Full-Time

SOC Analyst

Cyber Defense Operations

Posted on 8/19/2026

BeyondTrust

BeyondTrust

1,001-5,000 employees

PAM, vulnerability, and endpoint security solutions

No salary listed

Remote in Australia

Remote

Category
IT & Security (1)
Required Skills
LLM
PowerShell
Python
Incident Response

Get referred to BeyondTrust

See people who can refer or advise you

Requirements
  • At least 2 years of experience in a security operations center, security operations, or incident response role.
  • Understanding of common attack frameworks, including MITRE ATT&CK, network protocols, and endpoint behavior.
  • Experience with at least one security information and event management platform and familiarity with writing search or detection queries.
  • Familiarity with endpoint detection and response platforms and cloud environments, preferably infrastructure as a service.
  • Comfort using artificial intelligence systems, such as large language model assistants, copilots, or AI-driven analysis tools, in security workflows.
  • Ability to document findings clearly and concisely for technical and non-technical audiences.
Responsibilities
  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering corporate and product environments.
  • Investigate alerts to determine scope, severity, and whether escalation is warranted.
  • Use AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.
  • Classify, document, and track alerts through their full lifecycle using ticketing and case management systems.
  • Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.
  • Conduct investigations across SIEM, EDR, CSPM, identity provider logs, cloud audit trails, and network flow data spanning corporate and product infrastructure.
  • Execute established incident response runbooks across identity, endpoint, cloud, and email investigation workflows.
  • Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.
  • Produce incident summaries and post-incident reports for technical and leadership audiences.
  • Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms.
  • Translate threat intelligence into actionable detection content, including intelligence from CVE advisories, CISA alerts, vendor bulletins, and open-source feeds.
  • Maintain and evolve detection coverage mapped to MITRE ATT&CK.
  • Partner with threat-hunting peers to validate detection logic through hypothesis-driven hunts.
  • Use AI-driven tools for alert triage, enrichment, and investigation.
  • Contribute to the evaluation, integration, and optimization of AI and automation capabilities across team workflows.
  • Assist in designing prompts, agent workflows, or large-language-model-based pipelines that augment analyst capabilities.
  • Partner with engineering teams to improve log ingestion, data quality, and tool integrations.
  • Maintain daily operational notes and shift handoff documentation.
  • Contribute to and refine incident response runbooks, playbooks, and standard operating procedures.
  • Participate in an on-call rotation for after-hours incident escalation.
  • Track and report operational metrics, including mean time to detect, mean time to respond, mean time to contain, and false positive rate, and identify improvement opportunities.
  • Participate in tabletop exercises, purple team activities, and post-incident reviews.
Desired Qualifications
  • Experience leading or co-leading complex incident response engagements from triage through remediation.
  • Experience with identity and access management platforms and cloud security posture management tools.
  • Scripting and automation skills using Python, PowerShell, or equivalent, applied to security workflows.
  • Familiarity with security orchestration, automation, and response platforms or orchestration tools for automated response and enrichment.
  • Experience designing or implementing AI agent architectures, large-language-model-based automation pipelines, or prompt engineering for security use cases.
  • Experience building or contributing to threat intelligence programs or detection-as-code pipelines.
  • Understanding of the privileged access management landscape and the threat actors that target it.
  • Track record of evaluating and adopting emerging technologies in a production security environment.

BeyondTrust provides cybersecurity software for organizations. Its products include Privileged Access Management (PAM), which controls and monitors access to critical systems; Vulnerability Management, which finds and helps remediate security weaknesses; and Endpoint Protection, which secures devices from threats. The offerings are delivered as software and managed services, and the company works with large enterprises, government agencies, and partners to provide an integrated security platform. Its goal is to reduce cyber risk by preventing unauthorized access, detecting and fixing weaknesses, and protecting endpoints for safer IT operations.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$12.1M

Headquarters

Johns Creek, Georgia

Founded

1985

Get referred to BeyondTrust

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 3, 2026 Black Hat launches broaden Pathfinder into AI agent security.
  • July 22, 2026 NHI Governance targets exploding non-human identity sprawl with Fall 2026 GA.
  • BeyondTrust says internal AI-driven testing found August 2026 EPM flaws before attackers did.

What critics are saying

  • July 2026 Remote Support and PRA auth bypasses exposed core remote-access trust.
  • August 17, 2026 EPM flaws and repeated advisories erode confidence in product quality.
  • A major exploit or trust collapse could drive regulated customers toward Microsoft, CyberArk, or Delinea.

What makes BeyondTrust unique

  • BeyondTrust owns privilege-centric identity security, stretching PAM into AI agents and workloads.
  • Pathfinder unifies visibility, governance, and enforcement across human and non-human identities.
  • The company claims 20,000 customers, including 75 Fortune 100 firms, signaling enterprise trust.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

17%

1 year growth

17%

2 year growth

21%
GBHackers
Aug 19th, 2026
BeyondTrust Endpoint Privilege Management flaws enable local privilege escalation.

BeyondTrust Endpoint Privilege Management flaws enable local privilege escalation. August 19, 2026 BeyondTrust has revealed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) Windows Deployment product, which could lead to local privilege escalation and bypasses of anti-tamper protections on affected devices. Discover more Cybersecurity training platform Cyberattack prevention software Data recovery services These vulnerabilities are tracked as CVE-2026-40144 and CVE-2026-40145 and affect all versions of Endpoint Privilege Management for Windows before version 26.1.2. The company has released fixes in version 26.1.2 and is urging customers to upgrade their affected endpoints as soon as possible. BeyondTrust Endpoint Privilege Management flaws. The vulnerabilities are detailed in BeyondTrust advisory BT26-04, which was issued and updated on August 17, 2026. BeyondTrust identified both issues internally during security assessments utilizing advanced AI models alongside proprietary testing harnesses. Cloud security services The company has stated that there is no evidence suggesting that either vulnerability was exploited before being addressed. The more severe vulnerability, CVE-2026-40144, has a CVSS v4 score of 7.3 and is classified as a high-severity out-of-bounds read flaw, mapped to CWE-125. This issue exists in a kernel-mode component of the BeyondTrust Endpoint Privilege Management for Windows. According to the advisory, the component fails to validate input sufficiently, which could allow the software to access memory outside its designated bounds. Discover more Computer Security Security Products & Services A local attacker with standard, non-administrative privileges could potentially exploit this flaw to corrupt kernel memory and elevate their privileges. Successful exploitation could lead to arbitrary code execution in kernel mode, thereby giving the attacker control over one of the most privileged levels of the Windows operating system. The CVSS vector for CVE-2026-40144 is: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Although exploitation requires local access and low-level privileges on the endpoint, successful exploitation could compromise the confidentiality, integrity, and availability of the affected Windows device. The second vulnerability, CVE-2026-40145, has a CVSS v4 score of 7.1 and is categorized under CWE-1220, which refers to insufficient granularity of access control. Vulnerability scanning tool This vulnerability affects the interaction between an EPM Windows support utility and the product's anti-tamper controls. Under certain circumstances, protections designed to limit the support utility process may not function as intended. An attacker who has already gained elevated privileges could manipulate the support utility process and execute code outside the intended boundaries of the EPM anti-tamper protections. Discover more Ethical hacking course Malware removal tool Crime & Justice This vulnerability does not serve as an initial access or direct low-privilege escalation vector; it requires local access, an elevated process context, and additional endpoint-specific conditions. Its CVSS vector is: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Organizations using BeyondTrust Endpoint Privilege Management Windows Deployment should identify any endpoints running versions earlier than 26.1.2 and prioritize upgrading them. The fixes for these vulnerabilities are included in version 26.1.2 and later. Because EPM products are designed to enforce privilege controls and restrict unauthorized administrative activity, kernel-level weaknesses or anti-tamper bypasses can pose significant risks in enterprise environments. Security teams should validate the versions of deployed agents, review local administrator access, and monitor for abnormal interactions with EPM support utilities during remediation. Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world. Hot this week

GlobeNewswire
Aug 11th, 2026
BeyondTrust recognized on the 2026 Inc. 5000 list of America's fastest growing private companies.

BeyondTrust recognized on the 2026 Inc. 5000 list of America's fastest growing private companies. * Independent privilege-centric identity security leader recognized for sustained growth amid a consolidating cybersecurity market * Growth supported by sustained investment in identity security innovation throughout the 2022-2025 measurement period, alongside continued recognition from leading industry analysts "The ecosystem is changing fast. Organizations need a platform that treats privilege, not just identity, as the real point of control." ATLANTA, Aug. 11, 2026 (GLOBE NEWSWIRE) - BeyondTrust, the global leader in privilege-centric identity security protecting Paths to Privilege(TM), today announced it has been named on the prestigious 2026 Inc. 5000 list, which recognizes the fastest-growing private companies in America. "Being named to the Inc. 5000 for another year reflects the trust our customers place in us to secure their most critical identity security challenges, as well as the commitment of our employees and partners who make it possible to support our customers and sustain growth" said Janine Seebeck, CEO of BeyondTrust. "Identity has always been the front line of cybersecurity, but the ecosystem is changing fast, with non-human identities and AI agents multiplying inside organizations faster than security teams can track them. Organizations need a platform that treats privilege, not just identity, as the real point of control, and that's the problem we've built our platform to solve." BeyondTrust protects over 20,000 customers worldwide, including more than 75 of the Fortune 100, with a privilege-centric platform that reduces risk, simplifies compliance, and scales with the demands of a rapidly evolving identity landscape. That leadership continues to be validated across the industry's leading analyst reports and award programs, including: This year's Inc. 5000 recognizes a new class of companies redefining what growth looks like. From AI and advanced manufacturing to healthcare, consumer products, and professional services, these businesses are expanding their impact, creating jobs and proving that entrepreneurial ambition continues to fuel the U.S. economy. Among the 5,000 companies on the list, the median three-year revenue growth rate was 130%, and those companies have collectively added more than 627,208 jobs to the U.S. economy over the past three years. Platform Innovation Supporting Sustained Growth Throughout the 2022-2025 Inc. 5000 evaluation period, BeyondTrust continued to invest in expanding its identity security portfolio and addressing the evolving ways organizations manage and protect privileged access. Significant milestones included: * The launch of Identity Security Insights(R)(2023), expanding BeyondTrust's capabilities to provide visibility into identity threats and the Paths to Privilege(TM) attackers can exploit. * The acquisition of Entitle (2024), extending BeyondTrust's identity security platform with just-in-time access management and cloud permissions management capabilities. * The release of the True Privilege(TM) Graph (2025), advancing BeyondTrust's ability to reveal the true privilege of identities and uncover hidden attack paths across complex identity environments. Building on that trajectory, BeyondTrust has continued to accelerate investment in innovation since the close of the Inc. 5000 evaluation period, responding to the rapidly evolving identity security landscape and the emergence of AI agents, non-human identities, and workloads as critical new areas of privilege risk. Recent investments include PathfinderAI & MCP Server, AI Agent Security, NHI Governance, the expanded Identity Security Risk Assessment, and the preview of Workload Credentials, extending BeyondTrust's innovation across human, non-human, workload, and AI identities. "Every company on the Inc. 5000 has a story of perseverance, smart decision making, and a refusal to sit still," says Mike Hofman, editor-in-chief of Inc. "Their growth reflects more than strong financial performance-it reflects creativity, resilience, and the customer focus required to build companies that make a lasting impact. We congratulate all honorees on this significant achievement." * Organizations looking to uncover hidden identity and privilege risk can request a free Identity Security Risk Assessment at: https://www.beyondtrust.com/products/identity-security-insights/assessment * To learn more about BeyondTrust's latest innovations and request early access to capabilities like PathfinderAI, AI Agent Security, and NHI Governance, visit: https://www.beyondtrust.com/pathfinder * For the full Inc. 5000 list, honoree company profiles, and a searchable database by industry and location, visit: www.inc.com/inc5000 About BeyondTrust BeyondTrust is the global leader in privilege-centric identity security protecting Paths to Privilege(TM). Identity alone doesn't create risk. Privilege does. As human, non-human, and AI agent identities explode across every environment, BeyondTrust is the only company built to discover, control, and secure privilege across all of them from a single platform. Trusted by 20,000+ customers, including 75 of the Fortune 100, and recognized as a multi-category leader by top industry analysts, BeyondTrust reframes identity security from a management problem into a strategic advantage. About Inc. 5000 Companies on the 2026 Inc. 5000 are ranked according to percentage revenue growth from 2022 to 2025. To qualify, companies must have been founded and generating revenue by March 31, 2022. They must be U.S.-based, privately held, for-profit, and independent - not subsidiaries or divisions of other companies - as of December 31, 2025. (Since then, some on the list may have gone public or been acquired.) The minimum revenue required for 2022 is $100,000; the minimum for 2025 is $2 million. As always, Inc. reserves the right to decline applicants for subjective reasons. About Inc. Inc. is the leading media brand and playbook for the entrepreneurs and business leaders shaping its future. Through its journalism, Inc. aims to inform, educate, and elevate the profile of its community: the risk-takers, the innovators, and the ultra-driven go-getters who are creating the future of business. Inc. is published by Mansueto Ventures LLC, along with fellow leading business publication Fast Company. For more information, visit www.inc.com. For BeyondTrust: BeyondTrust Public Relations P: (516)-521-5582

iTWire
Aug 5th, 2026
BeyondTrust showcases the first wave of native Pathfinder capabilities for every identity at Black Hat USA 2026.

BeyondTrust showcases the first wave of native Pathfinder capabilities for every identity at Black Hat USA 2026. * Marks a major milestone in the evolution of the BeyondTrust Pathfinder platform as it advances BeyondTrust's vision for redefining privilege management * Further extends BeyondTrust's privilege-centric approach to secure every human, machine, workload, and AI identity that can hold or exercise privileged access * Combines visibility, intelligence, and protection to reduce the standing privilege attackers depend on * Brings together four native Pathfinder capabilities: PathfinderAI & MCP Server, AI Agent Security, NHI Governance, and the newly announced Workload Credentials capability BeyondTrust, the global leader in privilege-centric identity security protecting Paths to Privilege(TM), today announced its Black Hat USA 2026 showcase of the first wave of native capabilities built on the BeyondTrust Pathfinder platform, extending the identity visibility and intelligence already delivered through Identity Security Insights(R), while adding new context and telemetry that make those insights even more powerful. Together, these capabilities further extend privilege management beyond traditional human administrators to every identity that can hold or exercise privileged access, advancing BeyondTrust's vision for redefining privilege management. PathfinderAI & MCP Server, AI Agent Security, NHI Governance, and Workload Credentials are the first native Pathfinder capabilities designed to help organisations discover, prioritise, govern, and protect privileged access wherever it exists. Together, these capabilities bring human and non-human identities, including AI agents and workloads, onto a single platform that combines identity visibility, intelligence, and protection to help organisations uncover, understand, and reduce the standing privilege attackers depend on. "We are not a privileged access company adding AI," said Marc Maiffret, Chief Technology Officer, BeyondTrust. "We are the company that has long defined how to secure privileged action. For twenty years, that meant people with administrative rights, and we built the category for securing them. Today, that actor is just as likely to be an AI agent or autonomous workload. The actor has changed. Our job has not." The Problem: Privilege Now Lives Everywhere Recent research from BeyondTrust Phantom Labs(R) found enterprise AI agents grew more than 460% year over year, while security researchers continue to document the rapid expansion of machine and non-human identities across enterprise environments. These identities often have no clearly assigned owner. Their access evolves faster than organisations can review it, and credentials intended to be temporary often persist indefinitely. Attackers have taken notice. They're increasingly abusing trusted identity relationships, from OAuth integrations to workload credentials, to move laterally and access sensitive data without triggering traditional security controls. Excessive privilege has become one of the easiest paths into modern environments. The Response: The Next Evolution of the Pathfinder Platform The following native capabilities expand the Pathfinder platform with new ways to discover, prioritize, govern, and protect privileged access across every identity. * PathfinderAI & MCP Server: PathfinderAI lets security analysts investigate identity risk using natural-language queries across identity relationships, privileges, and hidden Paths to Privilege(TM), natively inside the Pathfinder platform. A new Pathfinder MCP Server extends that intelligence outward, letting AI agents, such as Microsoft Copilot, OpenAI, and Claude, securely connect to BeyondTrust's privilege-centric identity intelligence through the open Model Context Protocol. * AI Agent Security: AI Agent Security enforces what AI coworkers and autonomous agents, including Claude Code, Microsoft Copilot, Cursor, and OpenAI Codex, are allowed to do on the endpoint, in real time, before they act. It helps organisations discover, inventory, and govern AI agents on endpoints across the enterprise, providing visibility into AI identities, shadow AI, associated privileges, and paths to privilege separate from the human identities. The solution enables security teams to understand where AI agents exist, what they can access, and how to reduce unnecessary privilege before it becomes exploitable. * NHI Governance: NHI Governance extends privileged access management to the service accounts, API keys, OAuth clients, workload identities, and AI agents that now outnumber employees in nearly every organisation - and remain largely ungoverned. It moves organisations beyond simply discovering non-human identities to actively governing the privilege they hold. Organisations can establish ownership, review privileged access, automate lifecycle management, and apply governance controls to identities that have traditionally operated outside standard identity governance processes. * Workload Credentials: Workload Credentials is a new cloud-native secrets management capability on the Pathfinder platform, purpose-built to secure the non-human identities behind CI/CD pipelines, Kubernetes services, containers, and AI agents. Rather than vaulting and rotating static secrets, Workload Credentials replaces them with short-lived, auto-expiring credentials that are generated on demand and discarded after use, so there is nothing left to leak. A workload authenticates with an OIDC identity token, a policy engine evaluates the request, a scoped credential is issued, and it expires automatically - no manual rotation required. Availability & Early Access PathfinderAI, the Pathfinder MCP Server, AI Agent Security, and NHI Governance are available now through the BeyondTrust Early Access program. Workload Credentials early access opens soon. Organisations can request access at the links below, contact their BeyondTrust account teams, or stop by booth #4720 at BlackHat to learn more.

Yahoo Finance
Aug 3rd, 2026
BeyondTrust unveils native Pathfinder capabilities for AI agent, workload, and non-human identity security

BeyondTrust has unveiled the first native capabilities of its Pathfinder platform at Black Hat USA 2026. The platform extends privilege management beyond traditional human administrators to all identities capable of exercising privileged access, including AI agents and workloads. The initial wave includes PathfinderAI & MCP Server, AI Agent Security, NHI Governance, and Workload Credentials. These tools help organisations discover, prioritise, govern, and protect privileged access across human and non-human identities. Research from BeyondTrust Phantom Labs found enterprise AI agents grew more than 460% year over year. The company noted that attackers increasingly abuse trusted identity relationships to move laterally and access sensitive data. "We are the company that has long defined how to secure privileged action," said Marc Maiffret, chief technology officer at BeyondTrust.

Channel Post MEA
Jul 22nd, 2026
BeyondTrust Introduces NHI Governance for AI and Non-Human Identities.

BeyondTrust Introduces NHI Governance for AI and Non-Human Identities. On: July 22, 2026 BeyondTrust has announced NHI Governance, a new solution on the BeyondTrust Pathfinder platform that governs non-human identities operating across cloud, SaaS, endpoints, and on-premises environments. As service accounts, API keys, OAuth clients, workload identities, and AI agents continue to proliferate across enterprise environments, NHI Governance extends the privileged access discipline BeyondTrust has applied to human access for more than two decades to the identities that now outnumber employees in nearly every organization and remain largely ungoverned. The Problem: The Privileged Surface Changed. Controls Didn't Keep Up. Service accounts, API keys, OAuth clients, workload identities, and AI agents now hold most of the standing privilege in the enterprise, and they outnumber the people. BeyondTrust Phantom Labs research found that non-human identities already vastly outnumber human ones, with enterprise AI agents growing more than 460% year over year. Almost none are ever assigned an owner; their privileges are rarely reviewed, attested, or rightsized; and their credentials are seldom rotated or retired. They are granted access on the day they are created and often retain that access indefinitely. The industry's response has been to inventory them. But a longer list is not a control. The risk was never just that an identity exists; it is also, and especially, the privilege that identity holds and everything that privilege can reach. The recent wave of SaaS-to-SaaS software supply chain attacks made that abundantly clear. Attackers increasingly compromise the OAuth tokens trusted between applications, allowing legitimate access to data at scale. No malware, no escalation, no human in the loop. Every action reads as authorized because it was. Discovery and visibility alone do not stop an attack. Stopping the exfiltration requires controls to be executed ahead of the incident: access already scoped down, the token already rotated, or the unused identity already retired before the attacker arrived. "Seeing non-human identities was only half the equation," said Marc Maiffret, Chief Technology Officer, BeyondTrust. "The other half is doing something about the privilege they carry at scale: deciding who owns each one, pulling back the privilege they aren't using, and retiring the ones that should not exist. And doing so without requiring teams to address them one by one with the limited time they have. That's not paperwork you bolt onto a tool built for employee onboarding. That's managing non-human identities at machine scale." Helping Customers Move from an Inventory List to Real Control NHI Governance is built to execute the non-human equivalent of joiner, mover, leaver actions that actually reduce risk, in the right order: * Establish ownership. Every non-human identity is assigned to a person or a team who is accountable for it, so nothing runs unowned. * Enforce least privilege. Lock down the identities that hold real privilege, and constrain what each one can reach, closing the paths to privilege it was never meant to have. * Decommission NHIs. Retire the stale, orphaned, and abandoned identities that make up most of the ungoverned population, so the attack surface shrinks instead of growing unchecked. * Secure AI Agents. Bring them under the same controls, with their own credentials and their own access. Built on Two Decades of Privilege Enforcement For more than two decades, BeyondTrust has helped organizations reduce identity-based risk by governing privileged access across their most critical systems. Non-human identities are no exception. Identity Security Insights already provides industry-leading visibility and intelligence across non-human identities and the privileges they hold, while BeyondTrust Password Safe secures, manages, and rotates the credentials behind them. NHI Governance builds on that foundation by turning visibility and credential management into lifecycle governance that establishes ownership, enforces least privilege, and reduces identity-based risk. Part of the BeyondTrust Pathfinder platform, NHI Governance builds on the recent introduction of AI Agent Security, further unifying discovery, governance, and enforcement within a single platform to secure privilege consistently across every identity capable of privileged action. 2026-07-22