1

Security Operations Center Soc Engineer Jobs in Houston, TX

Senior Security Engineer

Houston, TX ยท On-site

$109K - $149K/yr

Soni's client is seeking a Senior Security Engineer to lead the design, modernization, and optimization of enterprise Security Operations Center (SOC) technologies. This role is responsible for ...

Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...

... security alerts using CrowdStrike (NGSIEM/EDR), Exabeam (SIEM/UEBA), WIZ, and Proofpoint โ€ข ... SOC, Incident Response, or Threat Hunting with proven experience handling critical/major incidents ...

... Engineering, or a related technical field is preferred, or equivalent practical experience Experience * 1-3 years of hands-on Security Operations Center (SOC) experience, including alert triage ...

... Engineering, or a related technical field is preferred, or equivalent practical experience Experience * 1-3 years of hands-on Security Operations Center (SOC) experience, including alert triage ...

Provides leadership and direction to contracted supervisors, SOC personnel, security officers, and ... Oversee Security Operations Center activities, including alarm monitoring, dispatch operations ...

... Operations Center (SOC) functions, and independent oversight. The Director will define and advance ... Demonstrated experience leading engineering and operations teams through large-scale technology ...

New

next page

Showing results 1-20

Security Operations Center Soc Engineer information

See Houston, TX salary details

$32K

$131.5K

$166.2K

How much do security operations center soc engineer jobs pay per year?

As of Aug 31, 2026, the average yearly pay for security operations center soc engineer in Houston, TX is $131,543.00, according to ZipRecruiter salary data. Most workers in this role earn between $106,000.00 and $165,200.00 per year, depending on experience, location, and employer.

What does a Security Operations Center (SOC) engineer do?

A Security Operations Center (SOC) Engineer is responsible for monitoring, detecting, and responding to cybersecurity threats within an organization's IT infrastructure. They use specialized tools and techniques to analyze security alerts, investigate incidents, and coordinate responses to minimize risk. SOC Engineers also help maintain and improve security systems, conduct vulnerability assessments, and implement security best practices to protect sensitive data and resources. Their role is critical in ensuring the organization's information security posture remains strong against evolving threats.

What are some common challenges faced by a Security Operations Center (SOC) engineer, and how can they be addressed?

SOC Engineers often face challenges such as managing a high volume of security alerts, staying updated with evolving threat landscapes, and ensuring effective communication across IT and security teams. To address these, it's important to leverage automation tools to filter and prioritize alerts, participate in ongoing training to remain current with new threats, and foster strong collaboration with other departments for coordinated incident response. Developing clear processes and documentation also helps mitigate confusion during high-pressure incidents.

What are the key skills and qualifications needed to thrive as a Security Operations Center (SOC) engineer, and why are they important?

To thrive as a Security Operations Center (SOC) Engineer, you need strong analytical skills, a solid understanding of network security principles, and typically a degree in computer science or cybersecurity. Familiarity with SIEM tools (like Splunk or QRadar), intrusion detection systems, and relevant certifications such as CompTIA Security+ or CISSP are highly valued. Excellent problem-solving abilities, attention to detail, and effective communication make someone stand out in this role. These skills and qualities are crucial for detecting, analyzing, and responding to security threats promptly, ensuring organizational data and infrastructure remain secure.

What is the difference between Security Operations Center Soc Engineer vs Security Analyst?

AspectSecurity Operations Center Soc EngineerSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, GIAC Security Essentials (GSEC)
Work EnvironmentSecurity operations center, monitoring and responding to threatsAnalyzing security data, assessing vulnerabilities
Employer & IndustryCybersecurity firms, large enterprises, government agenciesOrganizations with security teams, IT departments

While both roles focus on cybersecurity, Security Operations Center Soc Engineers primarily design, implement, and respond to security threats within a SOC environment. Security Analysts analyze security data and identify vulnerabilities. SOC Engineers often have more technical responsibilities related to system configuration and incident response, whereas Security Analysts focus on monitoring and reporting. Both roles are essential for a comprehensive security strategy.

How much do security operations center SOC engineers make?

Security Operations Center (SOC) engineers typically earn between $70,000 and $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced SOC engineers with certifications like CISSP or CEH can earn higher salaries, especially in high-demand areas or with specialized skills in threat detection and incident response.

What are popular job titles related to Security Operations Center Soc Engineer jobs in Houston, TX?

For Security Operations Center Soc Engineer jobs in Houston, TX, the most frequently searched job titles are:

What job categories do people searching Security Operations Center Soc Engineer jobs in Houston, TX look for?

The top searched job categories for Security Operations Center Soc Engineer jobs in Houston, TX are:

Infographic showing various Security Operations Center Soc Engineer job openings in Houston, TX as of August 2026, with employment types broken down into 84% Full Time, 13% Part Time, 1% Temporary, 1% Contract, and 1% Nights. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $131,543 per year, or $63.2 per hour.

Security Operations Center (SOC) Analyst

Airswift

Houston, TX โ€ข On-site

Full-time

Re-posted 10 days ago


Job description

Security Operations Center (SOC) Analyst
Duration: 6 months
Location: Houston, TX
Schedule: Monday - Friday: 7am - 4pm
Role Summary
The SOC Analyst is responsible for monitoring, investigating, documenting, and coordinating response to cybersecurity events across enterprise environments. This role is designed for an analyst with 3?5 years of hands-on experience in SOC operations, incident response, phishing investigation, threat monitoring, or related cybersecurity operations. The analyst is expected to communicate clearly, collaborate early with senior cybersecurity personnel and cross-functional teams, and exercise sound judgment during complex or time-sensitive investigations.
Key Responsibilities:
  • Monitor, triage, validate, and investigate security alerts from SIEM, EDR, email security, identity, network, cloud, and other cybersecurity platforms.
  • Analyse suspicious activity, indicators of compromise, malware alerts, account compromise indicators, unauthorised access attempts, phishing emails, smishing messages, malicious links, and business email compromise attempts.
  • Document investigation findings, actions taken, supporting evidence, recommendations, and response activities in designated ticketing or case management systems.
  • Coordinate with senior cybersecurity personnel, IT, OT, email administrators, endpoint teams, identity teams, business stakeholders, and affected users to support investigation, containment, remediation, and user guidance.
  • Participate in incident response activities, including evidence gathering, timeline development, stakeholder coordination, lessons learned, and post-incident improvement efforts.
  • Review threat intelligence, vulnerability disclosures, and security advisories to identify relevant indicators, attacker techniques, and potential impacts to the organisation.
  • Conduct proactive threat hunting and recommend detection improvements, correlation rules, alert tuning, and workflow enhancements.
  • Support security control validation, cybersecurity awareness activities, phishing simulations, vulnerability prioritisation, operational reporting, and metrics development.
  • Maintain and improve SOC playbooks, standard operating procedures, investigation templates, knowledge articles, and analyst handoff practices.
  • Communicate investigation status, risk, findings, and recommended next steps clearly to technical and non-technical stakeholders.
Must-Have Skills:
  • 3-5 years of hands-on experience in SOC operations, incident response, phishing investigation, threat monitoring, or related cybersecurity operations.
  • Strong understanding of SOC workflows, incident response concepts, threat intelligence, vulnerability management, and security monitoring fundamentals.
  • Experience investigating phishing, smishing, business email compromise, malware activity, credential compromise, suspicious user behaviour, and common attacker tactics.
  • Ability to work with SIEM, EDR, email security, identity, network, and cloud security alerts.
  • Strong technical analysis, documentation, prioritisation, problem-solving, and customer service skills.
  • Ability to collaborate effectively with senior analysts, incident responders, IT, OT, infrastructure, identity, email, endpoint, and business teams.
  • Clear communication skills with the ability to explain findings, risks, investigation status, and recommended next steps to technical and non-technical audiences.
  • Commitment to continuous learning, adaptability, and improving SOC processes, detections, and response workflows.
  • Ability to work in a professional office environment and within or alongside an industrial plant environment, with routine use of standard office equipment.
  • Ability to sit and/or stand for a full shift, lift up to 20 lbs. as needed, move throughout office or site locations, and travel to other company work locations if required.
  • Remote working is not available for this position.
Nice-to-Have:
  • Industry certification such as CompTIA Security+, CompTIA CySA+, Microsoft SC-200, Cisco CyberOps Associate, GSEC, GCIH, CEH, or similar cybersecurity certification (Preferred).
  • Experience writing or modifying SIEM queries, EDR detection logic, threat hunting queries, or basic automation scripts.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, NIST incident response concepts, or similar threat and response frameworks.
  • Experience supporting cybersecurity awareness programmes, phishing simulations, vulnerability prioritisation, remediation tracking, control validation, reporting, or exposure management activities.
  • Interest in mentoring junior analysts, improving SOC processes, and contributing to a collaborative, team-oriented security operations culture.
About Airswift:
Airswift is an international workforce solutions provider within the energy, process and infrastructure industries. Airswift serves as a strategic partner to clients, offering a turnkey workforce solution to capture and deliver the top talent needed to complete successful projects by aligning with unique project needs. With over 1000 employees and 9,000 contractors operating in over 60 countries, Airswift's geographical reach and pool of talent available is unmatched in the industry.
#LI-BF2