1

Cyber Security Operations Jobs in Chicago, IL (NOW HIRING)

The Manager, Cybersecurity Operations owns day to day security operations and incident response, with a strong focus on Microsoft Azure, Microsoft 365 (including Defender, Purview, DLP, and IRM), and ...

We are seeking a Lead, Cybersecurity Operations to play a critical role in advancing our global Cybersecurity Operations (CSOC) capabilities. This individual will serve as a senior technical leader ...

Operation and optimization of security tools, including but not limited to Azure Security (DLP, Compliance), Microsoft Defender (Endpoint, Cloud, Email), Rapid 7 (Vulnerability Management, SIEM) and ...

Cybersecurity Manager

Chicago, IL

$114K - $154K/yr

Business continuity and operational resilience * Infrastructure and application security controls * Assessing the design and operating effectiveness of cybersecurity and resilience controls against ...

Cybersecurity Manager

Chicago, IL · On-site

$105 - $214/hr

Business continuity and operational resilience * Infrastructure and application security controls * Assessing the design and operating effectiveness of cybersecurity and resilience controls against ...

Cybersecurity Manager

Chicago, IL · On-site

$114K - $154K/yr

Business continuity and operational resilience * Infrastructure and application security controls * Assessing the design and operating effectiveness of cybersecurity and resilience controls against ...

Cybersecurity Manager

Chicago, IL · On-site

$105 - $214/hr

Cybersecurity operations and controls Data protection principles HIPAA Security and Privacy Rule requirements * Demonstrated ability to independently manage engagements from planning through ...

next page

Showing results 1-20

Cyber Security Operations information

See Chicago, IL salary details

$58.8K

$137.1K

$191.8K

How much do cyber security operations jobs pay per year?

As of Aug 29, 2026, the average yearly pay for cyber security operations in Chicago, IL is $137,078.00, according to ZipRecruiter salary data. Most workers in this role earn between $114,400.00 and $154,600.00 per year, depending on experience, location, and employer.

What is cyber security operations?

Cyber Security Operations refers to the processes, teams, and technologies involved in monitoring, detecting, analyzing, and responding to security threats in an organization's digital environment. Professionals in this field work to protect networks, systems, and data from cyberattacks by continuously assessing vulnerabilities and implementing security measures. Their responsibilities often include incident response, threat intelligence, and ensuring compliance with security policies. Cyber Security Operations centers (SOCs) are often established to centralize and manage these activities effectively.

What are the key skills and qualifications needed to thrive in cyber security operations?

To thrive in Cyber Security Operations, you need expertise in network security, incident response, threat analysis, and a relevant degree or industry certifications like CISSP or CEH. Familiarity with security information and event management (SIEM) tools, firewalls, intrusion detection systems, and malware analysis platforms is essential. Strong problem-solving skills, attention to detail, and effective communication help professionals respond quickly and collaborate with stakeholders. These skills are critical for protecting organizational assets, minimizing cyber risks, and ensuring operational resilience against evolving threats.

What are some common challenges faced by professionals in cyber security operations, and how can they be addressed?

Professionals in Cyber Security Operations often face challenges such as rapidly evolving threats, high-pressure incident response situations, and the need to balance proactive monitoring with reactive mitigation. Staying current with the latest cyberattack techniques and security tools is essential, as is maintaining effective communication within cross-functional teams. Addressing these challenges involves continuous learning, participating in threat intelligence sharing, and fostering a culture of collaboration and knowledge-sharing within the organization.

What is the difference between Cyber Security Operations vs Cyber Security Analyst?

AspectCyber Security OperationsCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Work EnvironmentSecurity operations centers, monitoring teamsAnalysis teams, incident response
Employer & Industry UsageOrganizations with dedicated security teamsOrganizations analyzing threats and vulnerabilities

Cyber Security Operations focuses on managing and monitoring security systems, incident response, and maintaining security infrastructure. Cyber Security Analysts primarily analyze security data, identify threats, and recommend improvements. While both roles require similar certifications and often work in overlapping environments, Operations roles are more hands-on with security tools, whereas Analysts focus on threat analysis and reporting.

What are 5 careers in cyber security?

Five common careers in cyber security include Security Analyst, Penetration Tester, Security Engineer, Incident Responder, and Security Architect. These roles involve protecting systems, identifying vulnerabilities, and developing security protocols, often requiring certifications like CISSP or CEH and familiarity with tools such as firewalls and intrusion detection systems.

What do cybersecurity operations do?

Cybersecurity operations involve monitoring, detecting, and responding to security threats and incidents to protect an organization’s information systems. Professionals in this field use tools like intrusion detection systems, firewalls, and security information and event management (SIEM) platforms to maintain the security posture and ensure data integrity. They often work in shifts and require certifications such as CISSP or Security+ to perform their duties effectively.

What are popular job titles related to Cyber Security Operations jobs in Chicago, IL?

For Cyber Security Operations jobs in Chicago, IL, the most frequently searched job titles are:

What job categories do people searching Cyber Security Operations jobs in Chicago, IL look for?

The top searched job categories for Cyber Security Operations jobs in Chicago, IL are:

Infographic showing various Cyber Security Operations job openings in Chicago, IL as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, 1% Temporary, 2% Contract, and 1% Nights. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $136,970 per year, or $65.9 per hour.

Lead, Cybersecurity Operations

Westchester, IL


Ritchie Bros.
Machinery Manufacturing • 5 - 10K employees

7.5

Company rating: 7.5 out of 10

Based on 26 frontline employees who took The Breakroom Quiz

5th of 19 rated auctioneers

Good employer

Recommended by parents

Respectful managers


Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 22 days ago


Job description

About the Role: 

We are seeking a Lead, Cybersecurity Operations to play a critical role in advancing our global Cybersecurity Operations (CSOC) capabilities. 

This individual will serve as a senior technical leader responsible for overseeing threat detection, incident response, and continuous improvement of security operations across the organization. As part of the Cybersecurity Operations Team, the Lead will drive operational excellence by enhancing detection strategies, improving incident response processes, and ensuring effective use of security technologies. This role acts as the primary technical escalation point for analysts and a key liaison between leadership and the SOC team-translating strategic direction into actionable work and ensuring meaningful outcomes.

This position requires a hands-on leader with deep technical expertise, strong operational awareness, and a passion for elevating both team performance and cybersecurity capabilities in a fast-paced, evolving threat landscape.

Responsibilities: 

  • Lead Cybersecurity Operations Execution & Quality
    Oversee day-to-day security monitoring, detection, and response activities, ensuring high-quality investigations and timely remediation of security events and incidents.
  • Serve as Primary Technical Escalation Point
    Act as the go-to escalation resource for analysts, providing hands-on guidance for complex investigations and ensuring consistency and depth in investigative outcomes.
  • Own Incident Response Lifecycle & Stakeholder Coordination
    Lead and coordinate complex security incidents end-to-end, while acting as a liaison between leadership and the SOC-translating strategic direction into actionable tasks and delivering clear, meaningful updates.
  • Drive Detection & Response Maturity (SIEM & Tooling)
    Lead SIEM-driven operations and continuously improve detection capabilities through use-case development, tuning, telemetry optimization, and enhanced coverage across security domains.
  • Coordinate SME Programs & Operational Initiatives
    Break down strategic cybersecurity objectives into actionable workstreams, track progress, remove blockers, and ensure successful execution of team initiatives.
  • Develop & Optimize Playbooks, Processes, and Automation
    Create and refine incident response playbooks, SOPs, and automation opportunities to improve consistency, efficiency, and scalability of operations.
  • Leverage Metrics & Threat Insights to Drive Improvement
    Track key operational metrics (MTTD, MTTR, alert fidelity) and conduct advanced threat analysis to inform decisions, strengthen defenses, and continuously improve security posture.

Requirements: 

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent practical experience).
  • Security+, GCIH, GCIA, GCED, or equivalent certifications.
  • 5-8+ years of experience in cybersecurity operations or SOC environments 
  • Proven experience leading or coordinating incident response activities 
  • Hands-on experience with SIEM platforms and building detection-driven operations 
  • Strong familiarity with security technologies such as EDR, NDR, email security, WAF, and identity/security monitoring tools

RB Global (NYSE: RBA)


RB Global (NYSE: RBA) (TSX: RBA) is a leading, omnichannel marketplace that provides value-added insights, services and transaction solutions for buyers and sellers of commercial assets and vehicles worldwide. Through its auction sites in 13 countries and digital platform, RB Global serves customers in more than 170 countries across a variety of asset classes, including automotive, commercial transportation, construction, government surplus, lifting and material handling, energy, mining and agriculture.


The company's marketplace brands include Ritchie Bros., the world's largest auctioneer of commercial assets and vehicles offering online bidding, and IAA, a leading global digital marketplace connecting vehicle buyers and sellers. RB Global's portfolio of brands also includes Rouse Services, which provides a complete end-to-end asset management, data-driven intelligence and performance benchmarking system; SmartEquip, an innovative technology platform that supports customers' management of the equipment lifecycle and integrates parts procurement with both OEMs and dealers; Xcira, a leader in live simulcast auction technologies; and Veritread, an online marketplace for heavy haul transport.


RB Global full-time employees are offered medical, dental, vision, and basic life insurances. Employees are able to enroll in our company's 401k plan and RB Global will match 100% for the first 4% contributed.  Employees will also receive 15 days of PTO each year.



What Ritchie Bros. Auctioneers employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom