1

Security Operations Analyst Jobs in California (NOW HIRING)

As Security Operations Lead, you will build and own Northwood's security operations function ... analyze telemetry across network security, identity, endpoint, and email security platforms ...

As an Operations Analyst, you will be responsible for monitoring system alerts, integrations, and ... You will work closely with engineering, infrastructure, security, customer support, and partner ...

Operations Analyst

San Diego, CA · On-site

$50K - $100K/yr

Operations Analyst Location: San Diego, CA (Onsite with some hybrid flexibility as mission allows ... Department of Defense Secret security clearance. _____ Key Responsibilities Event & Meeting ...

The Cash Management Specialist (Operations Analyst) is responsible for performing operational support duties of the Cash Management Department. Provides WebEx product training to customers and/or ...

The Cash Management Specialist (Operations Analyst) is responsible for performing operational support duties of the Cash Management Department. Provides WebEx product training to customers and/or ...

Showing results 21-40

Security Operations Analyst information

See California salary details

$17

$43

$60

How much do security operations analyst jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for security operations analyst in California is $43.57, according to ZipRecruiter salary data. Most workers in this role earn between $34.18 and $53.85 per hour, depending on experience, location, and employer.

What is a security operations analyst?

Security Operations Analysts are IT professionals responsible for monitoring, detecting, and responding to cybersecurity threats within an organization. They work in security operations centers (SOCs) to analyze security incidents, investigate suspicious activities, and help implement measures to protect digital assets. Their role often involves using security tools and technologies, collaborating with other IT teams, and ensuring compliance with security policies. By proactively identifying vulnerabilities and responding to incidents, Security Operations Analysts play a critical role in safeguarding an organization's information systems.

What does a security operations analyst do?

A security operations analyst works with a company, organization, or government office to identify and reduce security risks to their computer network. Your duties are to keep records of any suspicious activity, install security measures to prevent breaches, and give the organization suggestions about how to avoid future incidents. As a security operations analyst, your responsibilities also include conducting research on new threats and upgrading software as necessary. You often collaborate with other employees to resolve incidents as quickly as possible.

What are the key skills and qualifications needed to thrive as a security operations analyst, and why are they important?

To thrive as a Security Operations Analyst, you need a strong understanding of cybersecurity principles, incident response, and risk assessment, typically supported by a degree in computer science or related fields. Familiarity with security information and event management (SIEM) tools, intrusion detection systems, and certifications like CompTIA Security+ or CISSP is highly valuable. Analytical thinking, attention to detail, and effective communication are key soft skills that set top analysts apart. These skills and qualifications are essential for quickly identifying, investigating, and mitigating security threats to protect organizational assets.

How does a security operations analyst typically collaborate with other IT and security teams?

Security Operations Analysts work closely with various IT and cybersecurity teams to monitor, detect, and respond to security threats. They regularly interact with network engineers, incident response teams, and system administrators to escalate and resolve security incidents. Effective communication and coordination are crucial, as analysts may need to provide detailed incident reports, share threat intelligence, and participate in post-incident reviews to improve security protocols. This collaborative environment helps ensure a swift response to threats and fosters ongoing professional development through cross-team knowledge sharing.

What is the difference between Security Operations Analyst vs Security Engineer?

AspectSecurity Operations AnalystSecurity Engineer
Primary FocusMonitoring, detecting, and responding to security incidentsDesigning, implementing, and maintaining security systems
CertificationsCompTIA Security+, CISSP, CEHCISSP, GIAC Security Certifications, CISSP
Work EnvironmentSecurity operations centers, incident response teamsSecurity architecture teams, development environments
ResponsibilitiesAnalyzing security alerts, incident response, threat huntingDeveloping security tools, deploying security solutions, system hardening

While both roles focus on cybersecurity, Security Operations Analysts primarily monitor and respond to threats in real-time, whereas Security Engineers design and build security infrastructure to prevent attacks. Both roles often collaborate but serve different functions within an organization's security strategy.

What job categories do people searching Security Operations Analyst jobs in California look for?

The top searched job categories for Security Operations Analyst jobs in California are:

What cities in California are hiring for Security Operations Analyst jobs?

Cities in California with the most Security Operations Analyst job openings:

Infographic showing various Security Operations Analyst job openings in California as of August 2026, with employment types broken down into 83% Full Time, 14% Part Time, 1% Temporary, 1% Contract, and 1% Nights. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $90,619 per year, or $43.6 per hour.

Security Operations Manager

Industrious Ventures

Torrance, CA • On-site

$120 - $150/hr

Other

Posted 4 days ago


Key responsibilities

  • Build and operate Northwood's SOC function, including continuous monitoring of security events across various environments.

  • Own alert triage, investigation, escalation workflows, and manage security incidents from detection to post-incident review.

  • Develop and improve detection logic, threat hunting queries, and integrate threat intelligence to enhance security monitoring and response.


Job description

About Northwood:

Northwood is on a mission to transform connectivity between earth and space and bring the benefits of space to the masses through innovations in space communications technologies. If you like building quickly and seeing your work deployed in locations around the globe with real impact, we want you at Northwood.

Role Overview

As Security Operations Lead, you will build and own Northwood's security operations function — standing up SOC capabilities, leading incident response, and developing the detection and threat hunting programs that protect mission‑critical infrastructure. This is a senior leadership role for an operator who brings deep hands‑on experience across SIEM engineering, EDR, and incident response, and who can build a team and program from the ground up in a highly regulated, dual‑use environment.

You will develop detection content tailored to Northwood's hybrid on‑premises and cloud infrastructure, building coverage across network security, identity, endpoint, and email security telemetry sources in a highly regulated dual‑use environment. This role partners closely with the Security Engineering Lead and reports to the Head of Security.

Responsibilities Security Operations & Monitoring
  • Build and operate Northwood's SOC function, including continuous monitoring of security events across AWS GovCloud, GCC, on‑premises facilities, and endpoint environments.
  • Own alert triage, investigation, and escalation workflows, ensuring critical threats are identified and actioned with the urgency required of a mission‑critical environment.
  • Monitor and analyze telemetry across network security, identity, endpoint, and email security platforms, ensuring comprehensive visibility into Northwood's on‑premises, cloud, and perimeter environments.
  • Develop and maintain SOC operational metrics, reporting cadences, and dashboards for internal stakeholders and government customers.
Detection Engineering
  • Develop and continuously improve custom detection logic within Northwood's SIEM platform, including log source onboarding, correlation rule development, tuning, and coverage gap analysis.
  • Build behavioral analytics, UEBA rules, and threat hunting queries tailored to Northwood's infrastructure and adversary profiles targeting aerospace and defense.
  • Maintain detection content aligned to MITRE ATT&CK, ensuring coverage maps are current and gaps are systematically addressed.
  • Integrate threat intelligence feeds into detection workflows and brief stakeholders on emerging threats relevant to government and dual‑use space communications infrastructure.
Incident Response & Forensics
  • Own security incidents end‑to‑end, from initial detection through containment, eradication, recovery, and post‑incident review.
  • Conduct digital forensics and malware analysis using tools such as Volatility, YARA, and supporting utilities across Linux and Windows environments.
  • Develop and maintain incident response playbooks and escalation procedures, including communication protocols for government customers and mission‑critical operations.
  • Lead tabletop exercises and incident response drills to validate playbook effectiveness and team readiness.
Threat Hunting & Intelligence
  • Proactively hunt for advanced persistent threats across Northwood's on‑premises and cloud environments, developing and refining hunting methodologies as the threat landscape evolves.
  • Research adversary tactics, techniques, and procedures targeting aerospace, defense, and critical infrastructure, and translate findings into actionable detection and hardening improvements.
  • Maintain familiarity with government incident reporting requirements and ensure response procedures satisfy applicable regulatory obligations.
Automation & Tooling
  • Develop Python, PowerShell, or Bash automation for incident response workflows, threat hunting pipelines, and security orchestration across Northwood's environment.
  • Build and maintain SOAR playbooks and automated response actions to reduce mean time to respond and minimize manual analyst burden.
  • Collaborate with the Security Engineering Lead to ensure SOC tooling integrations across SIEM, EDR, email security, and identity platforms are maintained and continuously improved.
Team Leadership
  • Hire, mentor, and develop security operations analysts and engineers as the team scales.
  • Define SOC operating procedures, analyst workflows, and on‑call responsibilities to ensure consistent operational coverage.
  • Serve as a senior security subject‑matter expert in cross‑functional collaboration with network engineering, infrastructure, and compliance teams.
Basic Qualifications
  • 5+ years of hands‑on SOC operations, incident response, or threat hunting experience, with demonstrated experience in a technical leadership capacity.
  • Hands‑on experience building and operating SIEM platforms, including custom detection rule development, log source onboarding, and advanced query development.
  • Experience with EDR platforms, including alert triage, policy management, and forensic investigation workflows.
  • Digital forensics and malware analysis proficiency, including tools such as Volatility and YARA.
  • Proficiency in Python, PowerShell, or Bash for security automation and threat hunting workflows.
  • Experience building and maintaining UEBA capabilities for insider risk detection and anomalous behavior identification.
  • Strong Linux forensics and log analysis skills across distributed systems.
  • Working knowledge of threat intelligence frameworks including MITRE ATT&CK and the Diamond Model.
  • Familiarity with compliance frameworks relevant to government environments, including NIST 800-171, CMMC, and DFARS incident reporting requirements.
  • Ability to obtain and maintain a TS/SCI clearance.
  • U.S. citizenship or status as a lawful permanent resident required to conform with ITAR export regulations.
Preferred Qualifications
  • Active TS clearance or higher.
  • Familiarity with Northwood's core security stack, including FortiGate firewall infrastructure, Cloudflare Zero Trust, Okta, CrowdStrike or SentinelOne EDR, and email security platforms such as Proofpoint or Sublime Security.
  • Experience with cloud security monitoring in AWS GovCloud and Microsoft GCC environments.
  • Hands‑on experience with SOAR platforms and automated response workflow development.
  • Background in aerospace, defense, critical infrastructure, or other highly regulated security operations environments.
  • Experience with threat hunting in air‑gapped or compliance‑constrained environments.
  • Familiarity with government incident reporting requirements and procedures including DFARS 252.204-7012.
  • Certifications such as GCIH, GCFA, GNFA, or equivalent incident response credentials.
  • ITAR compliance experience.
#J-18808-Ljbffr