1

Cyber Security Operations Engineer Jobs (NOW HIRING)

Job Summary The Director, Cybersecurity Operations leads the development, implementation, and ongoing coordination of enterprise-wide cybersecurity operations, including Threat Engineering, Threat ...

Salary: $142,647/Annually JLGOV is seeking a Cybersecurity Engineer to support enterprise cybersecurity operations, security engineering, continuous monitoring, and risk mitigation activities. The ...

New

Cybersecurity Manager - SME

Fairfax, VA · On-site

$110K - $148K/yr

... cyber engineering, Cyber Defense Assessment Program (CDAP) analytics, and advanced threat operations. This role serves as the primary cybersecurity authority to Government leadership and works ...

Cybersecurity Engineer

Huntsville, AL · On-site

$100K - $150K/yr

Cybersecurity Engineer Huntsville, AL SUMMARY: Founded in 2001, Indigo IT is an award winning ... Lead cybersecurity operations supporting classified and unclassified environments. * Manage RMF ...

Cybersecurity Engineer Huntsville, AL SUMMARY: Founded in 2001, Indigo IT is an award winning ... Lead cybersecurity operations supporting classified and unclassified environments. * Manage RMF ...

Job Summary The Director, Cybersecurity Operations leads the development, implementation, and ongoing coordination of enterprise-wide cybersecurity operations, including Threat Engineering, Threat ...

Senior Cybersecurity Engineer

Washington, DC · On-site

$135K - $216K/yr

The ideal candidate will possess advanced expertise in Splunk engineering, cybersecurity operations, and federal security compliance frameworks, with demonstrated experience supporting secure ...

The ideal candidate will possess advanced expertise in Splunk engineering, cybersecurity operations, and federal security compliance frameworks, with demonstrated experience supporting secure ...

Job Summary The Director, Cybersecurity Operations leads the development, implementation, and ongoing coordination of enterprise-wide cybersecurity operations, including Threat Engineering, Threat ...

Job Summary The Director, Cybersecurity Operations leads the development, implementation, and ongoing coordination of enterprise-wide cybersecurity operations, including Threat Engineering, Threat ...

The ideal candidate will possess advanced expertise in Splunk engineering, cybersecurity operations, and federal security compliance frameworks, with demonstrated experience supporting secure ...

next page

Showing results 1-20

Cyber Security Operations Engineer information

See salary details

$40.5K

$122.9K

$180K

How much do cyber security operations engineer jobs pay per year?

As of Jun 17, 2026, the average yearly pay for cyber security operations engineer in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What does a Cyber Security Operations Engineer do?

A Cyber Security Operations Engineer is responsible for protecting an organization's computer systems and networks from cyber threats and attacks. They monitor security systems, investigate incidents, and respond to breaches or vulnerabilities. Their duties include analyzing security alerts, implementing security measures, and ensuring compliance with security policies. These professionals work closely with other IT teams to maintain the overall security posture of the organization.

What engineers make $300,000 a year?

Senior cybersecurity engineers, especially those with extensive experience, advanced certifications, and expertise in areas like threat intelligence or security architecture, can earn $300,000 or more annually. High-level roles often require specialized skills, leadership responsibilities, and work in high-demand industries or organizations with large security budgets.

What are some common challenges faced by Cyber Security Operations Engineers in their daily work?

Cyber Security Operations Engineers often face challenges such as responding to rapidly evolving cyber threats, managing large volumes of security alerts, and coordinating incident response across multiple teams. Staying updated with the latest attack techniques and security tools is essential, as adversaries continuously adapt their methods. Additionally, balancing the need for strong security with operational efficiency can require careful prioritization and collaboration with IT and business units to ensure protective measures do not hinder productivity.

What is the difference between Cyber Security Operations Engineer vs Security Analyst?

AspectCyber Security Operations EngineerSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, GIAC Security Essentials
Work EnvironmentSecurity operations centers, incident response teamsMonitoring, analyzing security data, reporting
Employer & Industry UsageIT security teams across various industriesSecurity teams, cybersecurity firms, government agencies

While both roles focus on cybersecurity, the Cyber Security Operations Engineer primarily builds and maintains security systems and responds to incidents, whereas the Security Analyst monitors security alerts and analyzes threats. The engineer often handles more technical implementation, while the analyst focuses on detection and reporting.

What engineers make $500,000?

Cyber Security Operations Engineers can earn $500,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and leadership roles such as security managers or directors. High compensation is often associated with senior positions in large organizations or specialized consulting firms that handle complex security challenges.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is often considered an entry-level position in cybersecurity, suitable for individuals with foundational knowledge of networks, security tools, and incident response. However, some SOC roles require prior experience or certifications like CompTIA Security+ or Cisco CCNA, and responsibilities can vary depending on the organization.

What are the key skills and qualifications needed to thrive as a Cyber Security Operations Engineer, and why are they important?

To thrive as a Cyber Security Operations Engineer, you need a solid background in network security, threat analysis, and incident response, typically supported by a degree in computer science or a related field. Familiarity with SIEM tools (like Splunk or QRadar), intrusion detection systems, and certifications such as CISSP or CEH are commonly expected. Strong analytical thinking, attention to detail, and effective communication skills set outstanding candidates apart. These skills and qualifications are crucial for proactively identifying threats, minimizing risks, and ensuring the ongoing security of an organization's digital assets.

Can you make $500,000 a year in cyber security?

Cyber Security Operations Engineers can potentially earn $500,000 annually with extensive experience, advanced certifications, and leadership roles such as security managers or consultants working in high-demand industries. Achieving this level often requires specialized skills, a strong professional network, and working in organizations with large security budgets. Most entry- and mid-level positions do not reach this salary level.
More about Cyber Security Operations Engineer jobs
What cities are hiring for Cyber Security Operations Engineer jobs? Cities with the most Cyber Security Operations Engineer job openings:
Cybersecurity Engineer (CDAP) - Senior with Security Clearance

Cybersecurity Engineer (CDAP) - Senior with Security Clearance

ECS

Fairfax, VA

Other

Posted 16 days ago


Job description

Job Description Position Summary ECS is seeking a Cybersecurity Engineer (CDAP) - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. This role supports Task 3 - Cybersecurity Operations Support by implementing and maintaining CDAP data ingestion pipelines, connectors, and analytic components that enable enterprise security monitoring across the ARNG environment. The Cybersecurity Engineer (CDAP) assists with platform configuration, troubleshooting, performance validation, dashboard integration, and configuration change documentation, helping deliver the continuous monitoring, threat detection, and cybersecurity engineering outcomes required for Defensive Cyberspace Operations - Internal Defensive Measures (DCO-IDM).

The position works in coordination with broader cybersecurity operations personnel, including SOC, data feed, engineering, compliance, and RMF support functions. In this role, the selected candidate will help sustain cybersecurity visibility for an enterprise that supports more than 120,000 users and approximately 141,000 endpoints across about 2,800 sites in 54 states and territories. The position contributes to cybersecurity operations supporting both classified and unclassified network environments, aligned to ARNG Title 10 and Title 32 missions, mobilization readiness, domestic emergency response, and SIPRNet-enabled operations.

The technical environment includes integrated SIEM/C2C/DLP analytics, USIEM-enabled monitoring and analytics, endpoint and network data sources, continuous monitoring aligned with RMF, and coordination with organizations such as the NETCOM Global Cyber Center and DISA DCDC to strengthen cyber visibility and reporting across the DoDIN-Army-NG area of responsibility. Please Note: This position is contingent upon contract award. Responsibilities * Implement and maintain CDAP data ingestion pipelines, connectors, and analytic components that support enterprise security monitoring across ARNG classified and unclassified environments.

* Configure and troubleshoot CDAP platform components to ensure reliable telemetry flow, analytic performance, and operational reporting in support of Task 3 cybersecurity operations deliverables. * Validate platform performance and data quality to support continuous monitoring objectives, dependable telemetry ingestion, and accurate security dashboards. * Integrate dashboard outputs and reporting components to improve visibility for cybersecurity operations, data feed support, and threat-informed analysis.

* Document configuration changes, validation results, and supporting technical artifacts to maintain traceability and support RMF-aligned continuous monitoring requirements. * Support testing and verification activities for connectors, analytics, and reporting components before operational use or release into the monitoring environment. * Contribute to integrated SIEM/C2C/DLP analytics by helping sustain data feeds and analytic visibility that support USIEM monitoring and enterprise cyber reporting.

* Coordinate technical activities with cybersecurity operations teams supporting the SOC and related monitoring functions, including alignment with NETCOM Global Cyber Center and DISA DCDC processes as applicable. * Assist in maintaining telemetry and reporting capabilities that support cybersecurity operations for approximately 120,000 users and 141,000 endpoints across 2,800 sites in 54 states and territories. Required Skills Required Qualifications U.S.

Citizenship is required Security Clearance: Secret Eligible Required Certifications: DCWF Work Role 631-Information Systems Security Developer - Basic proficiency; must hold ONE OR MORE of the following: CC, CND, GISF, SSCP Experience: 3+ years of experience in cybersecurity * Experience implementing or sustaining data ingestion pipelines, connectors, or analytic components used for enterprise security monitoring. * Experience supporting platform configuration, troubleshooting, and performance validation in a cybersecurity operations environment. * Experience documenting configuration changes, test results, and technical artifacts in support of controlled operational environments.

* Familiarity with continuous monitoring practices aligned to RMF requirements and security reporting objectives. * Experience supporting dashboard integration or telemetry reporting functions for cybersecurity stakeholders. * Ability to work onsite in Fairfax, VA in an in-person environment five days per week.

Desired Skills Desired Qualifications Security Clearance: Active Secret (preferred) * Familiarity with USIEM, SIEM/C2C/DLP analytics, or comparable enterprise monitoring environments supporting cyber operations. * Experience supporting cybersecurity operations within DoD or Army enterprise environments with both classified and unclassified enclaves. * Experience working with telemetry or analytic data sources used for threat detection, correlation, and enterprise reporting.

* Familiarity with ARNG, NETCOM, DISA, or RCC/GCC-coordinated cyber operations processes. * Experience supporting RMF-related evidence collection, validation testing, or continuous monitoring documentation in operational environments. ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law.

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law. is the federal segment of , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow. We value: * Attracting and developing top talent and high-performing teams * Fostering a culture that is engaging, accountable, and mission-driven