1

Security Operations Engineer Jobs in Connecticut

... or IAM engineering. Responsibilities Operate identity threat detection and response with ... security operations and certification processes; track and report on identity-risk backlog burn ...

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AIassisted code quality, security scanning, and test coverage tools into CI/CD pipelines

DevOps Engineer

Shelton, CT · On-site

$102K - $128K/yr

... s Engineer - Shelton, CT Ready to build what's next with one of the world's most iconic brands? Why ... Integrate AI-assisted code quality, security scanning, and test coverage tools into CI/CD pipelines

DevOps Engineer

Shelton, CT · On-site

$53 - $72.50/hr

Job Title - DevOps Engineer Location: Shelton, CT Duration - 12+ Months Onsite - 4 Day''s in a Week ... Partner across security/IAM, database, development, QA, and platform engineering teams to embed ...

DevOps Engineer

Bristol, CT · On-site

$52.75 - $72.25/hr

... s Engineer responsible for designing and automating enterprise infrastructure systems across on ... security best practices, and audit requirements. • Self-motivated with the ability to work in a ...

DevOps Engineer

Bristol, CT · On-site

$52.75 - $72.25/hr

... s Engineer responsible for designing and automating enterprise infrastructure systems across on ... security best practices, and audit requirements. • Self-motivated with the ability to work in a ...

next page

Showing results 1-20

Security Operations Engineer information

See Connecticut salary details

$31.9K

$131K

$165.5K

How much do security operations engineer jobs pay per year?

As of Aug 16, 2026, the average yearly pay for security operations engineer in Connecticut is $131,035.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,600.00 and $164,600.00 per year, depending on experience, location, and employer.

What is the difference between Security Operations Engineer vs Security Analyst?

AspectSecurity Operations EngineerSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, GIAC Security Essentials
Work EnvironmentHands-on security infrastructure management, incident responseMonitoring, analyzing security data, reporting
Employer & Industry UsageIT security teams in various industries, focusing on security operations

The Security Operations Engineer focuses on managing security systems and responding to incidents, while the Security Analyst primarily monitors security data and analyzes threats. Both roles require similar certifications and work closely within security teams, but their daily tasks differ in scope and focus.

What are some of the main challenges security operations engineers face when responding to security incidents?

Security Operations Engineers often face challenges such as quickly identifying genuine threats among large volumes of security alerts, coordinating responses across multiple teams, and containing incidents before they escalate. Balancing thorough investigation with the need for rapid action can be demanding, especially in high-pressure situations. Additionally, staying updated on emerging threats and ensuring compliance with security protocols are ongoing responsibilities that require continuous learning and adaptability.

What does a security operations engineer do?

As a security operations engineer, your job is to monitor a network or system and help implement new methods of protection and data recovery. In this role, you may conduct a vulnerability assessment for each emerging threat, coordinate with other security specialists, and help develop responses with industry peers. This job title refers to maintaining network security systems and should not be confused with non-electronic security operations, such as safeguarding VIPs or facilities. A security operations engineer works regular hours, but employers may call you in for emergency help as needed. This position usually reports to someone, such as a chief information security officer. You may occasionally brief executives or other managers on relevant topics, so presentation skills are helpful.

What are the key skills and qualifications needed to thrive as a security operations engineer, and why are they important?

To thrive as a Security Operations Engineer, you need a solid understanding of network security, incident response, and vulnerability management, typically supported by a degree in computer science or a related field. Experience with SIEM tools (like Splunk or QRadar), firewalls, IDS/IPS, and certifications such as CISSP or CompTIA Security+ are commonly required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you quickly detect and respond to security threats while collaborating with teams. These skills are crucial to proactively safeguarding organizational assets, minimizing risks, and ensuring swift recovery from security incidents.

What are popular job titles related to Security Operations Engineer jobs in Connecticut?

For Security Operations Engineer jobs in Connecticut, the most frequently searched job titles are:

What job categories do people searching Security Operations Engineer jobs in Connecticut look for?

The top searched job categories for Security Operations Engineer jobs in Connecticut are:

Infographic showing various Security Operations Engineer job openings in Connecticut as of August 2026, with employment types broken down into 85% Full Time, 12% Part Time, 1% Temporary, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $131,035 per year, or $63 per hour.

Security Operations Analyst

Subway

Shelton, CT

Full-time

Posted 10 days ago


Subway rating

4.4

Company rating: 4.4 out of 10

Based on 2,050 frontline employees who took The Breakroom Quiz

98th of 106 rated fast food restaurants


Job description

Security Operations Analyst

Franchise World Headquarters, LLC

Shelton, CT


Why Join Subway?

At Subway, we are not standing still. We are building.


This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.


You will not just do the work. You will shape it.


We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.


If you bring energy, accountability and a bias for action, you will fit right in.

We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.

This is your chance to be part of whats next.



Position Overview

The Security Operations Analyst operates the identity security and access-governance layer of Subway's Cybersecurity program. Sitting within the Identity & Access Management team, this role is the operational bridge between IAM and the Detect & Respond function identity-first in day-to-day work, but grounded in general security operations center (SOC) practice. The Analyst runs access-governance controls that keep the enterprise least-privileged and audit-ready, operates identity threat detection and response using CrowdStrike Falcon Identity Protection, and investigates access anomalies in Falcon Next-Gen SIEM. This role is designed as a genuine growth seat and launchpad into the broader Cybersecurity program, with development paths toward senior identity security, threat detection engineering, security engineering, or IAM engineering.


Responsibilities

Operate identity threat detection and response with CrowdStrike Falcon Identity Protection: monitor and triage identity-based detections, assess risk and severity, apply risk-based policy actions within defined guardrails, and escalate confirmed threats to the Detect & Respond team; investigate access anomalies end to end using identity telemetry in CrowdStrike Falcon Next-Gen SIEM authentication events, MFA activity, privileged-account usage, and provisioning changes.

Support tuning of identity detections, dashboards, and alert quality with the Detect & Respond team; participate in incident response for identity-related incidents including account compromise, credential abuse, and unauthorized access executing containment actions such as session revocation, credential reset, and access suspension under team runbooks; monitor privileged and service-account activity for anomalous behavior and policy violations.

Run Okta Identity Governance access certification campaigns end to end: campaign setup and scoping, reviewer coordination and follow-up, revocation execution, exception tracking, and production of audit-ready evidence for PCI-DSS 4.0 and cyber-insurance programs; support access request workflow operations including approval-path exceptions and escalations outside self-service.

Apply least-privilege principles in daily work: flag over-broad group and role assignments, validate time-bound privileged access, and drive cleanup of dormant, orphaned, or over-privileged accounts; produce and maintain access evidence for internal and external audits and compliance programs.

Work down the standing identity-risk case backlog: investigate, prioritize, remediate, and close findings such as dormant accounts, stale privileged access, weak authentication paths, and unowned service accounts; track remediation against service-level targets and report progress and systemic patterns to Cybersecurity leadership.

Handle Tier-2/3 identity escalations remaining after automation complex access requests, provisioning exceptions, and onboarding/offboarding edge cases; manage assigned tickets in ServiceNow meeting SLA targets; support access-related requests from investigations, legal holds, and HR partners with appropriate discretion and documentation; participate in the team's shared on-call rotation.

Author and maintain runbooks, triage guides, and knowledge-base articles for identity security operations and certification processes; track and report on identity-risk backlog burn-down, certification completion rates, and detection quality metrics; propose governance, detection, and automation improvements from observed patterns.


Qualifications

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field or equivalent work experience.

13 years in security operations, identity operations, a security operations center (SOC), or IT operations with significant identity or security scope.

Working knowledge of IAM fundamentals: authentication and MFA, SSO concepts, directory services, joiner/mover/leaver lifecycle, and least-privilege access.

Hands-on exposure to Okta or a comparable identity provider: user and group administration, MFA management, and basic application assignment; Okta strongly preferred.

Familiarity with SOC practices: alert triage, severity assessment, escalation paths, evidence handling, and incident documentation.

Exposure to a SIEM or security analytics platform querying logs, investigating events, and reading detections; CrowdStrike Falcon Next-Gen SIEM a plus; willingness to develop CQL proficiency required.

Active Directory fundamentals (users, groups, OUs) and familiarity with Microsoft Entra ID and Microsoft 365 administration concepts.

Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.

Strong written documentation habits investigations, evidence, and runbooks that others can follow and auditors can rely on.

Comfort using LLM and generative AI tools in day-to-day technical and analytical work.


Preferred Qualifications

Direct experience with identity threat detection and response tooling (CrowdStrike Falcon Identity Protection or similar ITDR platform).

Exposure to Okta Identity Governance or another IGA/access-certification platform (SailPoint, Saviynt, Omada).

Familiarity with identity-focused attack techniques credential stuffing, MFA fatigue, token theft, Kerberos abuse, lateral movement and the MITRE ATT&CK framework.

Basic scripting in PowerShell or Python for reporting, reconciliation, and evidence gathering.

Awareness of non-human identity concepts: service accounts, credential scoping, and access patterns for LLM and agentic AI integrations.

Exposure to attack surface/asset management (CAASM) tooling.

Relevant certification: CompTIA Security+, Okta Certified Professional, Microsoft SC-300, or GIAC entry-level certification.


What do we offer?

Insurance Plans (Medical, Life)

Pension/401K/RSP (country specific)

Competitive Bonus

Mobility Allowance

Tuition Reimbursement

Company Holidays

Volunteering time

And More..




What Subway employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom