In this client-facing role, you will work with security engineers, security operations center teams ... Building automation playbooks, integrations, and workflow enhancements that improve analyst ...
In this client-facing role, you will work with security engineers, security operations center teams ... Building automation playbooks, integrations, and workflow enhancements that improve analyst ...
The analyst also contributes to operational automation efforts using scripting, Infrastructure as Code (IaC), orchestration tools, and entry-level data science concepts to improve security operations ...
The analyst also contributes to operational automation efforts using scripting, Infrastructure as Code (IaC), orchestration tools, and entry-level data science concepts to improve security operations ...
The analyst also contributes to operational automation efforts using scripting, Infrastructure as Code (IaC), orchestration tools, and entry-level data science concepts to improve security operations ...
The analyst also contributes to operational automation efforts using scripting, Infrastructure as Code (IaC), orchestration tools, and entry-level data science concepts to improve security operations ...
The analyst also contributes to operational automation efforts using scripting, Infrastructure as Code (IaC), orchestration tools, and entry-level data science concepts to improve security operations ...
The analyst also contributes to operational automation efforts using scripting, Infrastructure as Code (IaC), orchestration tools, and entry-level data science concepts to improve security operations ...
Security Officer - PT
Indianapolis, IN · On-site
$15.25 - $18.25/hr
... Security Operations Center (iSOC) and management. 4. Adhere to company policies and procedures that include participating in company-mandated training sessions -- such as annual training and ...
Security Officer - PT
Indianapolis, IN · On-site
$15.25 - $18.25/hr
... Security Operations Center (iSOC) and management. 4. Adhere to company policies and procedures that include participating in company-mandated training sessions -- such as annual training and ...
... security operations center threat hunting and incident response * Experience supporting at least one full lifecycle analytics engagement across strategy, design, and implementation * Bachelor ...
... security operations center threat hunting and incident response * Experience supporting at least one full lifecycle analytics engagement across strategy, design, and implementation * Bachelor ...
The Vulnerability Management Security Analyst supports recurring vulnerability scanning, validates ... In addition to day-to-day operations, this role will directly contribute to maturing Notre Dame ...
The Vulnerability Management Security Analyst supports recurring vulnerability scanning, validates ... In addition to day-to-day operations, this role will directly contribute to maturing Notre Dame ...
The Vulnerability Management Security Analyst supports recurring vulnerability scanning, validates ... In addition to day-to-day operations, this role will directly contribute to maturing Notre Dame ...
The Vulnerability Management Security Analyst supports recurring vulnerability scanning, validates ... In addition to day-to-day operations, this role will directly contribute to maturing Notre Dame ...
Security Analyst II
Elkhart, IN · On-site
The Security Analyst II is a role within the Information Security team who is responsible for supporting the organization's security operations and initiatives. This role involves monitoring and ...
Security Analyst II
Elkhart, IN · On-site
The Security Analyst II is a role within the Information Security team who is responsible for supporting the organization's security operations and initiatives. This role involves monitoring and ...
Security Analyst II
Elkhart, IN · On-site
The Security Analyst II is a role within the Information Security team who is responsible for supporting the organization's security operations and initiatives. This role involves monitoring and ...
Security Analyst II
Elkhart, IN · On-site
The Security Analyst II is a role within the Information Security team who is responsible for supporting the organization's security operations and initiatives. This role involves monitoring and ...
The Security Analyst II is a role within the Information Security team who is responsible for supporting the organization's security operations and initiatives. This role involves monitoring and ...
The Security Analyst II is a role within the Information Security team who is responsible for supporting the organization's security operations and initiatives. This role involves monitoring and ...
Proven ability to lead security analysis teams in high-pressure 24/7 operational environments ... Ability to support COOP exercises and emergency operations Preferred Qualifications: * GIAC ...
Proven ability to lead security analysis teams in high-pressure 24/7 operational environments ... Ability to support COOP exercises and emergency operations Preferred Qualifications: * GIAC ...
Proven ability to lead security analysis teams in high-pressure 24/7 operational environments ... Ability to support COOP exercises and emergency operations Preferred Qualifications: * GIAC ...
Proven ability to lead security analysis teams in high-pressure 24/7 operational environments ... Ability to support COOP exercises and emergency operations Preferred Qualifications: * GIAC ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist (DSS) to join our expanding Infrastructure Operations team, who will help manage and improve site security operations ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist (DSS) to join our expanding Infrastructure Operations team, who will help manage and improve site security operations ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in our ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in our ...
AWS is growing rapidly, and we are looking for a Data Center Security Manager (DSM) to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in ...
AWS is growing rapidly, and we are looking for a Data Center Security Manager (DSM) to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in our ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in our ...
AWS is growing rapidly, and we are looking for a Data Center Security Manager (DSM) to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in ...
AWS is growing rapidly, and we are looking for a Data Center Security Manager (DSM) to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in our ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in our ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in our ...
AWS is growing rapidly, and we are looking for a Data Center Security Specialist to join our expanding Infrastructure Operations team, who will help manage and improve site security operations in our ...
Security Operations Center Analyst information
See Indiana salary details
$16.47 - $21.09
19% of jobs
$22.06 is the 25th percentile. Wages below this are outliers.
$21.09 - $25.70
27% of jobs
$25.70 - $30.32
3% of jobs
The median wage is $30.53 / hr.
$30.32 - $34.93
12% of jobs
$38.86 is the 75th percentile. Wages above this are outliers.
$34.93 - $39.55
16% of jobs
$39.55 - $44.17
6% of jobs
$44.17 - $48.78
3% of jobs
$48.78 - $53.40
4% of jobs
$53.40 - $58.02
1% of jobs
$58.02 - $62.63
2% of jobs
$62.63 - $67.25
5% of jobs
$16
$35
$67
How much do security operations center analyst jobs pay per hour?
What skills make an effective security operations center analyst?
What are the most common challenges security operations center analysts face during daily operations?
What is a security operations center analyst?
What is the difference between Security Operations Center Analyst vs Security Analyst?
| Aspect | Security Operations Center Analyst | Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CEH, CISSP (preferred) | CompTIA Security+, CISSP, CISA (preferred) |
| Work Environment | Monitoring security alerts in a SOC, 24/7 shifts | Analyzing security data, conducting risk assessments |
| Employer & Industry Usage | Primarily in security operations centers, cybersecurity firms | Various industries including finance, healthcare, government |
The Security Operations Center Analyst focuses on real-time monitoring and incident response within a SOC environment, often working in shifts. In contrast, a Security Analyst typically conducts broader security assessments, policy development, and risk analysis across organizations. Both roles require similar certifications and are integral to cybersecurity teams, but their daily tasks and work settings differ.
What does a security operations center analyst do?
A security operations center analyst works on the cybersecurity team at an organization to proactively defend the organization's database, website, servers, and network. In this role you control the security alerts and ensure that each alert is taken care of before the threat of hackers gaining access to your company's information is realized. You may run an investigation if you see similar threats repeatedly to see who is attempting to attack your systems and why. Your other duties may include keeping and analyzing a security log, coordinating with other analysts or security team members, and assessing company vulnerability.

Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
As a Consultant - Cyber Defense and Resilience, you will support the design and deployment of security operations solutions that help clients improve monitoring, detection, response, and automation capabilities. In this client-facing role, you will work with security engineers, security operations center teams, and client stakeholders to build practical solutions across security information and event management, security orchestration automation and response, telemetry, and artificial intelligence-enabled workflows. You will help translate operational needs into scalable engineering outcomes across enterprise and cloud environments.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Consultant - Cyber Defense and Resilience on the Cyber Defense & Resilience team, you will be responsible for:
- Supporting the implementation and configuration of security information and event management, security orchestration automation and response, telemetry, and case management solutions across client environments
- Developing and maintaining log ingestion, normalization, enrichment, and routing workflows using application programming interfaces, connectors, and data pipelines
- Assisting with the development, testing, and tuning of detection content aligned to adversary behaviors and enterprise security requirements
- Building automation playbooks, integrations, and workflow enhancements that improve analyst efficiency and response execution
- Working directly with client stakeholders and Deloitte team members to document requirements, validate solutions, and support deployment activities
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte's Cyber Defense & Resilience team helps clients improve security operations by strengthening detection, monitoring, automation, threat-informed defense, and response capabilities. The team works across security platforms, cloud environments, and operating models to help organizations protect dynamic attack surfaces and improve readiness, response, and recovery across the cyber lifecycle.
Qualifications
Required:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field, or equivalent work experience
- 3+ years of experience in security operations, detection engineering, security engineering, or enterprise cyber defense
- Experience supporting security information and event management, security orchestration automation and response, detection, telemetry, or incident response workflows in enterprise or cloud environments
- Experience developing automations, integrations, or engineering workflows using Python or a similar scripting language
- Experience with log parsing, normalization, data transformation, application programming interface integrations, or workflow orchestration
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience with one or more security platforms across security information and event management, security orchestration automation and response, extended detection and response, endpoint detection and response, threat intelligence, or case management tools
- Experience with Amazon Web Services, Microsoft Azure, or Google Cloud security telemetry and cloud-native security services
- Experience with threat hunting, cyber threat intelligence, or purple team collaboration
- Experience with data pipeline or observability technologies used for ingestion, routing, or transformation
- Experience applying artificial intelligence, machine learning, or large language model workflows to security operations use cases
- Relevant industry certifications such as Security+, Global Information Assurance Certification Security Essentials, Global Information Assurance Certification Certified Intrusion Analyst, Global Information Assurance Certification Certified Incident Handler, Splunk, or cloud security certifications
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberCDR27
Qualifications:As a Consultant - Cyber Defense and Resilience, you will support the design and deployment of security operations solutions that help clients improve monitoring, detection, response, and automation capabilities. In this client-facing role, you will work with security engineers, security operations center teams, and client stakeholders to build practical solutions across security information and event management, security orchestration automation and response, telemetry, and artificial intelligence-enabled workflows. You will help translate operational needs into scalable engineering outcomes across enterprise and cloud environments.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Consultant - Cyber Defense and Resilience on the Cyber Defense & Resilience team, you will be responsible for:
- Supporting the implementation and configuration of security information and event management, security orchestration automation and response, telemetry, and case management solutions across client environments
- Developing and maintaining log ingestion, normalization, enrichment, and routing workflows using application programming interfaces, connectors, and data pipelines
- Assisting with the development, testing, and tuning of detection content aligned to adversary behaviors and enterprise security requirements
- Building automation playbooks, integrations, and workflow enhancements that improve analyst efficiency and response execution
- Working directly with client stakeholders and Deloitte team members to document requirements, validate solutions, and support deployment activities
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte's Cyber Defense & Resilience team helps clients improve security operations by strengthening detection, monitoring, automation, threat-informed defense, and response capabilities. The team works across security platforms, cloud environments, and operating models to help organizations protect dynamic attack surfaces and improve readiness, response, and recovery across the cyber lifecycle.
Qualifications
Required:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field, or equivalent work experience
- 3+ years of experience in security operations, detection engineering, security engineering, or enterprise cyber defense
- Experience supporting security information and event management, security orchestration automation and response, detection, telemetry, or incident response workflows in enterprise or cloud environments
- Experience developing automations, integrations, or engineering workflows using Python or a similar scripting language
- Experience with log parsing, normalization, data transformation, application programming interface integrations, or workflow orchestration
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience with one or more security platforms across security information and event management, security orchestration automation and response, extended detection and response, endpoint detection and response, threat intelligence, or case management tools
- Experience with Amazon Web Services, Microsoft Azure, or Google Cloud security telemetry and cloud-native security services
- Experience with threat hunting, cyber threat intelligence, or purple team collaboration
- Experience with data pipeline or observability technologies used for ingestion, routing, or transformation
- Experience applying artificial intelligence, machine learning, or large language model workflows to security operations use cases
- Relevant industry certifications such as Security+, Global Information Assurance Certification Security Essentials, Global Information Assurance Certification Certified Intrusion Analyst, Global Information Assurance Certification Certified Incident Handler, Splunk, or cloud security certifications
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberCDR27
Education:Bachelor's DegreeEmployment Type: