Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Must have strong analytical and technical skills in computer network defense operations, ability to ... This includes security event triage, incident investigation, implementing countermeasures, and ...
Must have strong analytical and technical skills in computer network defense operations, ability to ... This includes security event triage, incident investigation, implementing countermeasures, and ...
Network Operations Center (NOC) Lead
Denver, CO · On-site
$254K/yr
Network Operations Center (NOC) Lead Job Category: Information Technology Time Type: Full time ... Strong understanding of network protocols, infrastructure, and security concepts * Experience with ...
Network Operations Center (NOC) Lead
Denver, CO · On-site
$254K/yr
Network Operations Center (NOC) Lead Job Category: Information Technology Time Type: Full time ... Strong understanding of network protocols, infrastructure, and security concepts * Experience with ...
... and security operations ticket management. This position will support activities within Special ... Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force ...
... and security operations ticket management. This position will support activities within Special ... Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force ...
P-11 Security, based in Southern California, is a certified Economically-Disadvantaged Women-Owned ... Must have strong analytical and technical skills in computer network defense operations, ability to ...
Quick apply
P-11 Security, based in Southern California, is a certified Economically-Disadvantaged Women-Owned ... Must have strong analytical and technical skills in computer network defense operations, ability to ...
Network Operations Center (NOC) Lead with Security Clearance
Denver, CO · On-site
$254K/yr
Network Operations Center (NOC) Lead Job Category: Information Technology Time Type: Full time ... Strong understanding of network protocols, infrastructure, and security concepts * Experience with ...
Network Operations Center (NOC) Lead with Security Clearance
Denver, CO · On-site
$254K/yr
Network Operations Center (NOC) Lead Job Category: Information Technology Time Type: Full time ... Strong understanding of network protocols, infrastructure, and security concepts * Experience with ...
... Network Operations Center (NOC) Tier 3 supporting an Intelligence Community customer's wide-area (WAN), local-area (LAN) and campus-area (CAN) networks across multiple security domains.
... Network Operations Center (NOC) Tier 3 supporting an Intelligence Community customer's wide-area (WAN), local-area (LAN) and campus-area (CAN) networks across multiple security domains.
Security AI Technologist
Littleton, CO · On-site
$127K - $181K/yr
Develop agentic automation workflows that integrate directly into security tooling to augment security operations center analysts and threat hunters * Establish continuous monitoring models to ...
Quick apply
Security AI Technologist
Littleton, CO · On-site
$127K - $181K/yr
Develop agentic automation workflows that integrate directly into security tooling to augment security operations center analysts and threat hunters * Establish continuous monitoring models to ...
Space Security Operations Integration Engineer with Security Clearance
Colorado Springs, CO · On-site
As the operator of a federally funded research and development center (FFRDC), we are broadly ... The Space Security Operations Department team is seeking a Space Security Operations Integration ...
Space Security Operations Integration Engineer with Security Clearance
Colorado Springs, CO · On-site
As the operator of a federally funded research and development center (FFRDC), we are broadly ... The Space Security Operations Department team is seeking a Space Security Operations Integration ...
In this role, you will support Next-Generation Security Operations Center (SOC) capabilities, including platforms such as Cortex XSIAM, to help clients operate with confidence and proactively manage ...
In this role, you will support Next-Generation Security Operations Center (SOC) capabilities, including platforms such as Cortex XSIAM, to help clients operate with confidence and proactively manage ...
In this role, you will support Next-Generation Security Operations Center (SOC) capabilities, including platforms such as Cortex XSIAM, to help clients operate with confidence and proactively manage ...
In this role, you will support Next-Generation Security Operations Center (SOC) capabilities, including platforms such as Cortex XSIAM, to help clients operate with confidence and proactively manage ...
Principal Systems Security Engineer / Senior ISSM
Englewood, CO · On-site
$165.01 - $226.89/hr
S. Air Force's Survivable Airborne Operations Center (SAOC) mission, developing the ... Perform hands‑on technical security operations: vulnerability scanning, SIEM monitoring, STIG ...
Principal Systems Security Engineer / Senior ISSM
Englewood, CO · On-site
$165.01 - $226.89/hr
S. Air Force's Survivable Airborne Operations Center (SAOC) mission, developing the ... Perform hands‑on technical security operations: vulnerability scanning, SIEM monitoring, STIG ...
DoD SkillBridge Intern - (Cyber Security Analyst) (Active Duty Service Members)
Colorado Springs, CO · On-site
Two plus years of experience working in a Security Operations Center (SOC), or as a Cyber Security Analyst either in SIPRNET or NIPRNET environments; or * Two plus of experience working in system ...
DoD SkillBridge Intern - (Cyber Security Analyst) (Active Duty Service Members)
Colorado Springs, CO · On-site
Two plus years of experience working in a Security Operations Center (SOC), or as a Cyber Security Analyst either in SIPRNET or NIPRNET environments; or * Two plus of experience working in system ...
DoD SkillBridge Intern - (Cyber Security Analyst) (Active Duty Service Members)
Colorado Springs, CO · On-site
Two plus years of experience working in a Security Operations Center (SOC), or as a Cyber Security Analyst either in SIPRNET or NIPRNET environments; or * Two plus of experience working in system ...
DoD SkillBridge Intern - (Cyber Security Analyst) (Active Duty Service Members)
Colorado Springs, CO · On-site
Two plus years of experience working in a Security Operations Center (SOC), or as a Cyber Security Analyst either in SIPRNET or NIPRNET environments; or * Two plus of experience working in system ...
Two plus years of experience working in a Security Operations Center (SOC), or as a Cyber Security Analyst either in SIPRNET or NIPRNET environments; or * Two plus of experience working in system ...
Two plus years of experience working in a Security Operations Center (SOC), or as a Cyber Security Analyst either in SIPRNET or NIPRNET environments; or * Two plus of experience working in system ...
Network Operations Center (NOC) Trainer with Security Clearance
Denver, CO · On-site
$75K - $158K/yr
Network Operations Center (NOC) Trainer Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of ...
Network Operations Center (NOC) Trainer with Security Clearance
Denver, CO · On-site
$75K - $158K/yr
Network Operations Center (NOC) Trainer Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of ...
IT Security Analyst
Denver, CO · On-site
Coordinate with Leprino's co-sourced Security Operations Center and external security partners to support monitoring and response activities. * Help onboard and support remote security resources ...
IT Security Analyst
Denver, CO · On-site
Coordinate with Leprino's co-sourced Security Operations Center and external security partners to support monitoring and response activities. * Help onboard and support remote security resources ...
Coordinate with Leprino's co-sourced Security Operations Center and external security partners to support monitoring and response activities. * Help onboard and support remote security resources ...
Coordinate with Leprino's co-sourced Security Operations Center and external security partners to support monitoring and response activities. * Help onboard and support remote security resources ...
The GBS Operations Center Technician supports the 21st CS at Schriever SFB, Combatant Command ... DoD 8570 certification (CompTIA Security+) or ability to obtain within 90 days of hire. * Knowledge ...
The GBS Operations Center Technician supports the 21st CS at Schriever SFB, Combatant Command ... DoD 8570 certification (CompTIA Security+) or ability to obtain within 90 days of hire. * Knowledge ...
The GBS Operations Center Technician supports the 21st CS at Schriever SFB, Combatant Command ... DoD 8570 certification (CompTIA Security+) or ability to obtain within 90 days of hire. * Knowledge ...
The GBS Operations Center Technician supports the 21st CS at Schriever SFB, Combatant Command ... DoD 8570 certification (CompTIA Security+) or ability to obtain within 90 days of hire. * Knowledge ...
Security Operations Center information
See Colorado salary details
$8.34 - $10.32
3% of jobs
$10.32 - $12.29
0% of jobs
$12.29 - $14.27
0% of jobs
$14.27 - $16.25
2% of jobs
$18.20 is the 25th percentile. Wages below this are outliers.
$16.25 - $18.22
20% of jobs
$18.22 - $20.20
24% of jobs
The median wage is $20.25 / hr.
$20.20 - $22.17
22% of jobs
$22.53 is the 75th percentile. Wages above this are outliers.
$22.17 - $24.15
19% of jobs
$24.15 - $26.13
7% of jobs
$26.13 - $28.10
1% of jobs
$28.10 - $30.08
1% of jobs
$8
$20
$30
How much do security operations center jobs pay per hour?
What is a security operations center?
A Security Operations Center (SOC) job involves monitoring, detecting, analyzing, and responding to cybersecurity threats in real time. SOC analysts use various security tools to identify suspicious activities, mitigate risks, and protect an organization's digital assets. They work in a team environment, following incident response protocols to contain threats and prevent breaches. SOC professionals also conduct vulnerability assessments, generate reports, and collaborate with other IT teams to strengthen security defenses. The role requires knowledge of cybersecurity principles, threat intelligence, and security technologies.
What does a typical workday look like for someone in a security operations center role?
A typical day in a Security Operations Center involves monitoring network activity for suspicious behavior, responding to real-time security incidents, and conducting daily threat analysis using specialized software. SOC professionals often work in shifts within a collaborative, fast-paced team environment where quick decision-making and constant vigilance are required. Tasks may also include generating incident reports, performing vulnerability assessments, and coordinating with other departments to strengthen organizational security. This dynamic, hands-on role provides valuable experience and can serve as a strong foundation for advancing into more specialized cybersecurity positions.
What are the key skills and qualifications needed to thrive in the security operations center position?
To thrive in a Security Operations Center, you need strong analytical abilities, a solid understanding of cybersecurity principles, and typically a degree in computer science or a related field. Familiarity with SIEM (Security Information and Event Management) tools, intrusion detection/prevention systems, and certifications like CompTIA Security+, CISSP, or CEH are highly valued. Attention to detail, effective communication, and the ability to remain calm under pressure are crucial soft skills. These competencies enable professionals to quickly detect, analyze, and mitigate security threats while collaborating efficiently with IT and management teams.
Is a Security Operations Center an entry level job?
What does a security operations center do?
What are the most commonly searched types of Security Operations Center jobs in Colorado?
The most popular types of Security Operations Center jobs in Colorado are:
What are popular job titles related to Security Operations Center jobs in Colorado?
For Security Operations Center jobs in Colorado, the most frequently searched job titles are:
What job categories do people searching Security Operations Center jobs in Colorado look for?
The top searched job categories for Security Operations Center jobs in Colorado are:
What cities in Colorado are hiring for Security Operations Center jobs?
Cities in Colorado with the most Security Operations Center job openings:

Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
44th of 150 rated financial services
Job description
Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:
- Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
- Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
- Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
- Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
- Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
- Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
The team
Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.
Qualifications
Required:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
- 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
- Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
- Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
- Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
- Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
- Experience facilitating scope or build requirement discussions with internal or external stakeholders
- Experience with threat hunting or cyber threat intelligence fundamentals
- Experience with data fabric technologies such as Bindplane or Cribl
- Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:
- Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
- Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
- Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
- Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
- Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
- Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
The team
Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.
Qualifications
Required:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
- 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
- Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
- Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
- Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
- Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
- Experience facilitating scope or build requirement discussions with internal or external stakeholders
- Experience with threat hunting or cyber threat intelligence fundamentals
- Experience with data fabric technologies such as Bindplane or Cribl
- Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.