Security Operations Analyst Jobs
Security Operations Analyst jobs are open across defense, financial services, healthcare, and technology, from entry-level SOC tier-one roles to senior analyst and team-lead positions, with specializations in threat detection, incident response, and vulnerability management. Find a role that fits from the openings below and apply directly.
Find JobsLooking for remote work? View remote security operations analyst jobs →Overview
Showing 5 of 77+ Security Operations Analyst jobs









The Security Operations Center Analyst is responsible for the administration, support, optimization, and expansion of the organization's security monitoring and log management platforms, including Splunk and Cribl. This role serves as a key contributor to security operations by ensuring reliable collection, processing, and analysis of security telemetry across both IT and Operational Technology (OT) environments.
Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.
REQUIRED
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Engineering, or related field, or equivalent experience.
Minimum 3 years of experience supporting security monitoring, SIEM, or security engineering platforms.
Minimum 1 years’ experience administering Splunk Enterprise.
Minimum 1 years’ experience supporting Cribl or similar log management technologies.
Minimum 1 years’ experience with Syslog architecture and log ingestion technologies.
Minimum 1 years’ experience supporting Managed Detection and Response (MDR) services or Security Operations Centers.
Minimum 1 years’ experience working with Windows, Linux, network, and cloud log sources.
Familiarity with Operational Technology (OT) and Industrial Control System (ICS) environments.
DESIRED
Splunk Certified Administrator or Splunk Certified Architect certification.
Experience with industrial networking and OT/ICS environments.
Experience integrating enterprise logging platforms with MDR providers.
Knowledge of NIST Cybersecurity Framework, IEC 62443, or ISA/IEC industrial security standards.
Experience with scripting and automation using PowerShell, Python, or similar tools.
Familiarity with Microsoft Azure and cloud security monitoring.
Functions
The position is responsible for supporting the integration and ongoing operation of the Managed Detection and Response (MDR) Security Operations Center (SOC), enabling effective threat detection, incident investigation, and security monitoring capabilities.
Additionally, the role designs, implements, and maintains secure log forwarding infrastructure, including Syslog collectors and forwarders within the OT DMZ (Level 3.5) of the Purdue Model, ensuring visibility into critical industrial control system environments while maintaining required segmentation and security controls.
Splunk Administration & Engineering
Administer and maintain Splunk infrastructure, including search heads, indexers, forwarders, and supporting services.
Configure and optimize data ingestion, indexing, retention, and storage management.
Troubleshoot platform issues and coordinate remediation activities.
Develop and maintain Splunk dashboards, alerts, reports, and operational monitoring content.
Ensure system availability, performance, scalability, and compliance with organizational requirements.
Coordinate upgrades, patching, and lifecycle management activities.
Cribl Administration & Engineering
Administer and support Cribl Stream infrastructure and associated log pipelines.
Develop and maintain log routing, filtering, enrichment, masking, and normalization workflows.
Optimize data collection to improve security visibility while controlling storage and licensing costs.
Monitor and troubleshooting of ingestion issues across multiple log sources.
Collaborate with infrastructure, network, and security teams to onboard new data sources
MDR SOC Integration & Operations
Support deployment and integration activities associated with the managed security operations center (MDR SOC).
Coordinate onboarding of log sources and security telemetry required for threat monitoring.
Partner with MDR analysts to improve detection coverage and data quality.
Validate alerting, event correlation, and incident workflows.
Assist with tuning security use cases to reduce false positives and improve operational effectiveness.
Participate in ongoing operational reviews and continuous improvement activities.
OT Security Monitoring & Syslog Infrastructure
Design, implement, and support Syslog forwarding architecture within OT environments.
Deploy and maintain log collectors and forwarders within the Level 3.5 OT DMZ in accordance with the Purdue Model.
Work with OT, Infrastructure, and Network teams to onboard industrial and manufacturing systems into enterprise monitoring platforms.
Ensure security monitoring solutions align with OT segmentation and regulatory requirements.
Troubleshoot connectivity, log collection, and data quality issues across OT environments.
Support secure transmission and retention of OT security events.
Security Operations Support
Investigate platform-generated alerts and assist with security incident response activities.
Validate integrity and availability of security monitoring infrastructure.
Support audit, compliance, and regulatory reporting requirements.
Maintain engineering documentation, architecture diagrams, and operational procedures.
Participate in after-hours support activities when required.
Security Operations Analyst Jobs by Experience Level
See All 77 Security Operations Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsSecurity Operations Analyst Job Market
Who's Hiring
- CENCORE11

- Metro One LPSG8

- CEVA Logistics2

- Chenega Corporation2

- Royal Caribbean2

Top Industries Hiring
- Technology & Software
- Consulting & Professional Services
- Education
- Food & Beverage
- News & Publishing
What Employers Look For
The qualifications that appear most often in security operations analyst jobs.
- Experience monitoring and triaging alerts in a SIEM platform such as Splunk or Microsoft Sentinel
- Proficiency with endpoint detection and response tools, commonly CrowdStrike or SentinelOne
- CompTIA Security+ certification or equivalent baseline security credential
- Familiarity with the MITRE ATT&CK framework for threat classification and investigation
- Ability to write and tune detection rules, correlation searches, or playbooks for automated response
- Bachelor's degree in cybersecurity, information technology, or a related technical field
Tips for Your Security Operations Analyst Job Search
Tailor your resume to SOC tools
List the specific SIEM platforms, EDR tools, and ticketing systems you have hands-on experience with, such as Splunk, CrowdStrike, or ServiceNow. Hiring managers scan for these names first, so put them high on the page.
Earn certifications before you apply
CompTIA Security+, CySA+, and the GIAC Security Essentials are widely required or preferred across security operations analyst postings. Completing one before you apply makes your resume competitive even when your direct SOC experience is limited.
Target openings by SOC tier level
Job titles vary more than the responsibilities do. Search for Tier 1, Tier 2, and Tier 3 analyst roles separately, since each maps to a different alert-triage depth and you want to apply at the tier that matches your current skill set.
Apply early to roles that fit
Migrate Mate lists security operations analyst openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Prepare a walkthrough of a real incident
Interviewers almost always ask you to walk through a detection or triage scenario you have handled. Prepare a concise, structured narrative covering what triggered the alert, how you investigated, and what actions you took to contain or escalate.
Negotiate shift expectations upfront
Many SOC roles involve rotating shifts, overnight coverage, or on-call rotations that are not always spelled out in job postings. Clarify scheduling expectations before or during the offer stage so there are no surprises after you accept.
Security Operations Analyst Jobs: Frequently Asked Questions
Which companies are hiring the most security operations analysts?
The companies hiring the most security operations analysts right now include CENCORE, Metro One LPSG, and CEVA Logistics, with the largest share of openings in Texas, California, and Georgia, based on current listings on Migrate Mate as of August 2026. Defense contractors, large financial institutions, and managed security service providers consistently account for a significant portion of total demand.
How many security operations analyst jobs are remote?
About 59% of security operations analyst openings are fully remote or hybrid as of August 2026, though availability varies significantly by employer type. Threat intelligence, vulnerability management, and cloud security monitoring roles tend to offer more remote flexibility than shift-based SOC analyst positions, which often require on-site presence for classified environments or sensitive infrastructure.
How do you become a security operations analyst?
Start by building a foundation in networking and operating systems, then pursue a recognized entry-level certification such as CompTIA Security+ or CySA+. Get hands-on practice through a home lab, capture-the-flag competitions, or a helpdesk role that exposes you to security tooling. Apply to Tier 1 SOC positions, which are specifically designed for analysts who are earlier in their careers and learning triage workflows on the job.
Can I get a security operations analyst job with little experience?
Yes, Tier 1 SOC analyst roles are the standard entry point and do not require prior SOC experience. Employers in this tier prioritize your ability to follow a runbook, escalate correctly, and learn quickly under volume. Certifications like Security+ substitute for experience on many job postings, and a home lab or documented personal projects can demonstrate hands-on initiative when your resume is otherwise thin.
What does the security operations analyst interview process look like?
Most hiring processes include an initial recruiter screen, a technical phone interview covering networking fundamentals and security concepts, and a practical scenario or take-home exercise where you analyze a log file or walk through an incident. Final rounds often involve a panel with SOC leads or security engineers who ask you to talk through how you would respond to a specific alert type from initial detection through escalation or containment.
Where can I find and apply to security operations analyst jobs?
You can find and apply to security operations analyst jobs on Migrate Mate, which lists current openings from employers across the United States. Find roles that match your experience level and specialization, then apply directly to each listing from the page.
See All 77 Security Operations Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs