Security Operations Center Jobs
Security Operations Center jobs are open across financial services, healthcare, government, defense, and technology, from entry-level analyst to SOC manager and director, with specializations in threat detection, incident response, and security engineering. Find a role that fits from the openings below and apply directly.
Find JobsOverview
Showing 5 of 140+ Security Operations Center jobs











Oracle's Global Physical Security (GPS) Operations Team secures the corporation's data center and facility footprint through physical access, video monitoring, alarm management, incident response, and coordinated operational controls. The Physical Security Operations Analyst is the on-site IC4 owner for the Shackelford, TX local SOC operating model.
This role is not a people-manager position. It leads the SOC function: establishing reliable procedures, ensuring local operators and contracted personnel can execute them, coordinating with the Global Security Operations Center (GSOC) and site partners, and resolving the systems, process, documentation, training, and escalation gaps that affect monitoring and response.
The role operates with substantial independence and is accountable for operational readiness, consistent incident handling, clear handoffs, and measurable improvement across the local SOC environment.
This is an on-site role in our Santa Teresa, NM location.
Own the local SOC operating model for Shackelford, including alarm monitoring, camera verification, dispatch coordination, incident logging, shift handoffs, and escalation paths.
Translate GSOC SOPs, Alarm Master Matrix requirements, site post orders, and local operating needs into usable runbooks, job aids, and response workflows.
Standardize the investigation, documentation, and escalation of alarms and incidents so actions are timely, consistent, and traceable across shifts.
Maintain local readiness for Lenel access-control alarms, Milestone video monitoring and retrieval, communication tools, and documented degraded-mode procedures when systems or connectivity are impaired.
Coordinate with GSOC, Security Systems, Data Center Operations, construction, guard force leadership, IT/network teams, and vendors to diagnose monitoring gaps, restore service, and close recurring break/fix issues.
Support construction-to-operations transitions by validating monitoring coverage, alarm visibility, camera readiness, access-control changes, commissioning activity, and operational handoffs before sites or systems enter service.
Develop and maintain practical training plans, access readiness, and competency checks for SOC operators and contracted staff; provide functional guidance without assuming direct personnel-management authority.
Analyze alarm, incident, outage, response-time, and quality data; establish meaningful performance measures and recommend corrective actions, preventive controls, and process improvements.
Maintain audit-ready SOC documentation, including shift logs, incident records, escalation guides, operating procedures, training materials, outage playbooks, and after-action follow-up.
Serve as the local functional escalation point for SOC process and systems issues, escalating material risk, critical incidents, and unresolved service failures through the defined GPS and GSOC paths.
Support GPS Investigations by preserving, locating, and documenting relevant video, alarm, and access-control information for review of suspicious activity or incidents.
Scope, Judgment, and Collaboration
Works independently on significant operational issues where sound judgment is required to assess risk, define an appropriate response, and coordinate action across multiple teams.
May direct day-to-day functional work, training, and adherence to approved procedures for contracted SOC operators and technicians; does not have direct reports or responsibility for personnel actions.
Builds effective working relationships with GSOC, Security Systems, Data Center Operations, investigations, construction, IT/network teams, vendors, and guard-force partners.
- Escalates decisions outside the role's authority, including staffing, contractual matters, enterprise standards, and high-consequence incidents, to the appropriate GPS leader or GSOC partner.
Qualifications
Seven or more years of relevant experience in physical security operations, a security operations center, local alarm center, control room, or enterprise physical-security technology environment.
Hands-on experience with access-control, video-management, alarm-monitoring, and incident-management workflows; Lenel and Milestone experience strongly preferred.
Demonstrated ability to create, improve, and use operational runbooks, alarm response procedures, escalation guides, shift-handoff standards, and training materials.
Experience diagnosing or coordinating resolution of monitoring, camera, access-control, network, or system-integration issues in a live operational environment.
Strong incident documentation, analytical, communication, vendor-coordination, and cross-functional project skills.
Ability to work on-site in Shackelford, Texas and support a 24/7 operational environment, including response to significant incidents or system outages when required.
Preferred Qualifications
Experience supporting data center physical security operations, construction-to-operations transitions, or high-availability environments.
Experience with PSIM platforms, alarm/event automation, ticketing integration, analytics, or reporting/KPI development.
Familiarity with incident documentation and control expectations in regulated or audit-sensitive environments, including SOC 2, PCI DSS, ISO 27001, or equivalent.
Bachelor's degree in security, criminal justice, engineering, information systems, or a related discipline; equivalent experience will be considered.
Success Measures
Consistent alarm verification, dispatch, documentation, and escalation across shifts.
Current, usable runbooks, training records, shift-handoff standards, and degraded-mode procedures.
Improved visibility into system outages, camera/access-control issues, response performance, and recurring operational risks.
Reliable coordination and clear local-to-GSOC handoffs during incidents, outages, and operational transitions.
#LI-CG2
Security Operations Center Jobs by Experience Level
See All 140+ Security Operations Center Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsSecurity Operations Center Job Market
Who's Hiring
- Allied Universal12

- CENCORE11

- Metro One LPSG8

- Smith4

- Securitas3

Top Industries Hiring
- Consulting & Professional Services
- Education
- Technology & Software
- Electronics & Hardware
- Food & Beverage
What Employers Look For
The qualifications that appear most often in security operations center jobs.
- Experience with SIEM platforms such as Splunk, Microsoft Sentinel, or IBM QRadar
- CompTIA Security+, CySA+, or equivalent security certification
- Familiarity with incident response procedures and escalation workflows
- Understanding of network protocols, log analysis, and threat intelligence concepts
- Experience triaging and documenting security alerts in a ticketing system
- Associate or bachelor's degree in cybersecurity, information technology, or a related field
Tips for Your Security Operations Center Job Search
Tailor your resume to shift work
SOC roles often run 24/7 operations, so recruiters scan for shift coverage experience. Call out specific shifts you've worked, whether you've handled overnight escalations, and your familiarity with handoff procedures to signal you can operate in a continuous monitoring environment.
Lead with certifications, not just titles
Hiring managers for SOC analyst roles filter hard on certifications like Security+, CySA+, or CEH before reading your job history. Put active certifications near the top of your resume rather than burying them in a separate section at the bottom.
Apply early to roles that fit
Migrate Mate lists security operations center openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Quantify alerts handled per shift
Generic phrases like 'monitored network traffic' don't stand out. Where you can, describe the volume of alerts triaged per shift or the number of incidents escalated, so interviewers understand your real operational tempo and your comfort with high-alert environments.
Prepare for live scenario questions
SOC interviews routinely include live threat walkthroughs, such as analyzing a sample SIEM alert or tracing a phishing chain. Practice narrating your thought process out loud, not just arriving at the right answer, because analysts communicate findings to non-technical stakeholders in real time.
Negotiate beyond base pay in shift roles
SOC positions with overnight or weekend rotations sometimes carry shift differentials that don't appear in the posted range. When you receive an offer, ask specifically whether shift differentials, on-call pay, or certification reimbursement are part of the total package before accepting.
Security Operations Center Jobs: Frequently Asked Questions
Which companies are hiring the most security operations centers?
The companies hiring the most security operations centers right now include Allied Universal, CENCORE, and Metro One LPSG, with the largest share of openings in Texas, California, and Maryland, based on current listings on Migrate Mate as of August 2026. Demand is consistently strong in financial services, defense contracting, and managed security service providers.
How many security operations center jobs are remote?
About 21% of security operations center openings are fully remote or hybrid as of August 2026, though availability varies significantly by role type. Threat intelligence analyst and security engineering positions tend to see the highest share of remote arrangements, while tier-one analyst roles tied to on-premises infrastructure or classified networks are more likely to require an on-site presence.
How do you become a security operations center?
Start by building foundational knowledge through a degree or self-study in cybersecurity or IT, then earn an entry-level certification such as CompTIA Security+. Gain hands-on experience through a help desk, IT support, or internship role where you touch network monitoring or ticketing systems. From there, apply for a junior SOC analyst position, where you'll develop triage skills and work toward advanced certifications like CySA+ or CEH.
Can you get a security operations center job with little experience?
Yes, many SOC teams hire candidates at a tier-one analyst level specifically to train them on internal tooling and processes. Employers hiring entry-level analysts prioritize certifications like Security+ and demonstrated curiosity about threat analysis over years of experience. Home lab projects, capture-the-flag competitions, and coursework on SIEM platforms strengthen your application when professional experience is limited.
What does the security operations center interview process look like?
Most SOC interviews run in two to three stages. An initial screening covers your background and certifications, followed by a technical interview where you walk through a realistic scenario, such as analyzing a suspicious log or describing how you'd triage a phishing alert. Some employers add a practical exercise where you work live inside a SIEM or review a packet capture, then a final conversation with a hiring manager focused on shift availability and team fit.
Where can I find and apply to security operations center jobs?
You can find and apply to security operations center jobs on Migrate Mate, which lists current openings from employers across the United States. Search the listings to find roles that match your experience level and specialization, then apply directly to each one that fits.
See All 140+ Security Operations Center Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs