Security Operations Center Jobs in California
Security Operations Center jobs in California are in strong demand, concentrated in defense contracting, finance, technology, and critical infrastructure sectors, with openings at every level from entry-level SOC analyst through senior SOC engineer and team lead. The largest hiring clusters are in Los Angeles, San Diego, and the San Francisco Bay Area, where employers like Leidos, Northrop Grumman, and Palo Alto Networks maintain a significant and lasting presence. Threat detection, incident response, and cloud security monitoring are the most consistently sought specializations across California postings. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 11+ Security Operations Center jobs









JOB TITLE: Security Operations Center (SOC) Engineer
LOCATION: Foster City, CA (Hybrid)
PAY RANGE: $82-$92/hr.
DURATION: 6 months
TOP 3 SKILLS:
- 6+ years of experience in a Security Operations Center (SOC) environment or a similar cybersecurity role.
- Hands-on experience with managing and configuring SIEM platforms (e.g., Elastic SIEM, Splunk, QRadar, Microsoft Sentinel).
- Demonstrable experience with SOAR platforms (e.g., Palo Alto Cortex XSOAR, Splunk SOAR) and playbook development.
Overview:
We are seeking a motivated and experienced Security Operations Center (SOC) Engineer to strengthen the company’s security posture through automation and proactive threat hunting. The ideal candidate will have a strong background in Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms, coupled with proficiency in Python scripting. This role is pivotal in enhancing our security posture by developing and implementing automated security workflows, tuning our detection capabilities, and responding to sophisticated cyber threats.
Key Responsibilities:
SIEM and SOAR Platform Management:
- Maintain our SIEM and SOAR platforms to ensure optimal performance and effectiveness in detecting and responding to security threats.
- Develop and fine-tune detection and correlation rules, dashboards, and reports within the SIEM to accurately detect anomalous activities.
- Create, manage, and optimize SOAR playbooks to automate incident response processes and streamline security operations.
Automation and Scripting:
- Utilize Python scripting to develop custom integrations and automate repetitive tasks within the SOC.
- Build and maintain automation workflows to enhance the efficiency of threat detection, alert triage, and incident response.
- Integrate various security tools and threat intelligence feeds with our SIEM and SOAR platforms using APIs and custom scripts.
Incident Response and Threat Hunting:
- Conduct proactive threat hunting to identify potential security gaps and indicators of compromise.
- Analyze security alerts and data from various sources to identify and respond to potential security incidents.
Collaboration and Documentation:
- Collaborate with Information Security team members and other teams to enhance the overall security of the organization.
- Create and maintain clear and comprehensive documentation for detection rules, automation workflows, and incident response procedures.
Required Qualifications:
- 6+ years of experience in a Security Operations Center (SOC) environment or a similar cybersecurity role.
- Hands-on experience with managing and configuring SIEM platforms (e.g., Elastic SIEM, Splunk, QRadar, Microsoft Sentinel).
- Demonstrable experience with SOAR platforms (e.g., Palo Alto Cortex XSOAR, Splunk SOAR) and playbook development.
- Proficiency in Python for scripting and automation of security tasks.
- Strong understanding of incident response methodologies, threat intelligence, and cybersecurity frameworks (e.g., MITRE Telecommunication&CK, NIST).
- Excellent analytical and problem-solving skills with the ability to work effectively in a fast-paced environment.
Preferred Qualifications:
- Relevant industry certifications such as CISSP, GCIH, or similar.
- Experience with cloud security and environmental constructs (AWS, Azure, GCP).
- Familiarity with other scripting languages (e.g., PowerShell, Bash).
- Knowledge of network and endpoint security solutions.
BENEFITS SUMMARY:
Individual compensation is determined by skills, qualifications, experience, and location. Compensation details listed in this posting reflect the base hourly rate or annual salary only, unless otherwise stated. In addition to base compensation, full-time roles are eligible for Medical, Dental, Vision, Commuter and 401K benefits with company matching.
See All 11 Security Operations Center Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find JobsSecurity Operations Center Jobs by City in California
Where California roles are concentrated, by current openings.
Security Operations Center Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring


Top Industries Hiring
- Staffing & Recruiting
- Electronics & Hardware
What California Employers Look For
The qualifications that appear most often in security operations center jobs across California.
- Active CompTIA Security+ or equivalent industry certification recognized by California employers
- Experience monitoring and analyzing security events using a SIEM platform
- Familiarity with threat detection, incident response, and escalation procedures
- Knowledge of network protocols, firewalls, and intrusion detection systems
- Ability to obtain or maintain a security clearance for defense and government roles
- Associate or bachelor's degree in cybersecurity, information technology, or a related field
Security Operations Center Jobs in California: Frequently Asked Questions
How do you become a security operations center analyst in California?
Most California employers hire SOC analysts who hold an industry certification such as CompTIA Security+ or CySA+, combined with an associate or bachelor's degree in cybersecurity or information technology. California has no state-issued license specific to SOC work, so credentials and hands-on lab experience carry the most weight. Many candidates build their foundation through community college cybersecurity programs, then pursue entry-level SOC analyst roles at managed security service providers or technology firms.
How much do security operations centers make in California?
Security operations centers in California earn a median of about $138,570 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $66,070 for the lowest 10% to over $221,000 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire security operations center analysts in California?
Employers hiring security operations centers in California right now include Tesla, Allied Universal, and AUEPS, based on current listings on Migrate Mate as of August 2026. California's concentration of defense contractors, major tech companies, and financial institutions makes it one of the more active states for ongoing SOC hiring throughout the year.
Which California cities have the most security operations center jobs?
Anaheim, Fremont, and Sunnyvale have the most security operations center openings in California. Los Angeles draws volume from entertainment, finance, and defense contractors headquartered in the region, San Diego's market is driven by a large concentration of military and defense technology employers, and the Bay Area reflects strong demand from enterprise technology and cloud security firms based there.
Are there remote security operations center jobs in California?
Yes, and more than many technical roles. About 33% of security operations center openings tied to California are remote or hybrid as of August 2026, reflecting the desk-based, screen-intensive nature of SOC work. Threat monitoring, alert triage, and incident documentation are the functions most commonly performed remotely, while hands-on network engineering or on-site classified work typically remains in-person.
How can I get hired as a security operations center analyst in California with little or no experience?
The most realistic entry path is an associate-level SOC analyst role at a managed security service provider, where California employers such as large defense contractors and regional MSSPs regularly bring in candidates from adjacent IT support, help desk, or network administration positions. Completing a community college cybersecurity certificate, earning CompTIA Security+, and building a home lab with open-source SIEM tools are the credentials that give entry-level California applicants a concrete edge over candidates with no hands-on practice.
Where can I find and apply to security operations center jobs in California?
You can find and apply to security operations center jobs in California on Migrate Mate, which lists current California openings. Find roles that fit your experience and specialization, then apply directly to the employer through the listing.
See All 11 Security Operations Center Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Jobs