1

Security Operations Center Analyst Jobs in Austin, TX

... oversee $24/7/365$ cybersecurity operations supporting the Data Center Services (DCS ... Proven experience in managing security for multi-cloud environments (Public/Private Cloud) and ...

## Security Operations SpecialistApplylocations: Austin, TX (HQ)time type: Full timeposted on: Posted ... Our footprint consists of 11 data center campuses across seven states, housing advanced ...

Required Skills: * 5 Years of Experience performing cyber threat intelligence analysis within a Security Operations Center (SOC) or Cybersecurity Operations environment * 5 Years of Experience with ...

next page

Showing results 1-20

Security Operations Center Analyst information

See Austin, TX salary details

$17

$36

$70

How much do security operations center analyst jobs pay per hour?

As of Aug 24, 2026, the average hourly pay for security operations center analyst in Austin, TX is $36.53, according to ZipRecruiter salary data. Most workers in this role earn between $22.40 and $43.37 per hour, depending on experience, location, and employer.

What is a security operations center analyst?

Security Operations Center (SOC) Analysts are cybersecurity professionals who monitor, detect, and respond to security threats within an organization’s IT environment. They analyze security alerts, investigate incidents, and coordinate responses to mitigate risks and protect sensitive data. SOC Analysts use specialized tools to track suspicious activities, implement security measures, and ensure compliance with security policies. Their work is crucial in defending organizations against cyberattacks and maintaining overall information security.

What does a security operations center analyst do?

A security operations center analyst works on the cybersecurity team at an organization to proactively defend the organization's database, website, servers, and network. In this role you control the security alerts and ensure that each alert is taken care of before the threat of hackers gaining access to your company's information is realized. You may run an investigation if you see similar threats repeatedly to see who is attempting to attack your systems and why. Your other duties may include keeping and analyzing a security log, coordinating with other analysts or security team members, and assessing company vulnerability.

What skills make an effective security operations center analyst?

To thrive as a Security Operations Center Analyst, you need a strong understanding of cybersecurity principles, network protocols, and incident response, often backed by a relevant degree or certifications like CompTIA Security+ or CISSP. Familiarity with SIEM tools (e.g., Splunk, QRadar), intrusion detection systems, and ticketing platforms is essential for effective monitoring and analysis. Attention to detail, analytical thinking, and clear communication help SOC Analysts excel in identifying threats and collaborating with IT teams. These skills are crucial to quickly detecting, investigating, and mitigating security incidents, protecting organizational assets from cyber threats.

What are the most common challenges security operations center analysts face during daily operations?

Security Operations Center (SOC) Analysts often deal with a high volume of alerts, many of which may be false positives, requiring keen analytical skills to prioritize genuine threats. Staying updated on evolving cyber threats and attack patterns is another challenge, as adversaries continuously adapt their tactics. Additionally, SOC Analysts frequently work in high-pressure environments where quick, accurate decision-making is crucial, and collaboration with IT, incident response teams, and management is essential to ensure coordinated defense efforts.

What is the difference between Security Operations Center Analyst vs Security Analyst?

AspectSecurity Operations Center AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CISA (preferred)
Work EnvironmentMonitoring security alerts in a SOC, 24/7 shiftsAnalyzing security data, conducting risk assessments
Employer & Industry UsagePrimarily in security operations centers, cybersecurity firmsVarious industries including finance, healthcare, government

The Security Operations Center Analyst focuses on real-time monitoring and incident response within a SOC environment, often working in shifts. In contrast, a Security Analyst typically conducts broader security assessments, policy development, and risk analysis across organizations. Both roles require similar certifications and are integral to cybersecurity teams, but their daily tasks and work settings differ.

What are the most commonly searched types of Security Operations Center Analyst jobs in Austin, TX?

The most popular types of Security Operations Center Analyst jobs in Austin, TX are:

What are popular job titles related to Security Operations Center Analyst jobs in Austin, TX?

For Security Operations Center Analyst jobs in Austin, TX, the most frequently searched job titles are:

What job categories do people searching Security Operations Center Analyst jobs in Austin, TX look for?

The top searched job categories for Security Operations Center Analyst jobs in Austin, TX are:

What cities near Austin, TX are hiring for Security Operations Center Analyst jobs?

Cities near Austin, TX with the most Security Operations Center Analyst job openings:

Infographic showing various Security Operations Center Analyst job openings in Austin, TX as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 11% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $75,983 per year, or $36.5 per hour.

Cybersecurity Operations Center Analyst

Texas Health and Human Services Commission

Austin, TX • On-site

$7.0K - $11K/mo

Full-time

Medical, Retirement, PTO

Posted 4 days ago


Texas Health and Human Services rating

6.9

Company rating: 6.9 out of 10

Based on 33 frontline employees who took The Breakroom Quiz

682nd of 849 rated public administrative organizations


Job description

Join the Texas Health and Human Services Commission (HHSC) and be part of a team committed to creating a positive impact in the lives of fellow Texans. At HHSC, your contributions matter, and we support you at each stage of your life and work journey. Our comprehensive benefits package includes 100% paid employee health insurance for full-time eligible employees, a defined benefit pension plan, generous time off benefits, numerous opportunities for career advancement and more. Explore more details on the Benefits of Working at HHS webpage.
Functional Title: Cybersecurity Operations Center Analyst Job Title: Cybersecurity Analyst III Agency: Health & Human Services Comm Department: CHIEF INFO SECURITY OFFICE Posting Number: 20371 Closing Date: 10/20/2026 Posting Audience: Internal and External Occupational Category: Computer and Mathematical Salary Range: $7,015.16- $11,864.50 Pay Frequency: MonthlySalary Group: TEXAS-B-27 Shift: Day Additional Shift: Days (First) Telework: Travel: Regular/Temporary: Regular Full Time/Part Time: Full time FLSA Exempt/Non-Exempt: Exempt Facility Location: Job Location City: AUSTIN Job Location Address: 701 W 51ST ST Other Locations: MOS Codes: 0605,0630,0631,0639,0670,0679,0681,1702,1705,1710,1720,1721,1799,2611,2659,8055,8858,14N,14NX,170A
170B,17A,17B,17C,17C0,17DX,17S,17SX,17X,181X,182X,183X,184X,1B4X1,1D7X1,1N4X1,255A,255N,255S,25B,25D
26A,26B,26Z,514A,5C0X1D,5C0X1N,5C0X1R,5C0X1S,5IX,681X,682X,683X,781X,782X,783X,784X,CTI,CTM,CTR,CWT
CYB10,CYB11,CYB12,CYB13,CYB14,IS,ISM,ISS,IT,ITS
Brief Job Description:
This position is open to U.S. Citizens and permanent residents.
This onsite role requires the selected candidate to work from an HHS office in Austin, Texas.
The Cybersecurity Analyst III performs senior-level cybersecurity operations work with emphasis on threat detection, incident investigation, security monitoring, cyber defense, and operational response activities. The role supports agency on-premises and cloud environments by identifying, analyzing, investigating, and responding to cybersecurity threats impacting agency systems, applications, hosts, networks, cloud services, and data.
The Cybersecurity Operations Center (CSOC) Analyst is responsible for monitoring enterprise security operations and coordinating the detection and response of cybersecurity incidents. This position provides senior-level expertise in threat analysis, incident triage, threat intelligence, security monitoring, and cyber defense operations. The analyst leverages advanced security technologies and investigative methodologies to identify malicious activity, assess risk, and coordinate containment and remediation activities.
The CSOC Analyst develops and maintains awareness of the agency's cybersecurity threat landscape, evaluates emerging threats and attack techniques, and supports the implementation of strategies that strengthen the agency's security posture. This position serves as a critical operational resource in protecting agency systems and data while ensuring that cybersecurity monitoring, detection, and response activities align with agency security objectives, State of Texas requirements, and industry best practices.
This position performs highly complex information security and cybersecurity analysis work. The Analyst works under limited supervision with considerable latitude for the use of initiative and independent judgment. The Analyst will research and implement new threat detection methodologies, monitoring capabilities, investigative techniques, and response strategies for the prevention, detection, containment, and remediation of cybersecurity incidents.
The Analyst provides expert guidance regarding cybersecurity threats, incident response procedures, threat intelligence findings, and emerging risks. This role partners closely with security engineering, vulnerability management, system administration, cloud operations, and application support teams to strengthen organizational cyber resilience.
Essential Job Functions (EJFs):
Attends work on a regular and predictable schedule following agency leave policy and performs other duties as assigned.
Security Monitoring & Incident Detection - 35%
  • Monitors security events and alerts generated through Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR/XDR), identity security, cloud security, email security, vulnerability management, and network security platforms.
  • Performs initial triage and analysis of cybersecurity alerts to determine severity, scope, impact, and potential organizational risk.
  • Reviews indicators of compromise (IOCs), indicators of attack (IOAs), anomalous user activity, threat intelligence information, phishing campaigns, malware activity, and suspicious network behavior.
  • Correlates events from multiple security technologies to identify attack patterns and potential cybersecurity incidents.
  • Evaluates detection effectiveness and recommends improvements to monitoring capabilities and alert fidelity.

Incident Response & Investigation - 30%
  • Leads and conducts investigations of cybersecurity events and incidents.
  • Coordinates response activities with Incident Response, Security Engineering, Infrastructure Services, Cloud Operations, and other support teams.
  • Assists with incident containment, eradication, recovery, and post-incident review activities.
  • Documents investigations, findings, recommendations, lessons learned, and response actions.
  • Supports forensic investigations and evidence preservation activities as appropriate.

Threat Intelligence & Threat Hunting - 15%
  • Researches emerging cyber threats, adversary tactics, techniques, and procedures (TTPs), and industry threat trends.
  • Performs threat hunting activities across enterprise systems and cloud environments to identify previously undetected threats.
  • Leverages commercial, industry, government, and open-source threat intelligence to enhance detection and response capabilities.
  • Develops recommendations for improving agency visibility into emerging threats.

Security Operations Improvement & Collaboration - 10%
  • Supports development and tuning of detection use cases, analytics, dashboards, workflows, reports, and operational procedures.
  • Collaborates with security engineering teams to improve monitoring coverage and telemetry collection.
  • Assists with tabletop exercises, incident simulations, adversary emulation, operational readiness activities, and continuous improvement initiatives.
  • Provides input into cybersecurity strategy and operational enhancements.

Other Duties - 10%
  • Performs additional cybersecurity operations activities as assigned, including special projects, process improvement initiatives, operational readiness efforts, reporting activities, audit support, and agency cybersecurity initiatives.

Knowledge, Skills and Abilities (KSAs):
Knowledge of:
  • Security Operations Center methodologies, operations, and best practices.
  • Incident response concepts, procedures, and investigation techniques.
  • Enterprise cybersecurity technologies including SIEM, EDR/XDR, IDS/IPS, NDR, NGFW, SOAR, cloud security, email security, identity protection, and vulnerability management solutions.
  • Threat intelligence frameworks, MITRE ATT&CK, cyber threat actor behaviors, and attack methodologies.
  • Operating systems, networking protocols, Active Directory, Microsoft Entra ID, cloud computing platforms, and enterprise security architectures.
  • Security and risk management frameworks such as NIST Cybersecurity Framework, NIST 800-61, CIS Controls, and State of Texas cybersecurity requirements (including TAC Chapter 202).

Skill in:
  • Written and verbal communication.
  • Analyzing and solving complex cybersecurity problems.
  • Conducting threat investigations and incident analysis.
  • Correlating security data from diverse sources and technologies.
  • Identifying risk and recommending appropriate response actions.
  • Producing operational reports, technical documentation, and executive summaries.

Ability to:
  • Analyze large volumes of security telemetry and rapidly identify threats.
  • Make sound decisions during cybersecurity investigations and incident response activities.
  • Communicate technical information to both technical and non-technical audiences.
  • Work collaboratively with diverse teams and provide operational cybersecurity guidance.
  • Manage multiple concurrent investigations and priorities in a fast-paced environment.

Registrations, Licensure Requirements or Certifications:
Prefer one or more of the following certifications:
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA CySA+
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Continuous Monitoring Certification (GMON)
  • Certified SOC Analyst (CSA)

Initial Screening Criteria:
  • Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another on a year for year basis.
  • At least 5+ years of experience in information technology, cybersecurity, security operations, detection engineering, systems/network administration, or related disciplines.
  • Experience working in a Security Operations Center (SOC).

Additional Information:
Any employment offer is contingent upon available budgeted funds. The offered salary will be determined in accordance with budgetary limits and the requirements of HHSC Human Resources Manual.
Selected candidates must be legally authorized to work in the U.S. without sponsorship.
Selected candidate must be willing to commute to the office on the required days.
#LI-IN1
Review our Tips for Success when applying for jobs at DFPS, DSHS and HHSC.
Active Duty, Military, Reservists, Guardsmen, and Veterans:
Military occupation(s) that relate to the initial selection criteria and registration or licensure requirements for this position may include, but not limited to those listed in this posting. All active-duty military, reservists, guardsmen, and veterans are encouraged to apply if qualified to fill this position. For more information please see the Texas State Auditor's Job Descriptions, Military Crosswalk and Military Crosswalk Guide at Texas State Auditor's Office - Job Descriptions.
ADA Accommodations:
In compliance with the Americans with Disabilities Act (ADA), HHSC and DSHS agencies will provide reasonable accommodation during the hiring and selection process for qualified individuals with a disability. If you need assistance completing the on-line application, contact the HHS Employee Service Center at 1-888-894-4747. If you are contacted for an interview and need accommodation to participate in the interview process, please notify the person scheduling the interview.
Pre-Employment Checks and Work Eligibility:
Depending on the program area and position requirements, applicants selected for hire may be required to pass background and other due diligence checks.
HHSC uses E-Verify. You must bring your I-9 documentation with you on your first day of work. Download the I-9 Form
Telework Disclaimer:
This position may be eligible for telework. Please note, all HHS positions are subject to state and agency telework policies in addition to the discretion of the direct supervisor and business needs.

What Texas Health and Human Services employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom