1

Security Operations Center Analyst Jobs in Tulsa, OK

Security Operations Engineer

Tulsa, OK · On-site

$120 - $160/hr

The Security Operations Engineer is the operational backbone of the Security Operations Centre (SOC ... analyst time‑to‑context * Document automation logic and maintain version control for all ...

Security Analyst III

Tulsa, OK · On-site

$143 - $215/hr

Partner with Security Operations Center, Engineering, and IT teams to translate offensive security ... analytics platforms. Measure detection coverage through threat hunting and automated validation.

Partner with Security Operations Center, Engineering, and IT teams to translate offensive security ... analytics platforms. Measure detection coverage through threat hunting and automated validation.

Sustainable operations. Environmentally responsible. Employee focused. JOB SUMMARY The Security Analyst III serves as a senior technical contributor within the Enterprise Security Tools ...

Sustainable operations. Environmentally responsible. Employee focused. JOB SUMMARY The Security Analyst III serves as a senior technical contributor within the Enterprise Security Tools ...

... analyst role. You'll help drive the day-to-day execution of SageNet's information security program ... Our U.S.-based Network Operations Centers operate 24/7, and our national field force delivers ...

... analyst role. You'll help drive the day-to-day execution of SageNet's information security program ... Our U.S.-based Network Operations Centers operate 24/7, and our national field force delivers ...

... analyst role. You'll help drive the day-to-day execution of SageNet's information security program ... Our U.S.-based Network Operations Centers operate 24/7, and our national field force delivers ...

... Dylan Center, Tulsa Artists Fellowship offices and studios, and any other property that may be ... Monitor shift operations and work to resolve problems as they arise. Delegate specific tasks to ...

... Dylan Center, Tulsa Artists Fellowship offices and studios, and any other property that may be ... Monitor shift operations and work to resolve problems as they arise. Delegate specific tasks to ...

... Dylan Center, Tulsa Artists Fellowship offices and studios, and any other property that may be ... Monitor shift operations and work to resolve problems as they arise. Delegate specific tasks to ...

... Dylan Center, Tulsa Artists Fellowship offices and studios, and any other property that may be ... Monitor shift operations and work to resolve problems as they arise. Delegate specific tasks to ...

... Dylan Center, Tulsa Artists Fellowship offices and studios, and any other property that may be ... Monitor shift operations and work to resolve problems as they arise. Delegate specific tasks to ...

... Dylan Center, Tulsa Artists Fellowship offices and studios, and any other property that may be ... Monitor shift operations and work to resolve problems as they arise. Delegate specific tasks to ...

... Dylan Center, Tulsa Artists Fellowship offices and studios, and any other property that may be ... Monitor shift operations and work to resolve problems as they arise. Delegate specific tasks to ...

Learns to analyze inventory trends and supervises inventory management. Verifies proper standard ... Security Operations Center. * Complies with all company policies and procedures; maintains ...

Learns to analyze inventory trends and supervises inventory management. Verifies proper standard ... Security Operations Center. * Complies with all company policies and procedures; maintains ...

next page

Showing results 1-20

Security Operations Center Analyst information

See Tulsa, OK salary details

$15

$33

$64

How much do security operations center analyst jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for security operations center analyst in Tulsa, OK is $33.67, according to ZipRecruiter salary data. Most workers in this role earn between $20.62 and $39.95 per hour, depending on experience, location, and employer.

What is a security operations center analyst?

Security Operations Center (SOC) Analysts are cybersecurity professionals who monitor, detect, and respond to security threats within an organization’s IT environment. They analyze security alerts, investigate incidents, and coordinate responses to mitigate risks and protect sensitive data. SOC Analysts use specialized tools to track suspicious activities, implement security measures, and ensure compliance with security policies. Their work is crucial in defending organizations against cyberattacks and maintaining overall information security.

What does a security operations center analyst do?

A security operations center analyst works on the cybersecurity team at an organization to proactively defend the organization's database, website, servers, and network. In this role you control the security alerts and ensure that each alert is taken care of before the threat of hackers gaining access to your company's information is realized. You may run an investigation if you see similar threats repeatedly to see who is attempting to attack your systems and why. Your other duties may include keeping and analyzing a security log, coordinating with other analysts or security team members, and assessing company vulnerability.

What skills make an effective security operations center analyst?

To thrive as a Security Operations Center Analyst, you need a strong understanding of cybersecurity principles, network protocols, and incident response, often backed by a relevant degree or certifications like CompTIA Security+ or CISSP. Familiarity with SIEM tools (e.g., Splunk, QRadar), intrusion detection systems, and ticketing platforms is essential for effective monitoring and analysis. Attention to detail, analytical thinking, and clear communication help SOC Analysts excel in identifying threats and collaborating with IT teams. These skills are crucial to quickly detecting, investigating, and mitigating security incidents, protecting organizational assets from cyber threats.

What are the most common challenges security operations center analysts face during daily operations?

Security Operations Center (SOC) Analysts often deal with a high volume of alerts, many of which may be false positives, requiring keen analytical skills to prioritize genuine threats. Staying updated on evolving cyber threats and attack patterns is another challenge, as adversaries continuously adapt their tactics. Additionally, SOC Analysts frequently work in high-pressure environments where quick, accurate decision-making is crucial, and collaboration with IT, incident response teams, and management is essential to ensure coordinated defense efforts.

What is the difference between Security Operations Center Analyst vs Security Analyst?

AspectSecurity Operations Center AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CISA (preferred)
Work EnvironmentMonitoring security alerts in a SOC, 24/7 shiftsAnalyzing security data, conducting risk assessments
Employer & Industry UsagePrimarily in security operations centers, cybersecurity firmsVarious industries including finance, healthcare, government

The Security Operations Center Analyst focuses on real-time monitoring and incident response within a SOC environment, often working in shifts. In contrast, a Security Analyst typically conducts broader security assessments, policy development, and risk analysis across organizations. Both roles require similar certifications and are integral to cybersecurity teams, but their daily tasks and work settings differ.

What are popular job titles related to Security Operations Center Analyst jobs in Tulsa, OK?

For Security Operations Center Analyst jobs in Tulsa, OK, the most frequently searched job titles are:

What job categories do people searching Security Operations Center Analyst jobs in Tulsa, OK look for?

The top searched job categories for Security Operations Center Analyst jobs in Tulsa, OK are:

What cities near Tulsa, OK are hiring for Security Operations Center Analyst jobs?

Cities near Tulsa, OK with the most Security Operations Center Analyst job openings:

Infographic showing various Security Operations Center Analyst job openings in Tulsa, OK as of August 2026, with employment types broken down into 94% Full Time, and 6% Contract. Highlights an 80% In-person, 6% Hybrid, and 14% Remote job distribution, with an average salary of $70,033 per year, or $33.7 per hour.

Security Operations Engineer

Yellow Card

Tulsa, OK • On-site

$120 - $160/hr

Other

Medical

Posted 5 days ago


Key responsibilities

  • Own the full lifecycle of security detection and response inside the SOC, including alert design, triaging, and automated containment.

  • Manage cloud security posture by triaging vulnerabilities, reviewing IAM policies, and overseeing configuration and change management in AWS EKS and serverless environments.

  • Build, maintain, and improve automated response workflows (SOAR) to reduce manual effort and enhance security alert handling.


Job description

Who We Are

Yellow Card is the largest licensed Stablecoin-based infrastructure provider operating across over 60 countries. From Stablecoin payment infrastructure to fiat settlement rails, wallet services, and custom local Stablecoin issuance, Yellow Card provides the complete infrastructure businesses need to manage Stablecoins, payments, and operations across 50 emerging markets.

Yellow Card operates with a substantial global team spanning 24 countries. This workforce is characterized by its linguistic diversity, with collective speaking of over 25 languages, underscoring the company’s extensive international reach.

The Security Operations Engineer is the operational backbone of the Security Operations Centre (SOC). It is a fully remote, hands‑on, technical role that owns three tightly integrated domains: security alert design, triaging, and automated response; cloud security posture management across EKS and AWS environments; and posture tracking and reporting.

Reporting to the Associate Director, Product & Infrastructure Security, the engineer works alongside a mature Application Security team and collaborates closely with DevOps, Engineering, and Security GRC functions. The role sits within the First Line of Defense and is expected to progressively drive down manual effort through detection‑as‑code and SOAR automation.

This is not a perimeter‑security or scan‑and‑report role. The right candidate must be comfortable writing detection logic, triaging cloud misconfigurations at the infrastructure level, and owning end‑to‑end vulnerability remediation cycles in containerised environments.

What You'll Do 1. Security Operations

The engineer owns the full lifecycle of security detection and response inside the SOC, from signal design through to automated containment. This is the primary domain of the role.

Alert design and coverage
  • Design and maintain SIEM detection rules covering cloud, container, identity, and application layers, using both signature‑based and behavioural logic
  • Map detection coverage against the MITRE ATT&CK framework and identify gaps relevant to the organisation's AWS and EKS attack surface
  • Integrate threat intelligence feeds to refresh rule logic for emerging threats and TTPs
  • Maintain a detection backlog, prioritised by risk, with defined review cadences
Alert triage
  • Daily SIEM alert triage following defined response timing standard
  • Classify, investigate, and resolve security signals;
  • Reduce false‑positive rates through structured tuning cycles, with documented rationale for rule changes
  • Maintain triage runbooks for key production detection rules
Automated response workflows (SOAR)
  • Build and maintain SOAR playbooks for common alert types including IAM anomalies, misconfiguration alerts, exposed secrets, and container runtime events
  • Automate enrichment steps (asset lookup, threat intel correlation, ownership resolution) to reduce analyst time‑to‑context
  • Document automation logic and maintain version control for all playbooks
  • Measure and report automation coverage rate as a standing KRI
2. Cloud Security Posture Management

Cloud posture management is the infrastructure‑facing domain of the role, covering vulnerability management, identity governance, and configuration and change control. AWS EKS and Serverless resources are the primary environments.

Vulnerability management
  • Own the end‑to‑end vulnerability triage process for cloud and container environments, prioritising findings by business impact using CVSS scoring, asset criticality, and exploitability context
  • Manage EKS‑specific vulnerability coverage: base image currency, workload scanning results, pod security standards compliance, and node group patching cadence
  • Coordinate remediation with engineering teams by opening well‑scoped tickets, tracking progress, and escalating SLA breaches
  • Maintain MTTR and SLA compliance data by severity tier
  • Oversee CSPM posture score targets; triage new Critical findings within defined SLA windows
Identity and access governance
  • Review and approve IAM policy changes, enforcing least‑privilege and flagging over‑permissioned roles or service accounts
  • Execute scheduled IAM hygiene reviews: unused credentials, stale access keys, overly broad policies, and cross‑account trust boundaries
  • Govern workload identity configurations in EKS, ensuring service accounts carry only the permissions required
  • Support the secrets rotation program and enforce zero hardcoded credentials across the estate
Configuration and change management
  • Review and approve cloud network security changes: security group modifications, network ACL changes, and routing updates
  • Own container image security: base image update cadence, scanning results review, and image ownership classification
  • Investigate and remediate misconfiguration alerts surfaced by CSPM tooling within defined SLA windows
  • Maintain a configuration baseline for critical cloud resources and flag drift
3. Posture Tracking and Reporting

The engineer is the primary data owner for security posture metrics across both SOC and cloud domains. Reporting outputs feed executive dashboards, GRC compliance evidence, and quarterly risk reviews.

KRI data collection
  • Collect and maintain Key Risk Indicator data across all three KRA domains on defined cadences
  • SOC KRIs: MTTA (Mean Time to Acknowledge), MTTR, false‑positive rate, automation coverage rate, detection coverage score
  • VM KRIs: Critical/High finding counts, SLA compliance rate by severity, MTTR by tier, overdue remediation count
  • Posture KRIs: CSPM score, under‑protected asset count, misconfiguration closure rate, IAM hygiene score, log source coverage
Recurring control reviews
  • Execute infrastructure security control checks on weekly (CSPM critical findings), monthly (IAM hygiene, secrets rotation status), and quarterly (posture benchmark, detection coverage review) cadences
  • Produce structured findings reports for each review cycle, flagging control failures for escalation
Reporting
  • Provide SOC and cloud posture metrics, including trends, at the required reporting cycles
  • Support external audit and due diligence processes by providing evidence artefacts
4. Others
  • Co‑own the shared vulnerability backlog (infrastructure side) with the Application Security team, ensuring consistent prioritisation methodology across domains
  • Serve as the infrastructure and identity SME for the AppSec team during application security assessments and architecture reviews
  • Own infrastructure containment during incidents that span application and infrastructure layers, working alongside AppSec for root cause analysis
  • Provide infrastructure, identity, and network security review for new third‑party integrations prior to deployment
  • Collaborate with the Security GRC function on control evidence and compliance mapping, particularly for SOC 2, ISO 27001, and GDPR requirements
What You'll Bring
  • Fluency in English, both written and verbal
  • Ability to collaborate with cross‑functional teams and across different time zones
  • 3 to 5 years of experience in security operations, cloud security, or infrastructure security engineering
  • Hands‑on AWS security experience: IAM policy design, virtual network architecture, cloud‑native security services, CloudTrail, GuardDuty
  • Kubernetes and EKS security experience: pod security standards, network policy enforcement, workload identity, image scanning
  • SIEM operations: alert triage, detection rule authoring (signature‑based and behavioural), log analysis and correlation
  • Vulnerability management: CSPM tooling, risk‑based prioritisation, CVSS scoring, SLA framework operation
  • IaC security: ability to read and review Terraform or CloudFormation for misconfigurations
  • Incident response: investigation, containment, and post‑incident reporting
  • Experience in a regulated environment (FinTech, payments, banking, or crypto preferred)
  • Ability to author and tune detection rules without relying on vendor‑supplied defaults
  • Structured written communication for triage reports, post‑incident write‑ups, and stakeholder metrics
  • Ability to coordinate remediation across engineering teams without direct authority
  • Comfort operating in a lean team where domain boundaries are broader than in large enterprise security functions
  • Professional certifications: AWS Security Specialty (highly valued)
  • Experience with CSPM and SIEM platforms: Datadog, Wiz, Orca Security
  • Experience with secrets management platforms: AWS Secrets Manager
  • Familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, DORA
  • Scripting ability in Python or Bash for detection‑as‑code and operational automation
  • Experience with SOAR or workflow automation platforms
  • Understanding of cryptocurrency or blockchain security considerations
  • Experience in a startup or scale‑up environment
  • AI tooling familiarity and interest in applying AI to operational workflows
What We Offer
  • Compensation & Benefits: We offer competitive compensation and meaningful health coverage, and all full‑time employees are participants in our stock option plan.
  • Learning & Development: Access to resources, support, and autonomy to grow professionally.
  • Remote‑First Flexibility: We embrace a fully remote work environment.
  • Regulated, multi‑geography environment with real‑world impact on financial inclusion
  • Mental Health Support Services: Your mental well‑being matters to us.
  • Ownership of the SOC and cloud security posture function from day one, in a high‑growth FinTech environment
  • Broad domain exposure: detection engineering, cloud security, container security, incident response, and compliance
  • Collaborative team culture with a mature AppSec function and strong leadership support
#J-18808-Ljbffr