1

Cybersecurity Operations Manager Jobs in Austin, TX

Cybersecurity Manager

Austin, TX

$110K - $148K/yr

We are seeking a Cybersecurity Manager to join our growing team of professionals focused on both ... Business continuity and operational resilience * Infrastructure and application security controls

Cyber Security Assessment Manager

Austin, TX · On-site

$110K - $148K/yr

In management at Crowe, you play a pivotal role in leading teams, guiding project execution, and ... Assessing design and operational effectiveness of technical cybersecurity controls against ...

At Crowe, we bring deep industry specialization and functional expertise to help organizations manage cybersecurity risk, protect sensitive information, and strengthen operational and business ...

Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field. * 8+ years of experience leading security operations or managing enterprise SOC environments. * CISSP ...

The Cybersecurity Operations Center (CSOC) Threat Intelligence Analyst is responsible for ... Manage intelligence feed subscriptions and ensure threat intelligence data is properly integrated ...

Serving a global client base, the Group provides Consulting & Systems Integration services, Managed Services & BPO, Cloud operations, Big Data & Cyber-security solutions, as well as transactional ...

Senior Incident Response Engineer

Austin, TX · Remote

$117K - $160K/yr

The Tier 2 Incident Response Engineer works for, and is under the daily management of, the client Cybersecurity Operations Center team lead. Minimum Yrs of Experience, Skills, and Qualifications * 3 ...

next page

Showing results 1-20

Cybersecurity Operations Manager information

See Austin, TX salary details

$30.7K

$62.9K

$117.4K

How much do cybersecurity operations manager jobs pay per year?

As of Sep 1, 2026, the average yearly pay for cybersecurity operations manager in Austin, TX is $62,883.00, according to ZipRecruiter salary data. Most workers in this role earn between $40,600.00 and $76,800.00 per year, depending on experience, location, and employer.

What does a Cybersecurity Operations Manager do?

A Cybersecurity Operations Manager oversees the daily operations of an organization's cybersecurity team, ensuring that digital assets and information are protected from threats. Their responsibilities include managing incident response, monitoring security systems, developing security policies, and coordinating with other departments to ensure compliance. They also analyze potential risks and implement measures to mitigate vulnerabilities, leading efforts to detect, prevent, and respond to cyber attacks. This role requires strong leadership, technical expertise, and up-to-date knowledge of current cybersecurity threats.

What are the key skills and qualifications needed to thrive as a Cybersecurity Operations Manager?

To thrive as a Cybersecurity Operations Manager, you need a solid background in information security principles, risk management, and incident response, typically supported by a degree in computer science or a related field and relevant cybersecurity certifications. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and compliance frameworks such as NIST and ISO 27001 is crucial. Strong leadership, decision-making, and communication skills distinguish top performers in this role. These competencies are essential for effectively protecting organizational assets, managing security teams, and ensuring a proactive stance against evolving threats.

What are some common challenges faced by a Cybersecurity Operations Manager, and how can they be addressed?

Cybersecurity Operations Managers often face challenges such as managing a rapidly evolving threat landscape, coordinating incident response across departments, and ensuring compliance with industry regulations. Balancing proactive security measures with the need for efficient business operations can also be demanding. These challenges can be addressed by fostering strong cross-functional communication, investing in continuous team training, and implementing robust incident response plans. Staying current with industry best practices and leveraging automation tools can further help streamline operations and enhance security posture.

What is the difference between Cybersecurity Operations Manager vs Security Analyst?

AspectCybersecurity Operations ManagerSecurity Analyst
CertificationsCISSP, CISM, CompTIA Security+CompTIA Security+, GIAC Security Essentials
Work EnvironmentOversees security teams, manages security operationsMonitors security systems, analyzes threats
Employer & Industry UsageUsed in organizations with dedicated security teamsCommon in security monitoring roles across industries

The Cybersecurity Operations Manager focuses on leading security teams and managing overall security operations, while the Security Analyst primarily monitors security systems and analyzes threats. Both roles require relevant certifications and are vital in maintaining organizational security, but they differ in scope and responsibilities.

What cities near Austin, TX are hiring for Cybersecurity Operations Manager jobs?

Cities near Austin, TX with the most Cybersecurity Operations Manager job openings:

Cybersecurity Operations Center Engineer

Austin, TX • On-site


Texas Health and Human Services Commission
Legislative Bodies • 201 - 500 employees

6.9

Company rating: 6.9 out of 10

Based on 33 frontline employees who took The Breakroom Quiz

679th of 853 rated public administrative organizations

People enjoy working here

Respectful managers

Uninterrupted breaks


$7.0K - $11K/mo

Full-time

Medical, Retirement, PTO

Posted 13 days ago


Job description

Join the Texas Health and Human Services Commission (HHSC) and be part of a team committed to creating a positive impact in the lives of fellow Texans. At HHSC, your contributions matter, and we support you at each stage of your life and work journey. Our comprehensive benefits package includes 100% paid employee health insurance for full-time eligible employees, a defined benefit pension plan, generous time off benefits, numerous opportunities for career advancement and more. Explore more details on the Benefits of Working at HHS webpage.
Functional Title: Cybersecurity Operations Center Engineer Job Title: Cybersecurity Analyst III Agency: Health & Human Services Comm Department: CISO - DSHS 4.2.5 Posting Number: 20366 Closing Date: 10/19/2026 Posting Audience: Internal and External Occupational Category: Computer and Mathematical Salary Range: $7,015.16- $11,864.50 Pay Frequency: MonthlySalary Group: TEXAS-B-27 Shift: Day Additional Shift: Days (First) Telework: Travel: Regular/Temporary: Regular Full Time/Part Time: Full time FLSA Exempt/Non-Exempt: Exempt Facility Location: Job Location City: AUSTIN Job Location Address: 701 W 51ST ST Other Locations: MOS Codes: 0605,0630,0631,0639,0670,0679,0681,1702,1705,1710,1720,1721,1799,2611,2659,8055,8858,14N,14NX,170A
170B,17A,17B,17C,17C0,17DX,17S,17SX,17X,181X,182X,183X,184X,1B4X1,1D7X1,1N4X1,255A,255N,255S,25B,25D
26A,26B,26Z,514A,5C0X1D,5C0X1N,5C0X1R,5C0X1S,5IX,681X,682X,683X,781X,782X,783X,784X,CTI,CTM,CTR,CWT
CYB10,CYB11,CYB12,CYB13,CYB14,IS,ISM,ISS,IT,ITS
Brief Job Description:
This position is open to U.S. Citizens and permanent residents.
This onsite role requires the selected candidate to work from an HHS office in Austin, Texas.
The Cybersecurity Analyst III performs senior-level cybersecurity engineering work with emphasis on security operations engineering, security platform administration, detection engineering, automation, orchestration, and cybersecurity infrastructure integration. The role supports agency on-premises and cloud environments by designing, implementing, maintaining, and enhancing security technologies used to protect agency systems, applications, hosts, networks, cloud services, and data. The Cybersecurity Analyst III also participates in incident response as needed.
The Cybersecurity Operations Center (CSOC) Engineer is responsible for engineering and maintaining the technical capabilities that enable enterprise security monitoring, threat detection, incident response, threat hunting, and cybersecurity operations. This position provides senior-level expertise in SIEM engineering, security orchestration and automation, cloud security integrations, endpoint security platforms, security monitoring architecture, and detection development.
The CSOC Engineer develops and maintains enterprise security monitoring infrastructure, enhances agency cybersecurity visibility, and implements technical solutions that improve the efficiency and effectiveness of security operations. This position serves as a critical technical resource responsible for ensuring security platforms generate reliable, actionable, and meaningful intelligence for cybersecurity analysts, engineers, and leadership.
This position performs highly complex information security and cybersecurity engineering work. The Engineer works under limited supervision with considerable latitude for the use of initiative and independent judgment. The Engineer will research, evaluate, implement, and optimize new security technologies, detection methodologies, automation capabilities, integrations, and operational solutions used to prevent, detect, contain, and respond to cybersecurity threats.
The Engineer provides expert guidance regarding cybersecurity technologies, monitoring architectures, logging standards, data onboarding strategies, security automation opportunities, and defensive engineering practices. This role partners closely with Cybersecurity Operations, Threat Hunting, Incident Response, Security Architecture, Infrastructure Services, Cloud Operations, and Application Development teams to strengthen the agency's cybersecurity posture. The Engineer also serves as a member of the Incident Response team.
Essential Job Functions (EJFs):
Attends work on a regular and predictable schedule following agency leave policy and performs other duties as assigned.
Security Operations Engineering & Platform Administration - 35%
  • Administers, maintains, and optimizes enterprise cybersecurity technologies supporting security monitoring and incident response operations.
  • Designs, implements, and supports Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR/XDR), SOAR, threat intelligence, identity protection, cloud security, email security, network security, and vulnerability management platforms.
  • Manages platform configurations, data ingestion pipelines, integrations, scalability, availability, and operational health.
  • Develops and maintains logging standards, monitoring requirements, and telemetry collection strategies across enterprise environments.
  • Performs platform upgrades, configuration management, tuning activities, and technology lifecycle maintenance.

Detection Engineering & Security Automation - 25%
  • Designs, develops, and maintains security detections, correlation searches, behavioral analytics, dashboards, reports, and threat-hunting content.
  • Develops automation workflows and orchestration solutions to improve operational efficiency and response capabilities.
  • Creates use cases aligned to MITRE ATT&CK techniques, threat intelligence, and agency risk priorities.
  • Enhances alert quality through tuning, enrichment, suppression logic, and continuous improvement efforts.
  • Develops and maintains detection-as-code and content management processes where applicable.
  • Applies knowledge of scripting to automate repeatable tasks.

Security Integration & Data Engineering - 20%
  • Integrates enterprise security technologies and data sources into cybersecurity monitoring platforms.
  • Collaborates with infrastructure, cloud, identity, networking, and application teams to onboard new systems and services into enterprise monitoring capabilities.
  • Develops data normalization, enrichment, correlation, and operational reporting solutions.
  • Ensures security event visibility across cloud, endpoint, network, application, middleware, database, and authentication systems.
  • Identifies gaps in telemetry coverage and develops solutions to improve security visibility.

Engineering Strategy & Collaboration - 10%
  • Evaluates emerging security technologies and monitoring solutions to improve agency cybersecurity operations capabilities.
  • Participates in architecture reviews, project consultations, and cybersecurity planning efforts.
  • Supports incident response activities by providing subject matter expertise regarding security technologies and platform capabilities.
  • Provides technical guidance and mentorship to analysts, engineers, and project teams.

Other Duties - 10%
  • Performs additional cybersecurity engineering activities as assigned, including special projects, proof-of-concept evaluations, process improvements, operational readiness initiatives, audit support, and agency cybersecurity modernization efforts.

Knowledge, Skills, and Abilities (KSAs):
Knowledge of:
  • Security Operations Center architecture, processes, and cybersecurity monitoring methodologies.
  • SIEM, SOAR, EDR/XDR, NDR, IPS/IDS, NGFW, threat intelligence, cloud security, identity security, and vulnerability management technologies.
  • Enterprise logging, event collection, correlation, and security analytics principles.
  • Automation technologies, scripting methodologies, APIs, and systems integration practices.
  • Cloud computing architectures, identity and access management, networking, operating systems, and enterprise security controls.
  • MITRE ATT&CK framework, cybersecurity threat landscapes, adversary behaviors, and defensive engineering concepts.
  • Security frameworks and standards including NIST Cybersecurity Framework, NIST 800-53, CIS Controls, and State of Texas cybersecurity requirements (including TAC Chapter 202).

Skill in:
  • Security platform administration and configuration.
  • Detection engineering and security content development.
  • Scripting, automation, and systems integration.
  • Data analysis, event correlation, and security analytics.
  • Troubleshooting complex cybersecurity technologies and integrations.
  • Writing technical documentation, engineering procedures, and operational standards.
  • Evaluating cybersecurity technologies and developing technical recommendations.

Ability to:
  • Design, implement, and maintain enterprise cybersecurity monitoring capabilities.
  • Process large security data sets to support incident response and SOC operations.
  • Analyze complex technical environments and identify engineering improvements.
  • Develop scalable and maintainable security engineering solutions.
  • Communicate technical information to both technical and non-technical audiences.
  • Work collaboratively across multiple teams and disciplines.
  • Manage multiple projects, priorities, and engineering initiatives simultaneously.

Registrations, Licensure Requirements, or Certifications:
Prefer one or more of the following certifications:
  • Certified Information Systems Security Professional (CISSP)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • GIAC Continuous Monitoring Certification (GMON)
  • GIAC Certified Detection Analyst (GCDA)
  • GIAC Certified Enterprise Defender (GCED)
  • Splunk Enterprise Security Certified Admin
  • Splunk Core Certified Power User
  • CompTIA CySA+

Initial Screening Criteria:
  • Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another.
  • At least 5+ years of experience in information technology, cybersecurity engineering, SIEM administration, security operations, detection engineering, systems/network administration, or related disciplines.
  • Experience working in a Security Operations Center (SOC).
  • Experience with one or more SIEM platforms.
  • Experience with security operations automation.

Additional Information:
Any employment offer is contingent upon available budgeted funds. The offered salary will be determined in accordance with budgetary limits and the requirements of HHSC Human Resources Manual.
Selected candidates must be legally authorized to work in the U.S. without sponsorship.
Selected candidate must be willing to commute to the office on the required days.
#LI-IN1
Review our Tips for Success when applying for jobs at DFPS, DSHS and HHSC.
Active Duty, Military, Reservists, Guardsmen, and Veterans:
Military occupation(s) that relate to the initial selection criteria and registration or licensure requirements for this position may include, but not limited to those listed in this posting. All active-duty military, reservists, guardsmen, and veterans are encouraged to apply if qualified to fill this position. For more information please see the Texas State Auditor's Job Descriptions, Military Crosswalk and Military Crosswalk Guide at Texas State Auditor's Office - Job Descriptions.
ADA Accommodations:
In compliance with the Americans with Disabilities Act (ADA), HHSC and DSHS agencies will provide reasonable accommodation during the hiring and selection process for qualified individuals with a disability. If you need assistance completing the on-line application, contact the HHS Employee Service Center at 1-888-894-4747. If you are contacted for an interview and need accommodation to participate in the interview process, please notify the person scheduling the interview.
Pre-Employment Checks and Work Eligibility:
Depending on the program area and position requirements, applicants selected for hire may be required to pass background and other due diligence checks.
HHSC uses E-Verify. You must bring your I-9 documentation with you on your first day of work. Download the I-9 Form
Telework Disclaimer:
This position may be eligible for telework. Please note, all HHS positions are subject to state and agency telework policies in addition to the discretion of the direct supervisor and business needs.


What Texas Health and Human Services employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom