1

Security Operations Engineer Jobs in California (NOW HIRING)

Security Operations Expert

Sunnyvale, CA · On-site

$92K - $112K/yr

We are seeking a dynamic and highly skilled Security Operations Expert to join our SOC team ... Strong understanding of detection engineering, fine-tuning alerting rules, and managing SIEM/EDR ...

Overview The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role ... Partner with security engineers and analysts to turn relevant intelligence into detections, hunts ...

New

Security Operations Expert

Sunnyvale, CA · On-site

$92K - $112K/yr

We are seeking a dynamic and highly skilled Security Operations Expert to join our SOC team ... Strong understanding of detection engineering, fine-tuning alerting rules, and managing SIEM/EDR ...

As Security Operations Lead, you will build and own Northwood's security operations function ... Engineering Lead to ensure SOC tooling integrations across SIEM, EDR, email security, and identity ...

Operations Engineer

San Diego, CA · On-site

$73K - $99K/yr

Job Title Operations Engineer Location San Diego, CA 22400 US (Primary) Category Research ... System Administration & Security: Perform system administration tasks and physical security of ...

Security Operations Analyst

Redlands, CA · On-site

$70K - $114K/yr

Overview The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role ... Partner with security engineers and analysts to turn relevant intelligence into detections, hunts ...

Showing results 41-60

Security Operations Engineer information

See California salary details

$33.1K

$135.9K

$171.7K

How much do security operations engineer jobs pay per year?

As of Sep 6, 2026, the average yearly pay for security operations engineer in California is $135,941.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,500.00 and $170,700.00 per year, depending on experience, location, and employer.

What does a security operations engineer do?

As a security operations engineer, your job is to monitor a network or system and help implement new methods of protection and data recovery. In this role, you may conduct a vulnerability assessment for each emerging threat, coordinate with other security specialists, and help develop responses with industry peers. This job title refers to maintaining network security systems and should not be confused with non-electronic security operations, such as safeguarding VIPs or facilities. A security operations engineer works regular hours, but employers may call you in for emergency help as needed. This position usually reports to someone, such as a chief information security officer. You may occasionally brief executives or other managers on relevant topics, so presentation skills are helpful.

What are the key skills and qualifications needed to thrive as a security operations engineer, and why are they important?

To thrive as a Security Operations Engineer, you need a solid understanding of network security, incident response, and vulnerability management, typically supported by a degree in computer science or a related field. Experience with SIEM tools (like Splunk or QRadar), firewalls, IDS/IPS, and certifications such as CISSP or CompTIA Security+ are commonly required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you quickly detect and respond to security threats while collaborating with teams. These skills are crucial to proactively safeguarding organizational assets, minimizing risks, and ensuring swift recovery from security incidents.

What are some of the main challenges security operations engineers face when responding to security incidents?

Security Operations Engineers often face challenges such as quickly identifying genuine threats among large volumes of security alerts, coordinating responses across multiple teams, and containing incidents before they escalate. Balancing thorough investigation with the need for rapid action can be demanding, especially in high-pressure situations. Additionally, staying updated on emerging threats and ensuring compliance with security protocols are ongoing responsibilities that require continuous learning and adaptability.

What is the difference between Security Operations Engineer vs Security Analyst?

AspectSecurity Operations EngineerSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, GIAC Security Essentials
Work EnvironmentHands-on security infrastructure management, incident responseMonitoring, analyzing security data, reporting
Employer & Industry UsageIT security teams in various industries, focusing on security operations

The Security Operations Engineer focuses on managing security systems and responding to incidents, while the Security Analyst primarily monitors security data and analyzes threats. Both roles require similar certifications and work closely within security teams, but their daily tasks differ in scope and focus.

What are popular job titles related to Security Operations Engineer jobs in California?

For Security Operations Engineer jobs in California, the most frequently searched job titles are:

What job categories do people searching Security Operations Engineer jobs in California look for?

The top searched job categories for Security Operations Engineer jobs in California are:

What cities in California are hiring for Security Operations Engineer jobs?

Cities in California with the most Security Operations Engineer job openings:

Infographic showing various Security Operations Engineer job openings in California as of August 2026, with employment types broken down into 83% Full Time, 14% Part Time, 1% Temporary, 1% Contract, and 1% Nights. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $135,941 per year, or $65.4 per hour.

Staff Security Engineer, Security Operations - Moveworks

ServiceNow

Mountain View, CA • On-site

Full-time

Re-posted yesterday


ServiceNow rating

8.3

Company rating: 8.3 out of 10

Based on 10 frontline employees who took The Breakroom Quiz

99th of 247 rated software companies


Job description

Company Description
Who we are
Moveworks is the Agentic AI Assistant platform that empowers the entire workforce.
Our platform enables employees to converse with all of their business systems through natural language to quickly find answers and automate tasks. Powered by the world's most advanced LLMs, our proprietary models, and a sophisticated Agentic AI platform, we're transforming how work gets done by allowing AI to take initiative, streamline complex workflows, and continuously learn and adapt.
Moveworks is trusted by over 5.5 million employees at more than 350 of the world's largest companies, including 10% of the Fortune 500, to automate everyday tasks and streamline business operations. Recognized on the Forbes Cloud 100 and AI 50 lists, Moveworks was also named one of Fast Company's 2025 Most Innovative Companies and Inc's Best in Business, in the Best in Innovation category. Moveworks was also recognized at Microsoft's 2025 Partner of the Year and in 2024, received the AI Breakthrough Award.
In December 2025, Moveworks was acquired by ServiceNow, marking a pivotal milestone in our journey to create a single front door to work for all business systems. By combining ServiceNow's leading workflow automation with Moveworks' Reasoning Engine and natural language capabilities, we deliver the AI platform for every person and every workflow. Built to go beyond basic summaries to deliver meaningful business impact. Together, our AI acts across enterprise systems to turn conversations into completed work.
By joining our team, you'll be at the forefront of the AI transformation, backed by the global scale of ServiceNow and the agility of a high-growth company. We are looking for world-class talent to help us extend agentic AI to every employee across every corner of the business.
Come join us!
ServiceNow
It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today - ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.
Job Description
The Moveworks Security team at ServiceNow is not looking for a traditional SOC analyst to watch a dashboard. We are looking for a Staff Agentic Security Engineer. Our ultimate goal is to automate the SOC out of existence through autonomous systems.
At the IC4 level, you will not just execute workflows; you will define the architectural framework for our AI-driven defense. You will treat the incident response lifecycle as an advanced engineering problem-experimenting with, designing, and orchestrating complex, multi-agent frameworks and Model Context Protocol (MCP) systems that handle proactive threat hunting, triage, and remediation at machine speed. This is a role for a visionary engineer who wants to push the boundaries of what agentic AI can achieve in enterprise defense.
What you get to do in this role:
  • Building and AI Orchestration: Move beyond basic tool configuration to build, code, design and research advanced, framework-level approaches for chaining MCP servers and AI agents. You will optimize agentic networks for maximum performance, multi-step reasoning accuracy, and deterministic outcomes in high-stress security scenarios.
  • Proactive Threat Hunting Program: Architect and scale a proactive threat hunting program from scratch. You will leverage custom agents, MCP capabilities, and security tooling to proactively discover complex vulnerabilities, configuration drift, and hidden threats across the infrastructure network.
  • Advanced Purple Team Synergies: Forge a cutting-edge feedback loop between the Blue Team and our internally developed AI Red Team Agent. You will seamlessly bridge automated offense and defense, turning threat hunting insights into self-healing infrastructure.
  • Cross-Functional Influence & Leadership: Act as a strategic engineering partner across IT, Security Engineering, DevOps, DevSecOps, Compliance, Cloud, and Infrastructure teams to ensure corporate systems are natively "automation-ready."
  • E2E IR Automation Architecture: Own the overarching engineering roadmap for the end-to-end incident response lifecycle (Detection → Triage → Containment → Recovery), replacing traditional SOAR workflows with resilient, agentic orchestration.
  • Incident Commander Escalation: Serve as a high-tier technical escalation point for active, complex incidents. Use every incident as an adversarial data point to design superior automated immune responses.
  • Validate the Defense: Design, execute, and validate automated simulation testing to systematically prove that agentic workflows and detection pipelines trigger reliably against real-world attack behaviors.

Qualifications
To be successful in this role you have:
  • U.S. Citizenship Required: (Must meet strict compliance/FedRAMP criteria).
  • Experience: 8-10 years of experience in Security Operations, Systems Engineering, or DevSecOps (Minimum 5 years of highly relevant engineering experience required).
  • Cross-Functional Mastery: 3-5 years of proven track record working closely across multidisciplinary teams including Cloud Infrastructure, DevOps, DevSecOps, Compliance, and IT. Bonus points for direct collaboration experience with Product Security or Data Security teams.
  • AI & Agentic Fluency: Deep familiarity with modern LLM agent frameworks, including active research into their application, performance trade-offs, and behavioral guardrails. You know how to deeply integrate LLMs, orchestrate custom MCP servers, and build autonomous technical workflows.
  • Automation Engineering: High proficiency in Python and software engineering principles. You have extensive past experience with traditional workflow engines and legacy SOAR tooling, giving you the context needed to successfully replace them with AI-native alternatives.
  • Cloud & Infrastructure Depth: Strong, hands-on architectural familiarity with AWS security ecosystems (IAM, CloudTrail, GuardDuty) and containerized environments (Kubernetes/EKS).
  • FedRAMP & Trust Awareness: While an engineer first, you possess the communication skills and security compliance maturity to translate framework controls into automated, code-driven evidence generation pipelines.
  • Team & Collaboration Dynamics: A high-autonomy, high-collaboration mindset. You thrive in a lean, elite, fast-moving team environment where you independently drive massive technical impact while mentoring and leveling up surrounding engineers.

Additional Information
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license.

What ServiceNow employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


ServiceNow logo

About ServiceNow

Sourced by ZipRecruiter

At ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can't wait, and we innovate in ways no one else can for our customers and communities. By joining ServiceNow, you are part of an ambitious team of change makers who have a restless curiosity and a drive for ingenuity. We know that your best work happens when you live your best life and share your unique talents, so we do everything we can to make that possible. We dream big together, supporting each other to make our individual and collective dreams come true. The future is ours, and it starts with you. With more than 7,400+ customers, we serve approximately 80% of the Fortune 500, and we're proud to be one of FORTUNE's 100 Best Companies to Work For® and World's Most Admired Companies® 2022.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

Santa Clara, CA, US

Year founded

2004