1

Security Operations Technician Jobs (NOW HIRING)

As a Security Operations Technician at Whitefiber's Enovum Data Centers, you'll be the first line of defense for a mission-critical data center--monitoring systems, controlling access, and responding ...

The Operations Technician will support critical infrastructure operations. This position will be ... Perform Site Security functions, including visitor site access check in, badge processing and ...

Operations Technicians are responsible for the following: * Conducting daily airfield inspections ... Ensuring airfield security is maintained and provide escort to pedestrians and vehicles in secured ...

Maintain and complete regular facility and security tours documenting and responding to found ... Critical Operations Technician I Critical Operations Technician II Critical Operations Technician ...

Maintain and complete regular facility and security tours documenting and responding to found ... Critical Operations Technician I Critical Operations Technician II Critical Operations Technician ...

next page

Showing results 1-20

Security Operations Technician information

See salary details

$14

$26

$40

How much do security operations technician jobs pay per hour?

As of Aug 26, 2026, the average hourly pay for security operations technician in the United States is $26.61, according to ZipRecruiter salary data. Most workers in this role earn between $21.15 and $30.53 per hour, depending on experience, location, and employer.

What is a security operations technician?

Security Operations Technicians are IT professionals who monitor, manage, and maintain the security of an organization’s computer systems and networks. They work in Security Operations Centers (SOCs) and are responsible for detecting, analyzing, and responding to cybersecurity incidents. Their duties include monitoring security alerts, investigating suspicious activities, and implementing measures to protect against threats. They often collaborate with other IT and security staff to ensure the organization's information assets remain secure.

What skills and qualifications are needed to be a security operations technician?

To thrive as a Security Operations Technician, you need a solid understanding of cybersecurity principles, network monitoring, and incident response, typically supported by relevant IT or cybersecurity certifications. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and ticketing platforms is crucial. Attention to detail, problem-solving, and effective communication are standout soft skills in this role. These skills and qualities are essential for promptly identifying threats, minimizing risks, and maintaining the organization's security posture.

What are common challenges faced by security operations technicians in their daily work?

Security Operations Technicians often manage multiple security systems simultaneously, which can be challenging during high-alert situations or when handling multiple incidents at once. They must quickly identify and prioritize threats, communicate effectively with other security team members, and follow established protocols under pressure. Staying updated with the latest security technologies and adapting to evolving threats are also key aspects of the role. Strong analytical skills and attention to detail help technicians navigate these challenges and maintain a safe environment.

What is the difference between Security Operations Technician vs Security Analyst?

AspectSecurity Operations TechnicianSecurity Analyst
CertificationsCompTIA Security+, Network+CompTIA Security+, CISSP (preferred)
Work EnvironmentMonitoring security systems, troubleshooting, supporting security infrastructureAnalyzing security data, assessing threats, developing security strategies
Employer & Industry UsageIT departments, security service providersCorporate security teams, cybersecurity firms
Search & Comparison IntentFocus on operational support rolesFocus on analysis and strategy roles

The Security Operations Technician primarily handles monitoring and supporting security systems, while the Security Analyst focuses on analyzing security data and developing security strategies. Both roles require similar certifications and are integral to cybersecurity teams, but they differ in responsibilities and focus areas.

Is a Security Operations Technician an entry-level job?

A Security Operations Technician is often considered an entry-level position in cybersecurity or security operations, suitable for individuals with basic technical skills and knowledge of security tools. It typically requires some training or certifications such as CompTIA Security+ and involves monitoring security systems, analyzing alerts, and supporting security infrastructure. Advancement usually depends on gaining experience and additional certifications.
More about Security Operations Technician jobs
Infographic showing various Security Operations Technician job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 11% Part Time, and 1% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $55,353 per year, or $26.6 per hour.

Security Operations Technician

Jacksonville, FL

The Scarlett Group
IT Services • 11 - 50 employees

$27 - $34/hr

Full-time

PTO

Posted 5 days ago


Job description

Security Operations Technician Needed!
Job Overview:
The Security Operations Technician is a Tier 2 technical cybersecurity role responsible for the health, coverage, and configuration integrity of Scarlett-managed security platforms across internal and client environments. The primary duty of this role is security platform health management, coverage reconciliation, and execution of approved security changes, including firewall updates and security configuration changes. Queue coverage and incident support are secondary, rotational responsibilities performed under established runbooks and the direction of Security Operations leadership. When engaged in an active security incident, the Cyber Incident Response Specialist may provide direction for incident response activities. This role participates in the Security Operations on-call rotation and rotates into Security Analyst and incident support coverage when demand requires. This role is intended to strengthen operational consistency across the Scarlett security stack while providing a defined development path toward Security Analyst and Incident Response roles. Hours will fluctuate based on incident volume and maintenance schedules, and overtime is paid in accordance with company policy and applicable law.
Responsibilities amp; Duties:
Security Agent Health amp; Coverage Management
• Monitor and remediate security agent health across EDR, RMM, and application control platforms, including offline, degraded, outdated, and duplicate agents.
• Perform coverage reconciliation between RMM asset inventory, EDR consoles, and documentation systems to identify unprotected or unmanaged endpoints.
• Deploy, reinstall, and troubleshoot security agents during client onboarding, platform migrations, and remediation efforts.
• Maintain agent version currency and execute staged rollout schedules across the client portfolio.
• Track and report portfolio-wide coverage metrics and close gaps against each client’s contracted security stack.
Security Reconciliation amp; Auditing
• Reconcile security tool tenants and licensing against active client lists, removing stale tenants, licenses, and assets for offboarded clients and decommissioned systems.
• Audit alignment between contracted security services and deployed controls for each client.
• Perform recurring user account reconciliation across M365, security consoles, VPN, and firewall administration accounts, flagging orphaned and terminated-user accounts.
• Validate MFA enrollment coverage and conditional access policy application across managed tenants.
• Support evidence collection for compliance engagements related to platform configuration, coverage, and change records.
Firewall amp; Network Security Changes
• Execute approved firewall changes, including rule additions, NAT policies, VPN tunnel builds, and content filtering updates, in accordance with the change management process.
• Perform firmware updates and scheduled maintenance on firewalls and network security appliances.
• Conduct periodic firewall rule reviews, flagging stale, overly permissive, or undocumented rules for review.
• Maintain site-to-site and client VPN configurations, including certificate and pre-shared key rotation.
Security Change Execution
• Implement approved security configuration changes across M365 and Entra tenants, including conditional access, DLP policy deployment, and mail flow and anti-phishing rules.
• Perform application control policy maintenance, including application approvals, ringfencing adjustments, and policy tuning within defined guardrails, escalating novel approval requests.
• Apply security baseline configurations to new endpoints, servers, and tenants during onboarding.
• Support syslog and log source onboarding and maintenance, ensuring log flow continuity from firewalls, servers, and security platforms into the logging pipeline.
Vulnerability amp; Patch Support
• Track vulnerability scan output and coordinate or execute remediation, including patching, configuration changes, and mitigations, within defined SLAs.
• Validate remediation completion and maintain exception documentation.
• Support penetration testing engagement logistics, including runner deployment, connectivity validation, and pre-engagement checklist completion.
On-Call amp; Coverage Rotation
• Participate in the Security Operations on-call rotation, providing after-hours first response to alerts, agent outages, and client-reported security events. Participation in the on-call rotation is an essential function of the role.
• Provide surge support during active incidents under the direction of the Cyber Incident Response Specialist or Security Operations leadership, including evidence collection, containment task execution such as endpoint isolations, account disables, and block deployments, and status documentation.
• Rotate into Security Analyst queue coverage during PTO, incident surges, and staffing gaps, performing alert validation and initial triage per established runbooks.
• Support after-hours maintenance windows for firewall firmware, agent rollouts, and platform changes.
Documentation amp; Ticket Hygiene
• Maintain accurate platform documentation, credentials, network diagrams, and configuration records in the documentation system.
• Work the security change queue, meeting SLA targets for standard changes.
• Escalate anomalies discovered during routine work, including unexpected accounts, disabled agents, and unauthorized changes, to Security Operations leadership or the Cyber Incident Response Specialist.
Other
• To support onboarding, training, and team integration, employees in this position are expected to work onsite during their first 90 days of employment unless the position is specifically designated as fully remote. Following successful completion of the introductory period, employees may participate in the Company's flexible hybrid work arrangements in accordance with business needs, role requirements, manager discretion and Company policy.
• After-hours and weekend work is a requirement of this position as needed.
• Other duties as assigned.
Certification Requirement
CompTIA Security+ or an equivalent entry-level cybersecurity certification is not required at the time of role acceptance. The individual accepting the Security Operations Technician role must obtain CompTIA Security+ or an approved equivalent certification within 180 days of role acceptance, with training and exam costs funded by Scarlett. Maintaining progress toward this certification and completing it within the required period is an expectation of accepting and remaining in this role.
Qualifications:
• High school diploma or equivalent required.
• 2+ years of hands-on experience in IT support, systems administration, or security operations at a Tier 2 or equivalent level.
• Working knowledge of Windows administration and networking fundamentals, including TCP/IP, DNS, VPN, and firewall concepts.
• Experience with RMM, EDR, application control, or endpoint management platforms preferred.
• Familiarity with M365 and Entra administration preferred.
• Ability to participate in a rotating on-call schedule, including after-hours and weekend response, as an essential function of the role.
• Strong documentation habits and change management discipline.
• CompTIA Security+ or approved equivalent certification within 180 days of role acceptance; training provided by Scarlett.
Environmental and Physical Requirements:
• The work environment for this position is a standard office setting.
• The employee is regularly required to sit, stand, walk, and use hands to operate a computer and other office equipment.
• The employee must occasionally lift and/or move up to 25 pounds.
• Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Success Metrics
• Agent coverage and health maintained at or above defined targets across the client portfolio.
• Reconciliation audits completed on schedule, with identified gaps documented and closed.
• Firewall and security changes executed within SLA and in accordance with change management, with zero unauthorized changes.
• Vulnerability and patch remediation SLAs met, with exceptions documented.
• On-call response time targets met, and queue coverage performed in accordance with established runbooks.
• Documentation maintained accurate and current across assigned platforms and clients.