1

Security Operations Center Jobs in Chicago, IL (NOW HIRING)

Virtual CISO

Mettawa, IL

$135K - $150K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a member of Dot Security, you will get the opportunity to work from a brand-new, state of the art Security Operations Center (SOC) facility. What you will be doing: A Virtual CISO (vCISO) acts as ...

Virtual CISO

Mettawa, IL · On-site +1

$135K - $158K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a member of Dot Security, you will get the opportunity to work from a brand-new, state of the art Security Operations Center (SOC) facility. What you will be doing: A Virtual CISO (vCISO) acts as ...

Director, Global Security

Chicago, IL · On-site

$168.21 - $210.26/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Support executive protection, Board of Directors' activities, high‑risk events, crisis response, and the Global Security Operations Center (GSOC). * Lead and develop a team of intelligence and ...

SOAR and AI Engineer - Managed Security

Chicago, IL · On-site

$120 - $160/hr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Position Overview This is a technical hands-on position that requires someone with a strong understanding of the needs of a 24/7 SOC (Security Operations Center). We are looking for a candidate with ...

Armed Security Officer- 1st Shift

Chicago, IL · On-site

$49K - $61K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Officers perform duties in three main categories, including patrolling the S&C Ridge Boulevard Industrial Campus facility, working in the Global Security Operations Center (GSOC), and operating the ...

New

Armed Security Officer- 2nd Shift

Chicago, IL · On-site

$49K - $61K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Officers perform duties in three main categories, including patrolling the S&C Ridge Boulevard Industrial Campus facility, working in the Global Security Operations Center (GSOC), and operating the ...

New

Cybersecurity Compliance Consultant

Mettawa, IL · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a member of Dot Security, you will get the opportunity to work from a brand-new, state of the art Security Operations Center (SOC) facility. What you will be doing: A Cybersecurity Compliance ...

Cybersecurity Compliance Consultant

Mettawa, IL

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a member of Dot Security, you will get the opportunity to work from a brand-new, state of the art Security Operations Center (SOC) facility. What you will be doing: A Cybersecurity Compliance ...

Create and enhance dashboards, searches, and reports to support SOC (Security Operations Center) operations and threat hunting. * Contribute to documentation of SIEM architecture, data flows ...

New

SecOps Lead

Chicago, IL · On-site

$160K - $180K/yr

  • Medical

  • Dental

  • Vision

A rapidly growing technology-driven organization is seeking a Security Operations Lead to modernize and optimize its Security Operations Center (SOC). This role focuses on improving operational ...

Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...

Showing results 21-40

Security Operations Center information

See Chicago, IL salary details

$8

$20

$29

How much do security operations center jobs pay per hour?

As of Aug 14, 2026, the average hourly pay for security operations center in Chicago, IL is $20.44, according to ZipRecruiter salary data. Most workers in this role earn between $17.84 and $22.07 per hour, depending on experience, location, and employer.

What is a security operations center?

A Security Operations Center (SOC) job involves monitoring, detecting, analyzing, and responding to cybersecurity threats in real time. SOC analysts use various security tools to identify suspicious activities, mitigate risks, and protect an organization's digital assets. They work in a team environment, following incident response protocols to contain threats and prevent breaches. SOC professionals also conduct vulnerability assessments, generate reports, and collaborate with other IT teams to strengthen security defenses. The role requires knowledge of cybersecurity principles, threat intelligence, and security technologies.

What are the key skills and qualifications needed to thrive in the security operations center position?

To thrive in a Security Operations Center, you need strong analytical abilities, a solid understanding of cybersecurity principles, and typically a degree in computer science or a related field. Familiarity with SIEM (Security Information and Event Management) tools, intrusion detection/prevention systems, and certifications like CompTIA Security+, CISSP, or CEH are highly valued. Attention to detail, effective communication, and the ability to remain calm under pressure are crucial soft skills. These competencies enable professionals to quickly detect, analyze, and mitigate security threats while collaborating efficiently with IT and management teams.

What does a security operations center do?

A Security Operations Center (SOC) monitors and analyzes an organization’s security posture using tools like intrusion detection systems and security information and event management (SIEM) platforms. SOC analysts detect, respond to, and mitigate cybersecurity threats and incidents to protect critical systems and data around the clock.

Is a Security Operations Center an entry level job?

A Security Operations Center (SOC) analyst role can be entry-level, especially for positions requiring basic knowledge of cybersecurity tools and monitoring. However, many SOC roles prefer candidates with some experience, certifications like CompTIA Security+ or Cisco CCNA, and familiarity with security information and event management (SIEM) systems. Advancement often involves gaining experience and additional certifications.

What does a typical workday look like for someone in a security operations center role?

A typical day in a Security Operations Center involves monitoring network activity for suspicious behavior, responding to real-time security incidents, and conducting daily threat analysis using specialized software. SOC professionals often work in shifts within a collaborative, fast-paced team environment where quick decision-making and constant vigilance are required. Tasks may also include generating incident reports, performing vulnerability assessments, and coordinating with other departments to strengthen organizational security. This dynamic, hands-on role provides valuable experience and can serve as a strong foundation for advancing into more specialized cybersecurity positions.

What are the most commonly searched types of Security Operations Center jobs in Chicago, IL?

The most popular types of Security Operations Center jobs in Chicago, IL are:

What cities near Chicago, IL are hiring for Security Operations Center jobs?

Cities near Chicago, IL with the most Security Operations Center job openings:

Infographic showing various Security Operations Center job openings in Chicago, IL as of August 2026, with employment types broken down into 75% Full Time, and 25% Part Time. Highlights an 87% In-person, and 13% Remote job distribution, with an average salary of $42,521 per year, or $20.4 per hour.

Senior Director, Security Threat

Ecolab

Naperville, IL

Full-time

Posted 27 days ago


Ecolab rating

7.5

Company rating: 7.5 out of 10

Based on 210 frontline employees who took The Breakroom Quiz

57th of 100 rated chemical manufacturers


Job description

Job Summary: The Director of Threat Management is responsible for leading the enterprise detection and response function, owning the reactive side of security: identifying, investigating, and containing threats across a global Fortune 500 environment. This role provides leadership for the Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Detection Engineering, and Incident Response (IR), and is accountable for the speed and quality of threat detection, triage, investigation, and response across the enterprise.

The Director of Threat Management leads a 24x7 monitoring and response organization while advancing the detection engineering pipeline, maturing threat intelligence integration, and driving measurable improvement in mean time to detect and mean time to respond. The role combines strategic direction, operational accountability, and organizational leadership to reduce enterprise risk from active and emerging threats, partnering closely with the platform engineering team that owns the underlying security tooling.

What You Will Do:

Strategy, Governance, and Leadership

  • Define and own the enterprise threat detection and response strategy, roadmap, and operating model aligned to cybersecurity, risk, and business objectives.

  • Mature the threat management program through formal governance, playbooks, standards, metrics, and leadership reporting.

  • Present detection and response posture, incident trends, risks, and investment needs to security leadership and executive stakeholders.

  • Establish and monitor KPIs such as mean time to detect (MTTD), mean time to respond (MTTR), detection coverage, and alert quality.

  • Lead prioritization decisions across the SOC, threat intelligence, detection engineering, and incident response functions.

Security Operations and Monitoring

  • Lead a 24x7 Security Operations Center responsible for monitoring, alert triage, escalation, and initial investigation across the enterprise.

  • Own the detection content lifecycle within the SIEM, and define data source onboarding, log storage, and retention requirements for the platform-owning team.

  • Drive continuous improvement in alert quality, triage efficiency, and analyst workflow to reduce noise and analyst fatigue.

  • Establish tiered operating models, shift coverage, and escalation paths that ensure consistent 24x7 response readiness.

  • Oversee SOC performance metrics, service levels, and quality assurance across monitoring and triage activities.

Detection Engineering

  • Lead the detection engineering function responsible for building, tuning, and maintaining detection content across SIEM and security telemetry sources.

  • Drive a detection-as-code approach with version control, testing, peer review, and measurable detection coverage mapped to MITRE ATT&CK.

  • Prioritize detection development against threat intelligence, red team findings, incident learnings, and emerging adversary techniques.

  • Establish metrics for detection coverage, efficacy, and false-positive rates, and drive continuous tuning based on outcomes.

  • Partner with engineering and platform teams to ensure high-quality, well-structured log and telemetry sources feed detection pipelines.

Cyber Threat Intelligence

  • Lead the Cyber Threat Intelligence function responsible for strategic, operational, and tactical intelligence supporting detection and response.

  • Operationalize threat intelligence by driving indicator enrichment, threat actor tracking, and intelligence-led detection and hunting priorities.

  • Deliver executive and stakeholder threat briefings that translate the threat landscape into business-relevant risk and action.

  • Establish threat hunting programs that proactively search for adversary activity across the environment ahead of alerting.

  • Manage intelligence sources, sharing partnerships, and integration of intelligence into SIEM, SOAR, and detection workflows.

Incident Response

  • Own the enterprise incident response process across detection, triage, containment, eradication, recovery, and post-incident review.

  • Lead major incident coordination, serving as an escalation point and driving cross-functional response during significant events.

  • Establish and maintain incident response playbooks, runbooks, and tabletop exercises to ensure organizational readiness.

  • Drive post-incident reviews and lessons-learned processes that feed detection improvements and control gaps back into the program.

  • Partner with legal, communications, IT, and business stakeholders to ensure coordinated response and regulatory notification where required.

Tooling and Automation Requirements

  • Define detection and response requirements, use cases, and priorities for the SIEM, SOAR, and log storage platforms owned and operated by the platform engineering team.

  • Partner with the platform-owning team to shape roadmap, data onboarding, retention, and automation priorities that serve detection and response needs.

  • Specify SOAR automation use cases for triage, enrichment, and response, and validate that delivered automations meet analyst workflow requirements.

  • Provide feedback on tooling performance, gaps, and integration needs to drive a unified, efficient analyst workflow across detection, intelligence, and response.

  • Use modern tools including AI-assisted workflows to accelerate investigation, analysis, documentation, and decision-making across the team.

Organizational and People Leadership

  • Lead and develop a distributed threat management organization consisting of managers, analysts, detection engineers, threat intelligence analysts, and incident responders.

  • Build organizational clarity across the SOC, threat intelligence, detection engineering, and incident response functions.

  • Provide leadership in talent development, succession planning, coaching, performance management, and team engagement.

  • Manage staffing strategy across full-time employees, partners, and contingent resources, including managed detection and response providers where applicable.

  • Oversee third-party vendors and consulting partners supporting threat management programs and services.

Minimum Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline; equivalent experience may be considered.

  • 12+ years of progressive experience in cybersecurity, security operations, threat detection, incident response, or threat intelligence.

  • 5+ years of leadership experience managing multi-team security operations or threat functions at the Senior Manager or Director level.

  • Demonstrated success leading detection and response programs across SOC operations, detection engineering, threat intelligence, and incident response.

  • Experience managing 15+ person organizations including managers, analysts, and engineers with varied technical specializations.

  • Experience leading major incident response and driving measurable improvement in detection coverage and response times.

  • Experience building or standing up new detection, intelligence, or response capabilities, teams, or services.

Technical and Functional Qualifications

  • Strong knowledge of SIEM and log management platforms and log storage technologies such as Elasticsearch or Splunk, including data onboarding, retention, and detection content management.

  • Strong knowledge of security orchestration, automation, and response (SOAR) platforms such as Swimlane or Cortex XSOAR.

  • Strong knowledge of detection engineering practices, detection-as-code, and detection coverage mapped to MITRE ATT&CK.

  • Experience with the cyber threat intelligence lifecycle, threat actor tracking, and intelligence-led detection and hunting.

  • Experience with incident response frameworks, forensic investigation concepts, and major incident coordination.

  • Understanding of threat detection across cloud (Azure, AWS, GCP), endpoint, network, and identity telemetry sources.

  • Familiarity with security frameworks and models such as MITRE ATT&CK, NIST CSF 2.0, and the cyber kill chain.

Preferred Qualifications

  • Experience in a Fortune 500, global, manufacturing, or industrial environment with complex, heterogeneous technology estates.

  • Prior experience standing up or transforming a SOC, threat intelligence, detection engineering, or incident response function.

  • Experience with threat detection and response in operational technology (OT) or industrial control system (ICS) environments.

  • Familiarity with platforms such as Elastic, Splunk, Swimlane, Cortex XSOAR, CrowdStrike, or Microsoft Sentinel.

  • Relevant certifications such as CISSP, CISM, GCIH, GCIA, GCTI, or GCFA.

Leadership Competencies

  • Strategic thinker with the ability to set direction and translate strategy into operational execution.

  • Decisive leader who operates effectively under pressure and makes sound calls during active incidents and competing priorities.

  • Delivery-oriented leader with a strong focus on accountability, measurable outcomes, and service quality.

  • Effective communicator able to translate complex threat and incident topics for executives, stakeholders, and technical teams.

  • Strong collaborator with the ability to influence across infrastructure, cloud, application, legal, and business teams.

  • Proven people leader with the ability to coach talent, build teams, and develop future leaders.

Additional Information

  • The role leads a 24x7 operation and may require off-hours availability for major incidents, escalations, and key initiatives.

  • Travel up to 10% may be required for site assessments, team collaboration, and vendor engagements.

  • The role may require coordination across global teams, including off-hours support for key initiatives, escalations, or major incidents.

Annual or Hourly Compensation Range

The base salary range for this position is $168,400.00 - $252,600.00. This position is eligible for annual bonus and long-term incentives based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.

Benefits

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families.Click here to see our benefits.

If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here.


Potential Customer Requirements Notice

To meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:

- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.

Americans with Disabilities Act (ADA)

Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website.


What Ecolab employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Ecolab logo

About Ecolab

Sourced by ZipRecruiter

Ecolab is a global sustainability leader offering water, hygiene and infection prevention solutions and services that protect people and the resources vital to life.

Industry

Manufacturing

Company size

10,000+ Employees

Headquarters location

Saint Paul, MN, US

Year founded

1923