1

Security Operations Center Operator Jobs in Austin, TX

The Security Operations Center (SOC) serves as the front line of IBM's cyber defense mission ... Operating 24x7 across a global environment, the SOC detects, analyzes, and responds to security ...

... oversee $24/7/365$ cybersecurity operations supporting the Data Center Services (DCS ... Proven experience in managing security for multi-cloud environments (Public/Private Cloud) and ...

Security Operator 3

Austin, TX

$17.75 - $22/hr

Coordinate with Security leadership and the SpaceX Protective Operations Center (SPOC) as necessary ... Operator responsibilities may vary at each campus in order to ensure the most effective and secure ...

Security Operator 3

Austin, TX · On-site

$17.75 - $22/hr

Coordinate with Security leadership and the SpaceX Protective Operations Center (SPOC) as necessary ... Operator responsibilities may vary at each campus in order to ensure the most effective and secure ...

Global Security Operations Center (GSOC) Lead a High‑Impact Global Security Operations Center As ... Oversee the development, implementation, and continuous improvement of Standard Operating ...

next page

Showing results 1-20

Security Operations Center Operator information

See Austin, TX salary details

$7

$19

$28

How much do security operations center operator jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for security operations center operator in Austin, TX is $19.65, according to ZipRecruiter salary data. Most workers in this role earn between $17.16 and $21.20 per hour, depending on experience, location, and employer.

What does a Security Operations Center Operator do?

As a security operations center operator, or SOC operator, you monitor a variety of technologies including access control, video surveillance, and alarm systems to provide security service and threat elimination for industrial, business, or residential customers. You respond to medical crises, safety incidents, natural disasters and other emergencies, and dispatch security officers, police, fire, EMS personnel, and other services as required. Your duties and responsibilities also include investigating incidents, escalating situations to appropriate parties in the SOC, and filing incident reports. In some roles, you are responsible for monitoring social media and other news and information channels to support threat identification.

What are the key skills and qualifications needed to thrive as a Security Operations Center Operator?

To thrive as a Security Operations Center (SOC) Operator, you need a solid understanding of cybersecurity principles, incident response, and network monitoring, often supported by a relevant degree or certifications like CompTIA Security+ or CEH. Familiarity with security information and event management (SIEM) tools, intrusion detection systems, and ticketing platforms is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and collaborating with teams. These skills are essential to quickly detect, assess, and respond to security incidents, ensuring the organization's information assets remain protected.

What are some common challenges faced by Security Operations Center Operators, and how can they be managed?

SOC Operators often encounter challenges such as managing high volumes of alerts, distinguishing false positives from genuine threats, and maintaining situational awareness during fast-paced incidents. Effective time management, continuous training on new threat vectors, and leveraging automation tools can help address these challenges. Collaborating closely with incident response teams and participating in regular drills also ensures readiness and improves overall team effectiveness.

What is the difference between Security Operations Center Operator vs Security Analyst?

AspectSecurity Operations Center OperatorSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, GIAC certifications
Work EnvironmentMonitoring security systems in a SOC, responding to alertsAnalyzing security data, investigating incidents, reporting
Employer & Industry UsageCommon in cybersecurity firms, large enterprises, government agenciesUsed across industries for threat detection and risk assessment

Security Operations Center (SOC) Operators focus on real-time monitoring and initial response to security alerts, while Security Analysts perform in-depth analysis, investigation, and reporting. Both roles require similar certifications and often work within the same environment, but their responsibilities differ in scope and depth of analysis.

What are popular job titles related to Security Operations Center Operator jobs in Austin, TX?

For Security Operations Center Operator jobs in Austin, TX, the most frequently searched job titles are:

What job categories do people searching Security Operations Center Operator jobs in Austin, TX look for?

The top searched job categories for Security Operations Center Operator jobs in Austin, TX are:

What cities near Austin, TX are hiring for Security Operations Center Operator jobs?

Cities near Austin, TX with the most Security Operations Center Operator job openings:

Infographic showing various Security Operations Center Operator job openings in Austin, TX as of September 2026, with employment types broken down into 1% As Needed, 74% Full Time, 16% Part Time, 7% Temporary, 1% Contract, and 1% Nights. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $40,882 per year, or $19.7 per hour.

Security Operations Center Analyst

Austin, TX • On-site

Other

Posted 4 days ago


Job description

Introduction

The Office of the CISO is responsible for protecting IBM's systems, data, and global operations from cybersecurity threats. Our organization encompasses the full spectrum of cyber defense capabilities, including Threat Detection, Security Operations, Incident Response, Vulnerability Management, Endpoint Security, Product Security, Cloud Security, and Security Engineering.

The Security Operations Center (SOC) serves as the front line of IBM's cyber defense mission. Operating 24x7 across a global environment, the SOC detects, analyzes, and responds to security events affecting IBM's users, devices, applications, and infrastructure.

We are seeking a highly motivated Security Operations Center Analyst to join our SOC Team. This team is responsible for validating alerts, investigating suspicious activity, performing initial threat containment, and escalating confirmed security incidents. Successful candidates will possess a strong security operations mindset, excellent analytical skills, and the ability to make sound decisions in fast-paced operational environments.

Your role and responsibilities

As a SOC Analyst, you will serve as a first responder to cybersecurity threats, helping protect IBM's global enterprise by identifying, investigating, and containing malicious activity before it becomes a significant incident.

You will work closely with threat detection engineers, incident responders, security operations teams, and business stakeholders to assess security alerts, determine risk and impact, and take appropriate response actions.

This role requires strong investigative instincts, technical troubleshooting skills, and the ability to communicate findings clearly to both technical and non-technical audiences.

Key Responsibilities
  • Monitor and investigate security alerts generated from SIEM, EDR, email security, cloud security, and network security platforms
  • Perform triage and analysis of security events to determine legitimacy, severity, scope, and impact
  • Execute approved containment actions, including host isolation, account restrictions, malicious email remediation, and blocking indicators of compromise
  • Escalate confirmed or high-risk incidents while providing complete investigative context and supporting evidence
  • Analyze endpoint, network, identity, cloud, and application telemetry to identify malicious activity
  • Correlate data from multiple security technologies to investigate complex security events
  • Document investigations, containment actions, and recommendations in accordance with operational procedures
  • Participate in incident response activities and support post-incident reviews as needed
  • Continuously improve detection and triage processes through operational feedback and collaboration with engineering teams
  • Maintain awareness of emerging threats, attacker tactics, techniques, and procedures (TTPs), and industry trends
  • Contribute to operational readiness by assisting with playbook development, process improvement, and knowledge sharing
Key Technical Skills
  • Security Alert Triage and Investigation
  • Event Correlation and Threat Analysis
  • Endpoint Detection and Response (EDR)
  • Security Information and Event Management (SIEM)
  • Account Compromise Investigation
  • Phishing and Business Email Compromise Analysis
  • Threat Containment and Remediation
  • Log Analysis and Query Development
  • Threat Intelligence Utilization
  • Incident Documentation and Case Management
Required technical and professional expertise
  • Experience in a Security Operations Center (SOC), Cybersecurity Operations, Incident Response, or related cybersecurity role
  • Experience investigating and triaging security alerts in a large enterprise environment
  • Experience using EDR platforms
  • Experience working with SIEM platforms and log analysis technologies
  • Understanding of common cyber threats, attacker methodologies, and MITRE ATT&CK techniques
  • Experience performing threat containment actions and supporting incident response activities
  • Strong analytical and problem-solving skills with attention to detail
  • Experience analyzing endpoint, identity, email, network, and cloud-based security events
  • Knowledge of Windows, Linux, macOS, Active Directory, Entra ID, and enterprise authentication technologies
  • Working knowledge of networking fundamentals including DNS, TCP/IP, HTTP/S, firewalls, proxies, VPNs, and IDS/IPS technologies
  • Ability to assess risk and prioritize multiple investigations simultaneously in a fast-paced operational environment
  • Strong verbal communication, technical writing, and incident documentation skills
  • Ability to work independently while collaborating effectively across global teams
Preferred technical and professional experience
  • Experience working within an enterprise SOC supporting global operations
  • Experience using QRadar, Splunk, Sentinel, Elastic, or similar SIEM platforms
  • Experience with CrowdStrike Falcon and/or Microsoft Defender XDR
  • Familiarity with cloud security monitoring in AWS, Azure, IBM Cloud, or GCP environments
  • Experience performing threat hunting activities
  • Knowledge of identity-based attacks and Entra ID / Active Directory investigations
  • Understanding of malware behavior and attacker TTPs
  • Experience developing detections, use cases, or automation workflows
  • Basic scripting skills using Python, PowerShell, KQL, or similar technologies
  • Experience supporting incident response engagements or working closely with a CSIRT organization
  • Cybersecurity certifications such as Security+, CySA+, GCIH, GCIA, GCED, SC-200, SC-300, or equivalent experience

IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.

#J-18808-Ljbffr