1

Security Operations Center Analyst Jobs in Utah (NOW HIRING)

IT Security Engineer

Draper, UT · On-site

$83K - $114K/yr

... 24/7 Security Operations Center (SOC), while supporting day-to-day security operations and ... Perform event triage, root cause analysis, and containment actions in collaboration with internal ...

Cyber Defense Analyst

Clearfield, UT

$101K - $121K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a Cyber Defense Analyst, you will be a member of the Security Operations Center (SOC) team supporting a Department of Defense program of record. The position will be based in Clearfield, UT. This ...

Cyber Defense Analyst

Clearfield, UT

$101K - $121K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a Cyber Defense Analyst, you will be a member of the Security Operations Center (SOC) team supporting a Department of Defense program of record. The position will be based in Clearfield, UT. This ...

Cyber Defense Analyst

Clearfield, UT · On-site

$101K - $121K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a Cyber Defense Analyst, you will be a member of the Security Operations Center (SOC) team supporting a Department of Defense program of record. The position will be based in Clearfield, UT. This ...

GSOC Operator - Physical Security

Provo, UT

$17 - $21/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Manage and monitor security scheduling and staffing to ensure adequate coverage and operational ... onsite fitness center; a health savings account & 401k with company match; an incentive bonus ...

GSOC Operator - Physical Security

Provo, UT · On-site

$17 - $21/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Manage and monitor security scheduling and staffing to ensure adequate coverage and operational ... onsite fitness center; a health savings account & 401k with company match; an incentive bonus ...

Showing results 21-40

Security Operations Center Analyst information

See Utah salary details

$15

$33

$64

How much do security operations center analyst jobs pay per hour?

As of Aug 16, 2026, the average hourly pay for security operations center analyst in Utah is $33.56, according to ZipRecruiter salary data. Most workers in this role earn between $20.58 and $39.81 per hour, depending on experience, location, and employer.

What is a security operations center analyst?

Security Operations Center (SOC) Analysts are cybersecurity professionals who monitor, detect, and respond to security threats within an organization’s IT environment. They analyze security alerts, investigate incidents, and coordinate responses to mitigate risks and protect sensitive data. SOC Analysts use specialized tools to track suspicious activities, implement security measures, and ensure compliance with security policies. Their work is crucial in defending organizations against cyberattacks and maintaining overall information security.

What does a security operations center analyst do?

A security operations center analyst works on the cybersecurity team at an organization to proactively defend the organization's database, website, servers, and network. In this role you control the security alerts and ensure that each alert is taken care of before the threat of hackers gaining access to your company's information is realized. You may run an investigation if you see similar threats repeatedly to see who is attempting to attack your systems and why. Your other duties may include keeping and analyzing a security log, coordinating with other analysts or security team members, and assessing company vulnerability.

What skills make an effective security operations center analyst?

To thrive as a Security Operations Center Analyst, you need a strong understanding of cybersecurity principles, network protocols, and incident response, often backed by a relevant degree or certifications like CompTIA Security+ or CISSP. Familiarity with SIEM tools (e.g., Splunk, QRadar), intrusion detection systems, and ticketing platforms is essential for effective monitoring and analysis. Attention to detail, analytical thinking, and clear communication help SOC Analysts excel in identifying threats and collaborating with IT teams. These skills are crucial to quickly detecting, investigating, and mitigating security incidents, protecting organizational assets from cyber threats.

What are the most common challenges security operations center analysts face during daily operations?

Security Operations Center (SOC) Analysts often deal with a high volume of alerts, many of which may be false positives, requiring keen analytical skills to prioritize genuine threats. Staying updated on evolving cyber threats and attack patterns is another challenge, as adversaries continuously adapt their tactics. Additionally, SOC Analysts frequently work in high-pressure environments where quick, accurate decision-making is crucial, and collaboration with IT, incident response teams, and management is essential to ensure coordinated defense efforts.

What is the difference between Security Operations Center Analyst vs Security Analyst?

AspectSecurity Operations Center AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CISA (preferred)
Work EnvironmentMonitoring security alerts in a SOC, 24/7 shiftsAnalyzing security data, conducting risk assessments
Employer & Industry UsagePrimarily in security operations centers, cybersecurity firmsVarious industries including finance, healthcare, government

The Security Operations Center Analyst focuses on real-time monitoring and incident response within a SOC environment, often working in shifts. In contrast, a Security Analyst typically conducts broader security assessments, policy development, and risk analysis across organizations. Both roles require similar certifications and are integral to cybersecurity teams, but their daily tasks and work settings differ.

What are popular job titles related to Security Operations Center Analyst jobs in Utah?

For Security Operations Center Analyst jobs in Utah, the most frequently searched job titles are:

What job categories do people searching Security Operations Center Analyst jobs in Utah look for?

The top searched job categories for Security Operations Center Analyst jobs in Utah are:

What cities in Utah are hiring for Security Operations Center Analyst jobs?

Cities in Utah with the most Security Operations Center Analyst job openings:

Infographic showing various Security Operations Center Analyst job openings in Utah as of August 2026, with employment types broken down into 84% Full Time, 13% Part Time, 1% Temporary, and 2% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $69,803 per year, or $33.6 per hour.

Senior Cyber Threat Defense - Security Operations Engineer

Segment (Twilio)

Draper, UT • On-site

$110 - $159.72/hr

Other

Posted 11 days ago


Job description

About Us: Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people.

How We Work:
  • Bold in how we dream and innovateResponsive to feedback, challenges and opportunitiesAccountable for results and best in class outcomesVisionary in future focused problem-solvingExceptional in execution and impact

About Proofpoint At Proofpoint, we protect organizations and individuals from today's most advanced cyber threats. Through innovative security technologies, threat intelligence, and a global team of security experts, we help customers defend against phishing, malware, account compromise, insider threats, and data loss.

Role Overview

We are seeking an experienced Senior Cyber Threat Defense - Security Operations Engineer to join our global security team in Draper, UT. This critical role sits within the Global Information Security Operation team and is responsible for investigating and responding to sophisticated security incidents across Proofpoint's global operations. You will serve as a senior Level 3 escalation point for the 24/7 Security Operations Center (SOC), own complex investigations and technical decisions, participate in a scheduled on-call rotation, and set direction for detection, investigation, response, threat modeling, and security automation. The role also supports selected AI-enabled capabilities, including Agentic SOC workflows and AI Data Loss Prevention (AI DLP).

Key Responsibilities
  • Incident Response and Escalation Own Level 3 escalation for high-severity and technically complex incidents within the global 24/7 SOC. Lead major investigations involving malware, ransomware, phishing, identity attacks, insider threats, cloud compromise, and advanced persistent threats. Set containment, eradication, recovery, remediation, and post-incident improvement strategy, balancing risk and business impact. Direct response across Security, IT, Cloud Engineering, Legal, Privacy, and business leaders, and communicate incident status and decisions to executives. Participate in a scheduled on-call rotation and provide after-hours support for critical security incidents, including nights, weekends, and holidays as required.
  • Threat Hunting, Modeling, and Detection Engineering Proactively hunt for hidden threats across endpoints, identities, networks, cloud environments, SaaS applications, and data repositories. Lead cross-functional threat modeling for new and existing systems, cloud services, and security workflows to identify abuse cases, attack paths, and control gaps. Use threat intelligence and behavioral analytics to identify suspicious activity and emerging attack patterns. Develop, test, tune, and maintain detection rules, correlations, hunting queries, and response use cases. Translate threat intelligence and MITRE ATT&CK techniques into actionable detection and hunting use cases.
  • Security Automation and Orchestration Define and implement automation strategy for alert enrichment, prioritization, triage, containment, notification, and remediation. Use SOAR platforms and security APIs to streamline repeatable incident-response activities. Develop scripts, integrations, and automation using Python, PowerShell, Bash, or similar languages. Optimize SIEM log ingestion, normalization, correlation, retention, and alerting.
  • Emerging Security Capabilities Support practical Agentic SOC use cases for alert triage, investigation enrichment, case documentation, and response under defined human oversight. Help operate AI DLP controls that reduce sensitive-data exposure through generative AI applications and copilots.
  • Continuous Improvement Own root-cause analysis and drive improvements to security controls, telemetry, processes, and architecture. Partner with security architects and engineering leaders to set technical direction and evaluate detection and response technologies. Mentor engineers and analysts, establish investigation standards, and raise technical capability across the SOC.
Required Qualifications and Experience
  • Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations.
  • U.S. citizenship.
  • Demonstrated experience leading major incidents and serving as the final technical escalation point for complex or high-severity security events.
  • Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, and security monitoring.
  • Experience investigating malware, phishing, identity attacks, cloud compromise, insider threats, data loss, and advanced persistent threats.
  • Hands-on experience with SOAR platforms, APIs, and scripting languages such as Python, PowerShell, or Bash.
  • Strong understanding of the MITRE ATT&CK framework, attacker tactics, techniques, and procedures, and the cyber kill chain.
  • Experience applying threat modeling methods such as STRIDE, attack trees, or MITRE ATT&CK to enterprise or cloud systems.
  • Experience creating or tuning detection rules, hunting queries, and response playbooks.
  • Working knowledge of cloud security across AWS, Microsoft Azure, or Google Cloud Platform.
  • Proven ability to own technical strategy, influence architecture and control decisions, and drive cross-functional security improvements.
  • Strong executive communication, analytical, troubleshooting, and documentation skills, with the ability to make sound decisions during high-pressure incidents.
  • Willingness and ability to participate in an on-call rotation and respond to critical incidents outside normal business hours, including nights, weekends, and holidays as required.
Preferred Qualifications
  • Experience with Agentic SOC, AI-assisted investigation, or AI DLP capabilities.
  • Experience with identity, cloud, or data detection and response technologies.
  • Experience leading incident simulations, purple-team exercises, or adversary-emulation activities.
  • Relevant certifications such as GCIH, GCFA, CISSP, CISM, OSCP, GIAC, or cloud-security certifications.
Why Proofpoint?
  • Competitive compensation
  • Comprehensive benefits
  • Career success on your terms
  • Flexible work environment
  • Annual wellness and community outreach days
  • Always on recognition for your contributions
  • Global collaboration and networking opportunities

Our Culture:Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone.

We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to accessibility@proofpoint.com.

Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and/or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.

  • Base Pay Ranges:SF Bay Area, New York City Metro Area:Base Pay Range: 136,200.00 - 214,005.00 USD
  • Base Pay Ranges:California (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska:Base Pay Range: 112,700.00 - 177,100.00 USD
  • Base Pay Ranges:All other cities and states excluding those listed above:Base Pay Range: 101,600.00 - 159,720.00 USD
#J-18808-Ljbffr