1

Security Operations Center Analyst Jobs in Austin, TX

We are seeking a highly motivated Security Operations Center Analyst to join our SOC Team. This team is responsible for validating alerts, investigating suspicious activity, performing initial threat ...

We are seeking a highly motivated Security Operations Center Analyst to join our SOC Team. This team is responsible for validating alerts, investigating suspicious activity, performing initial threat ...

New

Security Operations Center (SOC) Analyst** to join our growing U.S. Managed Detection and Response team in Austin, Texas.This is an exciting opportunity to help build Sygnia's first U.S. MDR site as ...

... oversee $24/7/365$ cybersecurity operations supporting the Data Center Services (DCS ... Proven experience in managing security for multi-cloud environments (Public/Private Cloud) and ...

## Security Operations SpecialistApplylocations: Austin, TX (HQ)time type: Full timeposted on: Posted ... Our footprint consists of 11 data center campuses across seven states, housing advanced ...

next page

Showing results 1-20

Security Operations Center Analyst information

See Austin, TX salary details

$17

$36

$70

How much do security operations center analyst jobs pay per hour?

As of Sep 7, 2026, the average hourly pay for security operations center analyst in Austin, TX is $36.54, according to ZipRecruiter salary data. Most workers in this role earn between $22.40 and $43.37 per hour, depending on experience, location, and employer.

What is a security operations center analyst?

Security Operations Center (SOC) Analysts are cybersecurity professionals who monitor, detect, and respond to security threats within an organization’s IT environment. They analyze security alerts, investigate incidents, and coordinate responses to mitigate risks and protect sensitive data. SOC Analysts use specialized tools to track suspicious activities, implement security measures, and ensure compliance with security policies. Their work is crucial in defending organizations against cyberattacks and maintaining overall information security.

What does a security operations center analyst do?

A security operations center analyst works on the cybersecurity team at an organization to proactively defend the organization's database, website, servers, and network. In this role you control the security alerts and ensure that each alert is taken care of before the threat of hackers gaining access to your company's information is realized. You may run an investigation if you see similar threats repeatedly to see who is attempting to attack your systems and why. Your other duties may include keeping and analyzing a security log, coordinating with other analysts or security team members, and assessing company vulnerability.

What skills make an effective security operations center analyst?

To thrive as a Security Operations Center Analyst, you need a strong understanding of cybersecurity principles, network protocols, and incident response, often backed by a relevant degree or certifications like CompTIA Security+ or CISSP. Familiarity with SIEM tools (e.g., Splunk, QRadar), intrusion detection systems, and ticketing platforms is essential for effective monitoring and analysis. Attention to detail, analytical thinking, and clear communication help SOC Analysts excel in identifying threats and collaborating with IT teams. These skills are crucial to quickly detecting, investigating, and mitigating security incidents, protecting organizational assets from cyber threats.

What are the most common challenges security operations center analysts face during daily operations?

Security Operations Center (SOC) Analysts often deal with a high volume of alerts, many of which may be false positives, requiring keen analytical skills to prioritize genuine threats. Staying updated on evolving cyber threats and attack patterns is another challenge, as adversaries continuously adapt their tactics. Additionally, SOC Analysts frequently work in high-pressure environments where quick, accurate decision-making is crucial, and collaboration with IT, incident response teams, and management is essential to ensure coordinated defense efforts.

What is the difference between Security Operations Center Analyst vs Security Analyst?

AspectSecurity Operations Center AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CISA (preferred)
Work EnvironmentMonitoring security alerts in a SOC, 24/7 shiftsAnalyzing security data, conducting risk assessments
Employer & Industry UsagePrimarily in security operations centers, cybersecurity firmsVarious industries including finance, healthcare, government

The Security Operations Center Analyst focuses on real-time monitoring and incident response within a SOC environment, often working in shifts. In contrast, a Security Analyst typically conducts broader security assessments, policy development, and risk analysis across organizations. Both roles require similar certifications and are integral to cybersecurity teams, but their daily tasks and work settings differ.

What are the most commonly searched types of Security Operations Center Analyst jobs in Austin, TX?

The most popular types of Security Operations Center Analyst jobs in Austin, TX are:

What are popular job titles related to Security Operations Center Analyst jobs in Austin, TX?

For Security Operations Center Analyst jobs in Austin, TX, the most frequently searched job titles are:

What job categories do people searching Security Operations Center Analyst jobs in Austin, TX look for?

The top searched job categories for Security Operations Center Analyst jobs in Austin, TX are:

What cities near Austin, TX are hiring for Security Operations Center Analyst jobs?

Cities near Austin, TX with the most Security Operations Center Analyst job openings:

Infographic showing various Security Operations Center Analyst job openings in Austin, TX as of August 2026, with employment types broken down into 94% Full Time, and 6% Contract. Highlights an 80% In-person, 6% Hybrid, and 14% Remote job distribution, with an average salary of $76,001 per year, or $36.5 per hour.

Security Operations Center Analyst

IBM

Austin, TX • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


IBM rating

8.0

Company rating: 8.0 out of 10

Based on 76 frontline employees who took The Breakroom Quiz

125th of 247 rated software companies


Job description

Introduction
The Office of the CISO is responsible for protecting IBM's systems, data, and global operations from cybersecurity threats. Our organization encompasses the full spectrum of cyber defense capabilities, including Threat Detection, Security Operations, Incident Response, Vulnerability Management, Endpoint Security, Product Security, Cloud Security, and Security Engineering.
The Security Operations Center (SOC) serves as the front line of IBM's cyber defense mission. Operating 24x7 across a global environment, the SOC detects, analyzes, and responds to security events affecting IBM's users, devices, applications, and infrastructure.
We are seeking a highly motivated Security Operations Center Analyst to join our SOC Team. This team is responsible for validating alerts, investigating suspicious activity, performing initial threat containment, and escalating confirmed security incidents. Successful candidates will possess a strong security operations mindset, excellent analytical skills, and the ability to make sound decisions in fast-paced operational environments.
Your role and responsibilities
As a SOC Analyst, you will serve as a first responder to cybersecurity threats, helping protect IBM's global enterprise by identifying, investigating, and containing malicious activity before it becomes a significant incident.
You will work closely with threat detection engineers, incident responders, security operations teams, and business stakeholders to assess security alerts, determine risk and impact, and take appropriate response actions.
This role requires strong investigative instincts, technical troubleshooting skills, and the ability to communicate findings clearly to both technical and non-technical audiences.
Key Responsibilities
  • Monitor and investigate security alerts generated from SIEM, EDR, email security, cloud security, and network security platforms
  • Perform triage and analysis of security events to determine legitimacy, severity, scope, and impact
  • Execute approved containment actions, including host isolation, account restrictions, malicious email remediation, and blocking indicators of compromise
  • Escalate confirmed or high-risk incidents while providing complete investigative context and supporting evidence
  • Analyze endpoint, network, identity, cloud, and application telemetry to identify malicious activity
  • Correlate data from multiple security technologies to investigate complex security events
  • Document investigations, containment actions, and recommendations in accordance with operational procedures
  • Participate in incident response activities and support post-incident reviews as needed
  • Continuously improve detection and triage processes through operational feedback and collaboration with engineering teams
  • Maintain awareness of emerging threats, attacker tactics, techniques, and procedures (TTPs), and industry trends
  • Contribute to operational readiness by assisting with playbook development, process improvement, and knowledge sharing

Required education
Associate's Degree/College Diploma
Preferred education
Bachelor's Degree
Required technical and professional expertise
  • Experience in a Security Operations Center (SOC), Cybersecurity Operations, Incident Response, or related cybersecurity role
  • Experience investigating and triaging security alerts in a large enterprise environment
  • Experience using EDR platforms
  • Experience working with SIEM platforms and log analysis technologies
  • Understanding of common cyber threats, attacker methodologies, and MITRE ATT&CK techniques
  • Experience performing threat containment actions and supporting incident response activities
  • Strong analytical and problem-solving skills with attention to detail
  • Experience analyzing endpoint, identity, email, network, and cloud-based security events
  • Knowledge of Windows, Linux, macOS, Active Directory, Entra ID, and enterprise authentication technologies
  • Working knowledge of networking fundamentals including DNS, TCP/IP, HTTP/S, firewalls, proxies, VPNs, and IDS/IPS technologies
  • Ability to assess risk and prioritize multiple investigations simultaneously in a fast-paced operational environment
  • Strong verbal communication, technical writing, and incident documentation skills
  • Ability to work independently while collaborating effectively across global teams

Key Technical Skills
  • Security Alert Triage and Investigation
  • Event Correlation and Threat Analysis
  • Endpoint Detection and Response (EDR)
  • Security Information and Event Management (SIEM)
  • Account Compromise Investigation
  • Phishing and Business Email Compromise Analysis
  • Threat Containment and Remediation
  • Log Analysis and Query Development
  • Threat Intelligence Utilization
  • Incident Documentation and Case Management

Preferred technical and professional experience
  • Experience working within an enterprise SOC supporting global operations
  • Experience using QRadar, Splunk, Sentinel, Elastic, or similar SIEM platforms
  • Experience with CrowdStrike Falcon and/or Microsoft Defender XDR
  • Familiarity with cloud security monitoring in AWS, Azure, IBM Cloud, or GCP environments
  • Experience performing threat hunting activities
  • Knowledge of identity-based attacks and Entra ID / Active Directory investigations
  • Understanding of malware behavior and attacker TTPs
  • Experience developing detections, use cases, or automation workflows
  • Basic scripting skills using Python, PowerShell, KQL, or similar technologies
  • Experience supporting incident response engagements or working closely with a CSIRT organization
  • Cybersecurity certifications such as Security+, CySA+, GCIH, GCIA, GCED, SC-200, SC-300, or equivalent experience

ABOUT BUSINESS UNIT
IBM Systems helps IT leaders think differently about their infrastructure. IBM servers and storage are no longer inanimate - they can understand, reason, and learn so our clients can innovate while avoiding IT issues. Our systems power the world's most important industries and our clients are the architects of the future. Join us to help build our leading-edge technology portfolio designed for cognitive business and optimized for cloud computing.
YOUR LIFE @ IBM
In a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.
Being an IBMer means you'll be able to learn and develop yourself and your career, you'll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.
Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.
Are you ready to be an IBMer?
ABOUT IBM
IBM's greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.
Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we're also one of the biggest technology and consulting employers, with many of the Fortune 500 companies relying on the IBM Cloud to run their business.
At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it's time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.
IBM is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
OTHER RELEVANT JOB DETAILS
IBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:
- Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
- Financial programs such as 401(k), cash balance pension plan, the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
- Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs. IBM also offers paid family leave benefits to eligible employees where required by applicable law
- Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
- Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences
We consider qualified applicants with criminal histories, consistent with applicable law.
This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role.
IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship.
The compensation range and benefits for this position are based on a full-time schedule for a full calendar year. The salary will vary depending on your job-related skills, experience and location. Pay increment and frequency of pay will be in accordance with employment classification and applicable laws. For part time roles, your compensation and benefits will be adjusted to reflect your hours. Benefits may be pro-rated for those who start working during the calendar year.

What IBM employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


IBM logo

About IBM

Sourced by ZipRecruiter

At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most challenging problems? If so, lets talk.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Armonk, NY, US

Year founded

1911

Social media