B

BeyondTrust

PAM, vulnerability, and endpoint security solutions

Cyber Defense Engineer

Full-TimeUpdated on 10/5/2026
No salary listed
Mid, Senior
Manchester, UK
RemoteFully remote within the UK; up to four weeks per year working abroad is subject to approval.

About the job

Requirements
  • At least four years of experience in a security operations center, security operations, or incident response role.
  • Understanding of the MITRE ATT&CK framework, network protocols, and endpoint behavior.
  • Experience with at least one security information and event management platform and familiarity with writing search or detection queries.
  • Familiarity with endpoint detection and response platforms and cloud environments, preferably infrastructure as a service.
  • Comfort using artificial intelligence systems, such as large language model assistants, copilots, or AI-driven analysis tools, in security workflows.
  • Ability to document findings clearly and concisely for technical and non-technical audiences.
Responsibilities
  • Monitor and triage security alerts across security information and event management, endpoint detection and response, and cloud security posture management platforms for corporate and product environments.
  • Investigate alerts to determine scope and severity and whether escalation is warranted.
  • Use AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.
  • Classify, document, and track alerts throughout their lifecycle using ticketing and case-management systems.
  • Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root-cause determination, and stakeholder communication.
  • Investigate security events across SIEM, EDR, CSPM, and cloud-native log sources, including identity-provider logs, cloud audit trails, and network-flow data, across corporate and product infrastructure.
  • Execute established incident-response runbooks for identity, endpoint, cloud, and email investigations.
  • Manage or assist with evidence handling, forensic-artifact collection, and chain-of-custody procedures.
  • Produce clear, decision-ready incident summaries and post-incident reports for technical and leadership audiences.
  • Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms to reduce false positives and close coverage gaps.
  • Translate threat intelligence, including CVE advisories, CISA alerts, vendor bulletins, and open-source feeds, into actionable detection content, with attention to threats targeting privileged-access tooling and supply-chain attack vectors.
  • Help maintain and evolve detection coverage mapped to MITRE ATT&CK.
  • Partner with threat-hunting peers to validate detection logic through hypothesis-driven hunts.
  • Use AI-driven tools for alert triage, enrichment, and investigation in daily operations.
  • Contribute to evaluating, integrating, and optimizing AI and automation capabilities across team workflows.
  • Assist in designing prompts, agent workflows, or large language model-based pipelines to augment analyst capabilities and reduce manual effort.
  • Partner with engineering teams to improve log ingestion, data quality, and tool integrations.
  • Maintain daily operational notes and shift-handoff documentation.
  • Contribute to and refine incident-response runbooks, playbooks, and standard operating procedures.
  • Participate in an on-call rotation for after-hours incident escalation.
  • Track and report operational metrics, including mean time to detect, mean time to respond, mean time to contain, and false-positive rate, and identify improvement opportunities.
  • Participate in tabletop exercises, purple-team activities, and post-incident reviews.
Desired Qualifications
  • Experience leading or co-leading complex incident-response engagements from triage through remediation.
  • Experience with identity and access management platforms and cloud security posture management tools.
  • Scripting and automation skills using Python, PowerShell, or equivalent, applied to security workflows.
  • Familiarity with security orchestration, automation, and response platforms or orchestration tools for automated response and enrichment.
  • Experience designing or implementing AI agent architectures, large language model-based automation pipelines, or prompt engineering for security use cases.
  • Experience building or contributing to threat-intelligence programs or detection-as-code pipelines.
  • Understanding of the privileged-access management landscape and the threat actors that target it.
  • A track record of evaluating and adopting emerging technologies in a production security environment.

About the company

BeyondTrust provides cybersecurity software for organizations. Its products include Privileged Access Management (PAM), which controls and monitors access to critical systems; Vulnerability Management, which finds and helps remediate security weaknesses; and Endpoint Protection, which secures devices from threats. The offerings are delivered as software and managed services, and the company works with large enterprises, government agencies, and partners to provide an integrated security platform. Its goal is to reduce cyber risk by preventing unauthorized access, detecting and fixing weaknesses, and protecting endpoints for safer IT operations.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$12.1M

Headquarters

Johns Creek, Georgia

Founded

1985

Get referred to BeyondTrust

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • NHI Governance and AI Agent Security target exploding non-human identity demand in 2026.
  • Black Hat 2026 launches positioned BeyondTrust as a platform leader for AI-era privilege control.
  • 20,000 customers and 75 Fortune 100 accounts create strong expansion and reference leverage.

What critics are saying

  • CVE-2026-1731 exploitation hit BeyondTrust RS and PRA within 24 hours in February 2026.
  • September 2026 SaaS incident stole BeyondTrust sales contacts, exposing customer trust and operations.
  • SynchroFi v. BeyondTrust and repeated EPM flaws deepen litigation and product-security scrutiny.

What makes BeyondTrust unique

  • Pathfinder unifies visibility, intelligence, and protection across human, machine, and AI identities.
  • BeyondTrust owns privileged access management depth from Password Safe, PRA, and Endpoint Privilege Management.
  • CrowdStrike Falcon integration embeds privilege context into SOC workflows, strengthening detection and response.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

↑ 17%

1 year growth

↑ 17%

2 year growth

↑ 21%
Ignition Technology
Sep 24th, 2026
You can't secure what you can't see: identity security lessons from BeyondTrust Partner Summit 2026.

You can't secure what you can't see: identity security lessons from BeyondTrust Partner Summit 2026. Posted by Ignition Technology September 24, 2026 Earlier this month, BeyondTrust hosted its Partner Summit London 2026 bringing together partners from across the channel to examine the trends reshaping identity security and explore how organisations can adapt to an increasingly complex digital landscape. A clear theme emerged throughout the event: identity has become the foundation of modern cybersecurity. As AI adoption accelerates and non-human identities proliferate, organisations must rethink how they establish visibility, manage privilege and maintain trust across increasingly interconnected environments. Identity has changed. Identity is no longer about just human identities, it's about machine identities, service accounts and AI agents. Identity is becoming a much broader attack surface, with 100 machine identities and AI agents now existing for every human identity. During the summit, BeyondTrust CEO Janine Seebeck highlighted that "only 19% of organisations have implemented security controls for AI agents." This statistic demonstrates that the vast majority of organisations remain exposed to risks posed by unmanaged and unaccounted-for non-human identities. It's no longer about who is privileged, it's about who could become privileged Attackers don't care where an attack starts. They only care about the path to privilege. Reading a list of privileged accounts only tells you where that privilege currently exists. Organisations should be looking ahead to where privilege can be reached from. At the summit, one example demonstrated how 200 contact-centre employees could potentially reach Domain Admin through misconfigured trust paths. It wasn't simply about employees who were privileged, as they weren't. It was about a chain of relationships that could potentially create a path to privilege. You can't protect what you can't see When it comes to protecting your organisation, you must have full oversight to understand everything that needs protecting. The go-to-market framework to help protect identities is Visibility | Intelligence | Protection. Customers can enter this framework at different areas of the cycle and be brought into the wider platform over time. The first step is understanding what identities exist, what access they have and where privilege sits. From there, organisations can identity what matters most, uncover hidden risk and understand potential paths to privilege. This evidence-led approach was a key theme throughout the summit. Rather than starting with a product, organisations can start by understanding the risks that are already present in their environment. The opportunity As identity environments become more complex, organisations need the expertise to understand and act on identity risk. This presents an opportunity for security partners to take a more advisory role, helping organisations assess their identity environments, hidden privilege and understand risks crated by AI agents and non-human identities. Want to find out more about how identity security is changing? Discover BeyondTrust's approach to identity security here.

TechDay
Sep 24th, 2026
BeyondTrust links privilege data to CrowdStrike Falcon.

BeyondTrust links privilege data to CrowdStrike Falcon. Thu, 24th Sep 2026 (Today) BeyondTrust has introduced new integrations between its Pathfinder Platform and CrowdStrike Falcon Next-Gen SIEM, bringing BeyondTrust identity and privilege data into the Falcon platform. The integrations are designed to give joint customers a single view of privilege risk and threat activity by combining identity relationships and privilege exposure data with Falcon security telemetry. Security teams face growing pressure to detect attacks that rely on compromised credentials rather than malware. BeyondTrust's Phantom Labs research found that about 75% of modern attack paths exploit identity relationships rather than software vulnerabilities alone. The new integrations cover several Pathfinder Platform products, including Endpoint Privilege Management, Password Safe and Privileged Remote Access. Endpoint Privilege Management sends policy changes, privilege elevation requests and blocked execution events into Falcon. Password Safe adds privileged access information to the Falcon console, while Privileged Remote Access shares configuration changes, console authentications and session activity tied to cloud and network infrastructure. Identity focus The announcement reflects a wider shift in cybersecurity towards identity and privilege as central indicators of risk. As organisations manage a growing mix of human users, service accounts and AI agents, security teams are under pressure to understand how those identities relate to access rights and potential attack paths. The integrations are intended to close the gap between prevention and detection by adding identity context to incident investigation. In practice, analysts using Falcon can see not only threat signals but also the privileges and relationships attached to the identities involved. That visibility matters because attackers often move through an organisation by abusing legitimate access. Correlating telemetry with privilege exposure can help security teams determine whether an alert is tied to a highly privileged account, a remote session or a recent policy change. David Manks, Vice President of Strategic Alliances at BeyondTrust, commented on the trend behind the launch. "Attackers increasingly exploit legitimate identities and privileges to move through enterprise environments, making identity context critical to understanding and responding to threats," said David Manks, Vice President of Strategic Alliances at BeyondTrust. "By bringing BeyondTrust's identity and privilege intelligence into CrowdStrike Falcon, joint customers can connect privilege risk with threat activity, bringing identity threat prevention and detection together to accelerate investigation and response." Broader platform The integrations also extend BeyondTrust's Pathfinder strategy, which centres on identifying, prioritising and reducing privilege risk across different classes of identity. The company has increasingly emphasised non-human and AI-linked identities as more software agents and automated processes gain access to systems and data. For buyers, the launch points to continued consolidation across cybersecurity tools, as vendors seek to feed more specialised data into broader detection and response platforms. SIEM products have become a focal point for that effort because they serve as central hubs for alerting, investigation and response workflows. BeyondTrust says its customer base includes more than 20,000 organisations, including 75 of the Fortune 100. The company positions privilege as the key risk factor in identity security, arguing that the issue is not simply who or what an identity is, but what access it holds. The CrowdStrike integration gives customers another way to use that data within an existing security operations environment. It also underlines the commercial importance of partnerships between specialist identity security providers and larger platform vendors that already sit at the centre of many enterprise security teams.

VMblog
Sep 23rd, 2026
BeyondTrust launches new integrations with CrowdStrike Falcon Next-Gen SIEM.

BeyondTrust launches new integrations with CrowdStrike Falcon Next-Gen SIEM. BeyondTrust announced new integrations between solutions on the BeyondTrust Pathfinder Platform and CrowdStrike Falcon(R) Next-Gen SIEM. The integrations bring BeyondTrust's identity and privilege intelligence directly into the CrowdStrike Falcon(R) platform. By correlating identity relationships and privilege exposure insights across human, non-human, and AI agent identities with Falcon threat telemetry, joint customers can bring additional identity and privilege context into Falcon to accelerate investigation and response. Identity and privilege have become critical security signals. Security teams are increasingly confronting attackers who gain access using legitimate, compromised credentials rather than traditional malware, making identity and privilege two of the most consequential risk surfaces in the enterprise. Recent BeyondTrust Phantom Labs research has found that approximately 75% of modern attack paths exploit identity relationships rather than software vulnerabilities alone, underscoring the need to correlate identity intelligence with threat activity. "Attackers increasingly exploit legitimate identities and privileges to move through enterprise environments, making identity context critical to understanding and responding to threats," said David Manks, Vice President, Strategic Alliances at BeyondTrust. "By bringing BeyondTrust's identity and privilege intelligence into CrowdStrike Falcon, joint customers can connect privilege risk with threat activity, bringing identity threat prevention and detection together to accelerate investigation and response." Closing the gap between identity prevention and detection. The integrations connect several BeyondTrust Pathfinder Platform solutions with Falcon Next-Gen SIEM, including: * BeyondTrust Endpoint Privilege Management (EPM), which surfaces policy changes, privilege elevation requests, and blocked execution events within Falcon alongside other threat indicators. * BeyondTrust Password Safe(R), which brings privileged access insights into the Falcon console to enrich threat detection with privileged credential context. * BeyondTrust Privileged Remote Access (PRA), which shares configuration changes, console authentications, and session activity to extend visibility into cloud and network infrastructure. The integrations build on BeyondTrust's broader vision for privilege-centric identity security across human, non-human, workload, and AI identities. David Marshall is the founder of VMblog.com, one of the industry's longest-running independent publications covering modern data center technologies. What began as a focus on virtualization and cloud computing has expanded to cover the full spectrum of enterprise IT, including AI, security, and DevOps, making VMblog a trusted destination for vendor news, technology analysis, and industry commentary.Beyond publishing, David has spent his career at the intersection of technology and business, inventing, marketing, and launching a number of successful software companies and products, and building a reputation as a skilled marketing executive in the enterprise IT space.David is also a published author, having written two well-regarded books on virtualization and served as technical editor for two "For Dummies" titles covering virtualization and cloud computing. He co-founded CloudCow.com, a publication focused on cloud computing, and has been named a VMware vExpert every year since 2009, one of the longest continuous honoree streaks in the program's history.Connect with David on LinkedIn: https://www.linkedin.com/in/davidmarshall/

GBHackers
Aug 19th, 2026
BeyondTrust Endpoint Privilege Management flaws enable local privilege escalation.

BeyondTrust Endpoint Privilege Management flaws enable local privilege escalation. August 19, 2026 BeyondTrust has revealed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) Windows Deployment product, which could lead to local privilege escalation and bypasses of anti-tamper protections on affected devices. Discover more Cybersecurity training platform Cyberattack prevention software Data recovery services These vulnerabilities are tracked as CVE-2026-40144 and CVE-2026-40145 and affect all versions of Endpoint Privilege Management for Windows before version 26.1.2. The company has released fixes in version 26.1.2 and is urging customers to upgrade their affected endpoints as soon as possible. BeyondTrust Endpoint Privilege Management flaws. The vulnerabilities are detailed in BeyondTrust advisory BT26-04, which was issued and updated on August 17, 2026. BeyondTrust identified both issues internally during security assessments utilizing advanced AI models alongside proprietary testing harnesses. Cloud security services The company has stated that there is no evidence suggesting that either vulnerability was exploited before being addressed. The more severe vulnerability, CVE-2026-40144, has a CVSS v4 score of 7.3 and is classified as a high-severity out-of-bounds read flaw, mapped to CWE-125. This issue exists in a kernel-mode component of the BeyondTrust Endpoint Privilege Management for Windows. According to the advisory, the component fails to validate input sufficiently, which could allow the software to access memory outside its designated bounds. Discover more Computer Security Security Products & Services A local attacker with standard, non-administrative privileges could potentially exploit this flaw to corrupt kernel memory and elevate their privileges. Successful exploitation could lead to arbitrary code execution in kernel mode, thereby giving the attacker control over one of the most privileged levels of the Windows operating system. The CVSS vector for CVE-2026-40144 is: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Although exploitation requires local access and low-level privileges on the endpoint, successful exploitation could compromise the confidentiality, integrity, and availability of the affected Windows device. The second vulnerability, CVE-2026-40145, has a CVSS v4 score of 7.1 and is categorized under CWE-1220, which refers to insufficient granularity of access control. Vulnerability scanning tool This vulnerability affects the interaction between an EPM Windows support utility and the product's anti-tamper controls. Under certain circumstances, protections designed to limit the support utility process may not function as intended. An attacker who has already gained elevated privileges could manipulate the support utility process and execute code outside the intended boundaries of the EPM anti-tamper protections. Discover more Ethical hacking course Malware removal tool Crime & Justice This vulnerability does not serve as an initial access or direct low-privilege escalation vector; it requires local access, an elevated process context, and additional endpoint-specific conditions. Its CVSS vector is: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Organizations using BeyondTrust Endpoint Privilege Management Windows Deployment should identify any endpoints running versions earlier than 26.1.2 and prioritize upgrading them. The fixes for these vulnerabilities are included in version 26.1.2 and later. Because EPM products are designed to enforce privilege controls and restrict unauthorized administrative activity, kernel-level weaknesses or anti-tamper bypasses can pose significant risks in enterprise environments. Security teams should validate the versions of deployed agents, review local administrator access, and monitor for abnormal interactions with EPM support utilities during remediation. Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world. Hot this week

GlobeNewswire
Aug 11th, 2026
BeyondTrust recognized on the 2026 Inc. 5000 list of America's fastest growing private companies.

BeyondTrust recognized on the 2026 Inc. 5000 list of America's fastest growing private companies. * Independent privilege-centric identity security leader recognized for sustained growth amid a consolidating cybersecurity market * Growth supported by sustained investment in identity security innovation throughout the 2022-2025 measurement period, alongside continued recognition from leading industry analysts "The ecosystem is changing fast. Organizations need a platform that treats privilege, not just identity, as the real point of control." ATLANTA, Aug. 11, 2026 (GLOBE NEWSWIRE) - BeyondTrust, the global leader in privilege-centric identity security protecting Paths to Privilege(TM), today announced it has been named on the prestigious 2026 Inc. 5000 list, which recognizes the fastest-growing private companies in America. "Being named to the Inc. 5000 for another year reflects the trust our customers place in us to secure their most critical identity security challenges, as well as the commitment of our employees and partners who make it possible to support our customers and sustain growth" said Janine Seebeck, CEO of BeyondTrust. "Identity has always been the front line of cybersecurity, but the ecosystem is changing fast, with non-human identities and AI agents multiplying inside organizations faster than security teams can track them. Organizations need a platform that treats privilege, not just identity, as the real point of control, and that's the problem we've built our platform to solve." BeyondTrust protects over 20,000 customers worldwide, including more than 75 of the Fortune 100, with a privilege-centric platform that reduces risk, simplifies compliance, and scales with the demands of a rapidly evolving identity landscape. That leadership continues to be validated across the industry's leading analyst reports and award programs, including: This year's Inc. 5000 recognizes a new class of companies redefining what growth looks like. From AI and advanced manufacturing to healthcare, consumer products, and professional services, these businesses are expanding their impact, creating jobs and proving that entrepreneurial ambition continues to fuel the U.S. economy. Among the 5,000 companies on the list, the median three-year revenue growth rate was 130%, and those companies have collectively added more than 627,208 jobs to the U.S. economy over the past three years. Platform Innovation Supporting Sustained Growth Throughout the 2022-2025 Inc. 5000 evaluation period, BeyondTrust continued to invest in expanding its identity security portfolio and addressing the evolving ways organizations manage and protect privileged access. Significant milestones included: * The launch of Identity Security Insights(R)(2023), expanding BeyondTrust's capabilities to provide visibility into identity threats and the Paths to Privilege(TM) attackers can exploit. * The acquisition of Entitle (2024), extending BeyondTrust's identity security platform with just-in-time access management and cloud permissions management capabilities. * The release of the True Privilege(TM) Graph (2025), advancing BeyondTrust's ability to reveal the true privilege of identities and uncover hidden attack paths across complex identity environments. Building on that trajectory, BeyondTrust has continued to accelerate investment in innovation since the close of the Inc. 5000 evaluation period, responding to the rapidly evolving identity security landscape and the emergence of AI agents, non-human identities, and workloads as critical new areas of privilege risk. Recent investments include PathfinderAI & MCP Server, AI Agent Security, NHI Governance, the expanded Identity Security Risk Assessment, and the preview of Workload Credentials, extending BeyondTrust's innovation across human, non-human, workload, and AI identities. "Every company on the Inc. 5000 has a story of perseverance, smart decision making, and a refusal to sit still," says Mike Hofman, editor-in-chief of Inc. "Their growth reflects more than strong financial performance-it reflects creativity, resilience, and the customer focus required to build companies that make a lasting impact. We congratulate all honorees on this significant achievement." * Organizations looking to uncover hidden identity and privilege risk can request a free Identity Security Risk Assessment at: https://www.beyondtrust.com/products/identity-security-insights/assessment * To learn more about BeyondTrust's latest innovations and request early access to capabilities like PathfinderAI, AI Agent Security, and NHI Governance, visit: https://www.beyondtrust.com/pathfinder * For the full Inc. 5000 list, honoree company profiles, and a searchable database by industry and location, visit: www.inc.com/inc5000 About BeyondTrust BeyondTrust is the global leader in privilege-centric identity security protecting Paths to Privilege(TM). Identity alone doesn't create risk. Privilege does. As human, non-human, and AI agent identities explode across every environment, BeyondTrust is the only company built to discover, control, and secure privilege across all of them from a single platform. Trusted by 20,000+ customers, including 75 of the Fortune 100, and recognized as a multi-category leader by top industry analysts, BeyondTrust reframes identity security from a management problem into a strategic advantage. About Inc. 5000 Companies on the 2026 Inc. 5000 are ranked according to percentage revenue growth from 2022 to 2025. To qualify, companies must have been founded and generating revenue by March 31, 2022. They must be U.S.-based, privately held, for-profit, and independent - not subsidiaries or divisions of other companies - as of December 31, 2025. (Since then, some on the list may have gone public or been acquired.) The minimum revenue required for 2022 is $100,000; the minimum for 2025 is $2 million. As always, Inc. reserves the right to decline applicants for subjective reasons. About Inc. Inc. is the leading media brand and playbook for the entrepreneurs and business leaders shaping its future. Through its journalism, Inc. aims to inform, educate, and elevate the profile of its community: the risk-takers, the innovators, and the ultra-driven go-getters who are creating the future of business. Inc. is published by Mansueto Ventures LLC, along with fellow leading business publication Fast Company. For more information, visit www.inc.com. For BeyondTrust: BeyondTrust Public Relations P: (516)-521-5582