabling security teams to bridge the gap in alert context and distinguish actual threats from false positives with greater confidence. The integration combines ANY.RUN's conclusive malware and phishing verdicts, actionable intelligence, and real-time enrichment with the Torq AI SOC Platform, resulting in faster incident resolution and reduced alert fatigue for Security Operations Centers (SOC) and Managed Security Service Providers (MSSPs). Behavior-Driven Analysis and IOC Intelligence in Torq ANY.RUN users now have access to five ready-to-use Torq HyperAgents(TM) designed to accelerate time-to-verdict. These custom AI agents leverage ANY.RUN's Interactive Sandbox and Threat Intelligence (TI) Lookup to supply verified behavior and fresh IOC context. Results, including reputation data, threat names, tags, and structured JSON responses, are delivered directly into Torq Case Management. This ensures that analysts have immediate, high-fidelity context without ever needing to leave their primary workspace. Operational Outcomes Security Leaders Can Expect The integration introduces several measurable improvements that strengthen triage and support more efficient response operations: - Lower MTTR: Automated enrichment and analysis provide clear verdicts in seconds, with an average reduction in MTTR of 21 minutes. - Operational Scaling: Teams can handle a growing volume of alerts with Torq HyperAgents(TM) handling routine Tier 1 tasks, allowing analysts to focus on complex threats without increasing headcount. - Standardized Investigation Logic: Every alert is checked against the same high-fidelity criteria, ensuring consistent results and reducing human error regardless of an analyst's experience level. The integration is straightforward to enable: users simply locate ANY.RUN within the Torq Integrations menu, enter their API key, and begin leveraging Torq to deploy custom Torq HyperAgents that streamline investigation and response. Advancing Innovation via the Torq AMP Alliance Program In addition to the technical integration, ANY.RUN has officially joined the Torq AMP (Alliance Program), a builder-focused initiative designed to drive agentic AI innovation. "Torq AMP partners include some of the most prestigious and cutting-edge cybersecurity companies in the world, and we are excited to welcome ANY.RUN to the fold," said Eldad Livni, CINO and Co-Founder, Torq. "ANY.RUN is an example of an innovative vendor that delivers solutions with maximum impact as we realize the potential of the AI SOC together". About ANY.RUN Trusted by over 600,000 cybersecurity professionals and 15,000+ organizations worldwide, ANY.RUN helps security teams investigate threats faster and with greater accuracy. The solution combines an Interactive Sandbox for real-time analysis of suspicious files across multiple operating systems with Threat Intelligence solutions that provide the context necessary to anticipate and stop advanced attacks. About Torq Torq is transforming cybersecurity with the Torq AI SOC Platform. Torq empowers enterprises to instantly and precisely triage, investigate, and respond to security events at scale. Torq's customer base includes major multinational enterprise customers, including Abnormal Security, Armis, Check Point Security, Chipotle Mexican Grill, Inditex (Zara, Bershka, and Pull & Bear), Informatica, Kyocera,, Procter & Gamble, Siemens, Telefónica, Valvoline, Virgin Atlantic, and Wiz. Legal Disclaimer: EIN Presswire provides this news content "as is" without warranty of any kind. Abu Dhabi Reporter do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.