Senior Security Operations Engineer Jobs in Washington
Senior Security Operations Engineer jobs in Washington are among the most active in the country, concentrated in aerospace and defense, cloud computing, and federal contracting sectors at every level from mid-career through principal engineer. The heaviest hiring centers on Seattle, Bellevue, and Redmond, where employers like Microsoft, Amazon, and Boeing maintain large security operations teams. Threat detection engineering, cloud security architecture, and security incident response are the most consistently in-demand specialties across Washington's technology and defense corridors. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 7+ Senior Security Operations Engineer jobs











Who we are:
Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. For the first time ever, safety, operations and finance teams can manage their drivers, vehicles, equipment, and fleet related spend in a single system. Combined with industry leading AI, the Motive platform gives you complete visibility and control, and significantly reduces manual workloads by automating and simplifying tasks.
Motive serves nearly 100,000 customers – from Fortune 500 enterprises to small businesses – across a wide range of industries, including transportation and logistics, construction, energy, field service, manufacturing, agriculture, food and beverage, retail, and the public sector.
Visit gomotive.com to learn more.
About the Role:
We are hiring a Senior Manager, Security Operations to build, lead and grow Motive's SOC. This is a founding leadership role — you will shape the team, the tooling, the detection strategy and the operating model rather than inheriting a mature organization and maintaining it. Reporting to the CISO, you will own the full detection and response lifecycle: detection engineering, 24/7 incident response, threat hunting, threat intelligence, security analytics, and endpoint and workload security.
The scope spans Motive's entire estate. Product and production environments cover the cloud infrastructure, services, APIs and data platforms behind Fleet Management, Driver Safety, Spend Management, Workforce Management and AI Vision, plus the connected device fleet. Enterprise and corporate systems cover endpoints, identity and SSO, SaaS applications, network, email and internal tooling. These estates have different telemetry, threat models and response constraints — you cannot contain a production workload the way you isolate a laptop — and a central part of this role is running them as one detection and response capability with one view of the adversary, because real attacks cross the boundary between them.
The mandate is coverage: we want to detect everything that goes wrong. That is a deliberately high bar, and it is an engineering problem rather than a staffing problem. We expect this SOC to be built AI-first and data-driven from day one, designed around automation from the start rather than staffing a traditional tiered analyst model and layering automation on later. Success looks like a small, senior, highly leveraged team whose time goes to hard problems, not queue processing.
What You'll Do:
- Stand up and grow the SOC — operating model, coverage structure, runbooks, escalation paths, hiring and career development for a globally distributed team — and decide the 24/7 coverage model, whether in-house follow-the-sun, MDR-augmented or hybrid
- Own Motive's detection strategy and coverage posture across both estates, treating detection content as code and mapping coverage explicitly against MITRE ATT&CK and Motive's own threat model, with a live view of gaps closed in risk order
- Extend detection into production and cloud workloads in close partnership with Platform Engineering — the highest-priority coverage expansion for the function — and build detections that span the boundary, since identity compromise on a corporate endpoint pivoting into cloud infrastructure is the attack path that matters most
- Own 24/7 incident response across product and enterprise environments, serve as incident commander for significant incidents, and be the calm, credible voice to executives when one is underway
- Own the security telemetry and analytics platform — collection, normalization, enrichment, retention and cost — and instrument the function honestly on MTTD, MTTR, detection coverage, alert precision and automation rate
- Establish a structured, hypothesis-driven threat hunting program and a threat intelligence capability tailored to Motive's sector, translating intel into detections, hunts and hardening priorities rather than newsletters
- Own EDR across the corporate fleet and, with Platform Engineering, runtime and workload protection for production, treating any unmonitored endpoint as an open finding rather than an accepted condition
- Own the operational side of phishing and social engineering defense — detection, reporting triage, takedown and credential-compromise response — partnering with the Compliance and Trust function, which owns simulation and awareness training
- Architect the AI-first operating model for the SOC, personally building and iterating on triage, enrichment, correlation and investigation automation rather than delegating it to a vendor
What We're Looking For:
- 8+ years in security operations, incident response, detection engineering or threat intelligence, with 3+ years leading teams
- Demonstrably hands-on. You have personally written detections, run investigations, led incidents as commander and built automation — recently, not early in your career. Be prepared to walk through work you did with your own hands
- Experience building or substantially rebuilding a SOC function, rather than only operating within an established one
- Credible across both estates — production and cloud security monitoring as well as corporate and enterprise security operations. Candidates strong in only one should be ready to show how they would build the other
- Deep experience with modern detection and response tooling — SIEM and security data platforms, EDR, SOAR or equivalent automation, and cloud-native telemetry — plus strong detection engineering skills you can apply personally
- Strong background in cloud and container security monitoring, with AWS and Kubernetes strongly preferred, including the practical reality that production monitoring must be introduced without destabilizing production
- Solid grounding in identity-centric attack paths — SSO, OAuth, session compromise, MFA bypass and privilege escalation across SaaS and cloud
- Proven incident command experience on significant incidents, including executive communication under pressure, and the judgment to escalate appropriately without crying wolf or sitting on something serious
- Concrete, demonstrated use of AI to run security operations — triage, enrichment, detection authoring, investigation support or reporting. We will ask what you built, what it replaced, and what it measurably changed. General enthusiasm for AI is not what we're looking for
- Experience building 24/7 coverage and leading globally distributed teams across multiple timezones. Experience in transportation, logistics, IoT and connected devices, or critical infrastructure is a plus
Creating a diverse and inclusive workplace is one of Motive's core values. We are an equal opportunity employer and welcome people of different backgrounds, experiences, abilities and perspectives.
Please review our Candidate Privacy Notice here.
UK Candidate Privacy Notice here.
The applicant must be authorized to receive and access those commodities and technologies controlled under U.S. Export Administration Regulations. It is Motive's policy to require that employees be authorized to receive access to Motive products and technology.
All job postings are for existing vacancies. Please note; some interviews or new-hire training sessions may be held in person at one of our global offices.
See All 7 Senior Security Operations Engineer Jobs in Washington
Find roles in Washington that match your experience and apply in just a few clicks.
Find JobsSenior Security Operations Engineer Jobs by City in Washington
Where Washington roles are concentrated, by current openings.
Senior Security Operations Engineer Job Market in Washington
A snapshot from current Washington openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Retail
- Banking & Financial Services
What Washington Employers Look For
The qualifications that appear most often in senior security operations engineer jobs across Washington.
- Five or more years of hands-on experience in a security operations center environment
- Active CISSP, CISM, or equivalent senior-level security certification recognized by Washington employers
- Deep proficiency with SIEM platforms such as Splunk, Microsoft Sentinel, or Chronicle
- Experience with cloud security operations across AWS, Azure, or Google Cloud environments
- Strong background in threat hunting, incident response, and digital forensics methodologies
- Familiarity with federal compliance frameworks including NIST, FedRAMP, or CMMC for defense contractors
Senior Security Operations Engineer Jobs in Washington: Frequently Asked Questions
How do you become a senior security operations engineer in Washington?
Reaching a senior security operations engineer role in Washington typically requires a bachelor's degree in computer science, cybersecurity, or information systems combined with several years of progressive SOC experience. Washington has no state-issued license for this role, but employers strongly favor candidates holding certifications such as CISSP, CISM, or GCIA. Defense and aerospace contractors in the Seattle and Bellevue corridor often require or prefer candidates who can obtain a federal security clearance.
How much do senior security operations engineers make in Washington?
Senior security operations engineers in Washington earn a median of about $128,940 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $60,210 for the lowest 10% to over $200,610 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire senior security operations engineers in Washington?
Employers hiring senior security operations engineers in Washington right now include Amazon, Brex, and Google, based on current listings on Migrate Mate as of September 2026. Washington's dense concentration of cloud technology headquarters and federal defense contractors means hiring activity remains strong throughout the year, with particularly active postings in the greater Seattle metro.
Which Washington cities have the most senior security operations engineer jobs?
Seattle, Redmond, and Kirkland lead Washington for senior security operations engineer openings. Seattle anchors demand through its concentration of major cloud and technology employers, while Bellevue and Redmond draw significant postings from enterprise software and platform companies headquartered there, and Tacoma and Olympia contribute openings tied to state government agencies and defense installations in the south Puget Sound region.
Are there remote senior security operations engineer jobs in Washington?
Yes, and more than most fields. About 100% of senior security operations engineer openings tied to Washington are remote or hybrid as of September 2026, reflecting the desk-based and analytical nature of much SOC work. Threat monitoring, alert triage, and security architecture tasks translate well to remote arrangements, though roles requiring hands-on lab access or a federal security clearance are more likely to mandate an on-site presence.
How can I get hired as a senior security operations engineer in Washington with little or no experience?
The most realistic entry path is landing a SOC analyst or junior security analyst role at one of Washington's large technology employers or managed security service providers, then building toward senior responsibilities over time. Microsoft, Amazon, and major defense contractors in the Puget Sound region hire associate-level security analysts and run structured rotational programs for candidates with relevant certifications like CompTIA Security+ or CySA+. Lateral moves from systems administration, network operations, or IT support roles are common entry points, and hands-on home lab projects or a portfolio of documented incident response work can meaningfully offset limited formal experience.
Where can I find and apply to senior security operations engineer jobs in Washington?
You can find and apply to senior security operations engineer jobs in Washington on Migrate Mate, which lists current Washington openings across the state's technology, defense, and government sectors. Search the listings to find roles that match your experience level and specialization, then apply directly to the positions that fit.
See All 7 Senior Security Operations Engineer Jobs in Washington
Find roles in Washington that match your experience and apply in just a few clicks.
Find Jobs