Security Operations Engineer Jobs
Security Operations Engineer jobs are open across defense, financial services, healthcare, and technology, from entry-level analyst roles to senior and staff-level positions, with specializations in threat detection, incident response, and cloud security engineering. Find a role that fits from the openings below and apply directly.
Find JobsLooking for remote work? View remote security operations engineer jobs →Overview
Showing 5 of 796+ Security Operations Engineer jobs











We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position Summary
The Lead Director - Security Operations Center (SOC) is responsible for leading the cybersecurity operations function for a rapidly evolving healthcare business, ensuring the organization can effectively detect, investigate, respond to, and recover from cybersecurity threats. By establishing strong operational processes, actionable threat intelligence, and effective response capabilities, the position helps protect critical business operations, sensitive data, and customer trust.
As the leader of the SOC function, this role is accountable for building and maturing security operations capabilities that balance security, scalability, and business agility. The Lead Director partners closely with infrastructure, cloud, identity, engineering, and business leaders to strengthen cyber resilience and prepare the organization for emerging threats. Through strong leadership, operational discipline, and continuous improvement, this position helps ensure cybersecurity remains an enabler of growth while reducing risk in a highly regulated environment.
Key Responsibilities:
Security Operations Leadership
- Lead the strategy, execution, and continuous improvement of the Security Operations Center, including threat monitoring, detection, investigation, response, and threat hunting activities.
- Establish operational processes, service levels, metrics, and reporting to measure effectiveness and support informed decision-making.
- Build and mature SOC capabilities that align security operations to business priorities, risk tolerance, and growth objectives.
- Ensure operational readiness, escalation procedures, and effective coordination during cybersecurity events and incidents.
Threat Detection & Incident Response
- Serve as the primary escalation point for significant cyber incidents and coordinate response efforts across technical and business stakeholders.
- Drive improvements in detection engineering, investigation processes, and response workflows to reduce risk and improve response times.
- Leverage automation, analytics, and AI-enabled capabilities to improve operational efficiency and strengthen cyber defense outcomes.
Cybersecurity Strategy & Resilience
- Develop and maintain security operations standards, processes, and controls aligned with regulatory requirements and industry best practices.
- Lead initiatives that strengthen cyber resilience, incident preparedness, ransomware response readiness, and recovery capabilities.
- Provide leadership with visibility into threat activity, operational performance, emerging risks, and strategic recommendations.
- Support regulatory, audit, and risk management activities related to cybersecurity operations.
Cloud, Identity & Platform Security
- Lead security operations across cloud, endpoint, identity, and network environments.
- Drive the effective use and continuous optimization of security technologies supporting monitoring, detection, investigation, and response functions.
- Partner with cloud, infrastructure, identity, and engineering teams to improve security visibility, response capabilities, and overall security posture.
- Ensure appropriate monitoring and threat detection coverage across critical systems, applications, and business services.
Leadership & Talent Development
- Build, develop, and lead a high-performing team of security operations professionals.
- Foster a culture of accountability, collaboration, innovation, and continuous learning.
- Provide mentorship, coaching, and career development opportunities to strengthen team capability and succession depth.
- Align team priorities and resources to evolving business needs, threat landscapes, and organizational objectives.
Operational Excellence & Continuous Improvement
- Identify opportunities to improve efficiency through process optimization, automation, and standardization.
- Establish meaningful metrics and reporting that demonstrate operational performance, effectiveness, and risk reduction.
- Drive continuous improvement initiatives that enhance the maturity, scalability, and effectiveness of security operations capabilities.
- Collaborate with stakeholders across technology and business functions to ensure security operations remains aligned with organizational priorities.
Required Qualifications
- 10+ years of progressive cybersecurity experience within medium-large scale environments.
- 5+ years leading Security Operations Center (SOC), Incident Response, Cyber Defense, or Threat Detection teams.
- 5+ years of Sexperience operating and optimizing enterprise security platforms, including SIEM, EDR/XDR, SOAR, and security automation technologies such as Microsoft Sentinel, CrowdStrike Falcon, and Wirespeed.
- 3+ years of demonstrated experience building, managing, and maturing security operations capabilities, including security monitoring, threat hunting, incident response, digital forensics, and security investigations.
Preferred Qualifications
- Experience supporting cloud-native and hybrid security operations across Microsoft Azure, Google Cloud Platform (GCP), and Amazon Web Services (AWS).
- Hands-on experience with Microsoft Security technologies, including Sentinel, Defender XDR, Defender for Cloud, and Entra ID, as well as Google Security Command Center.
- Experience implementing security automation, orchestration, AI-enabled security operations, or operational workflow optimization within a SOC environment.
- Strong knowledge of Zero Trust architecture, identity security, vulnerability management, cyber resilience, and ransomware response preparedness.
- Proven ability to lead teams, establish operational metrics, and communicate cybersecurity risks, incident impacts, and program performance to senior leadership.
- Industry certifications such as CISSP, CISM, CCSP, GIAC certifications, Microsoft Security certifications (SC-100, SC-200), Google Professional Cloud Security Engineer, or CrowdStrike Falcon Certification
Education
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field, or equivalent experience.
Pay Range
The typical pay range for this role is:
$144,200.00 - $288,400.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
Additional details about available benefits are provided during the application process and on Benefits Moments.
We anticipate the application window for this opening will close on: 09/30/2026
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
Security Operations Engineer Jobs by Experience Level
Top Cities Hiring Security Operations Engineers
Explore security operations engineer openings in the cities hiring most right now.
See All 796+ Security Operations Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsSecurity Operations Engineer Job Market
Who's Hiring
- Allied Universal235

- CVS Health52

- Arganteal15

- Leidos6

- Securitas6

Top Industries Hiring
- Insurance25
- Technology & Software24
- Banking & Financial Services7
- Healthcare & Medical Services6
- Electronics & Hardware5
What Employers Look For
The qualifications that appear most often in security operations engineer jobs.
- Three or more years of hands-on experience in a security operations center or equivalent environment
- Proficiency with at least one major SIEM platform such as Splunk, Microsoft Sentinel, or IBM QRadar
- Experience with endpoint detection and response tools including CrowdStrike Falcon or Carbon Black
- Relevant certification such as CompTIA Security+, CEH, GCIA, GCIH, or CISSP
- Familiarity with cloud security monitoring across AWS, Azure, or Google Cloud Platform
- Knowledge of incident response frameworks and threat intelligence integration practices
Tips for Your Security Operations Engineer Job Search
Tailor your resume to the threat stack
List the specific SIEM platforms, EDR tools, and cloud security services you've worked with, not just broad categories like 'security tools.' Recruiters and hiring managers scan for exact tool names like Splunk, CrowdStrike, or Microsoft Sentinel to filter candidates quickly.
Lead with metrics from incident response
Quantify your impact with response time improvements, alert volume reductions, or the scope of environments you've protected. Generic statements about 'monitoring infrastructure' won't differentiate you from dozens of other applicants at the same seniority level.
Apply early to roles that fit
Migrate Mate lists security operations engineer openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Filter openings by clearance requirements early
Many security operations engineer roles in defense and government contracting require an active or adjudicated clearance. Identify clearance requirements in the posting before you spend time on a tailored application to a role you can't currently qualify for.
Prepare a hands-on technical scenario walkthrough
Interviewers frequently ask you to walk through a real incident you investigated, including your detection method, containment steps, and post-incident actions. Prepare two or three concise walkthroughs that demonstrate your decision-making under pressure, not just your tool familiarity.
Negotiate on scope, not just compensation
After an offer, ask about on-call rotation frequency, the escalation structure, and whether the team operates 24/7 or business hours. These factors affect workload more than title, and understanding them before you accept helps you evaluate the role accurately.
Security Operations Engineer Jobs: Frequently Asked Questions
Which companies are hiring the most security operations engineers?
The companies hiring the most security operations engineers right now include Allied Universal, CVS Health, and Arganteal, with the largest share of openings in Texas, California, and Virginia, based on current listings on Migrate Mate as of September 2026. Demand is concentrated in defense contracting, financial services, and large enterprise technology environments.
How many security operations engineer jobs are remote?
About 53% of security operations engineer openings are fully remote or hybrid as of September 2026, though roles that involve classified systems or government contracting are almost always on-site. Cloud security and threat intelligence-focused positions are the most likely to offer remote flexibility within the broader security operations function.
How do you become a security operations engineer?
Most security operations engineers start in IT support, network administration, or a junior SOC analyst role to build foundational skills in log analysis and network traffic monitoring. From there, earning certifications like CompTIA Security+ or GCIA, gaining experience with a SIEM platform, and handling real incident response cases builds the profile employers expect at the engineer level.
Can you get a security operations engineer job with little experience?
Yes, entry-level security operations engineer roles do exist, but they typically require you to demonstrate hands-on ability rather than years of employment history. Building a home lab, completing platforms like TryHackMe or Hack The Box, earning a recognized entry-level certification, and contributing to capture-the-flag competitions can substitute for professional experience when your resume is otherwise thin.
What does the security operations engineer interview process look like?
The process typically includes an initial recruiter screen, a technical phone interview focused on your tool experience and incident response knowledge, and then a practical stage where you walk through a past investigation or work through a simulated alert triage scenario. Final rounds often involve meeting the broader security team and discussing your approach to threat detection and escalation decisions.
Where can I find and apply to security operations engineer jobs?
You can find and apply to security operations engineer jobs on Migrate Mate, which lists current openings from employers across the United States. Search the listings to find roles that match your experience, specialization, and location preference, then apply directly to each one that fits.
See All 796+ Security Operations Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs