1

Soc Analyst Jobs in Minnesota (NOW HIRING)

As a Cybersecurity Analyst - CSIRT, you'll take the lead as you detect and assess cyber security ... Experience with network monitoring in a SOC environment preferred Work Arrangement: This position ...

Evaluate SOC report scope, control design, testing results, and auditor opinions. * Collect and analyze supporting evidence from control owners. * Assess control exceptions, coordinate corrective ...

Evaluate SOC report scope, control design, testing results, and auditor opinions. * Collect and analyze supporting evidence from control owners. * Assess control exceptions, coordinate corrective ...

Internal Auditor II

Bloomington, MN · On-site

$65K - $97K/yr

Evaluate SOC report scope, control design, testing results, and auditor opinions. * Collect and analyze supporting evidence from control owners. * Assess control exceptions, coordinate corrective ...

... SOC 2 Type II and SOC 3. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and ...

Showing results 21-40

Soc Analyst information

See Minnesota salary details

$34.8K

$97.1K

$124.4K

How much do soc analyst jobs pay per year?

As of Sep 2, 2026, the average yearly pay for soc analyst in Minnesota is $97,116.00, according to ZipRecruiter salary data. Most workers in this role earn between $70,500.00 and $123,900.00 per year, depending on experience, location, and employer.

What is a SOC analyst?

SOC Analysts, or Security Operations Center Analysts, are cybersecurity professionals responsible for monitoring, detecting, and responding to security threats within an organization's IT infrastructure. They analyze security alerts, investigate suspicious activities, and help protect against data breaches and cyber attacks. SOC Analysts often work in shifts to provide round-the-clock surveillance and are essential for maintaining an organization’s security posture. Their duties also include reporting incidents, conducting threat analysis, and recommending improvements to security policies.

What are the key skills and qualifications needed to thrive as a SOC analyst?

To thrive as a SOC Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident response, often backed by a degree in information security or a related field. Familiarity with security information and event management (SIEM) tools, intrusion detection systems, and relevant certifications like CompTIA Security+ or CISSP are typically required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for quickly identifying and mitigating threats. These skills and qualifications are crucial for effectively protecting organizational assets and maintaining robust security operations.

What are some typical challenges a SOC analyst faces during incident response, and how can these be managed?

SOC Analysts often encounter challenges such as distinguishing legitimate threats from false positives, responding quickly to multiple simultaneous incidents, and managing large volumes of security alerts. These challenges can be managed by developing strong analytical skills, maintaining up-to-date knowledge of threat landscapes, and leveraging automated tools to prioritize incidents. Effective communication with IT teams and regular training in incident response protocols also play a key role in overcoming these obstacles and ensuring organizational security.

What is the difference between Soc Analyst vs Security Engineer?

AspectSoc AnalystSecurity Engineer
CredentialsCertifications like CompTIA Security+, CEH, CISSP (entry-level to mid-level)Certifications like CISSP, CEH, OSCP, often more technical and advanced
Work EnvironmentSecurity operations centers, monitoring and analyzing security alertsDesigning, implementing, and maintaining security systems and infrastructure
Employer & Industry UsageFinancial, healthcare, government, and corporate sectorsTech companies, cybersecurity firms, large enterprises
Common Search & Comparison IntentUnderstanding roles in security monitoring and incident responseUnderstanding technical security implementation and architecture

While both roles focus on cybersecurity, Soc Analysts primarily monitor security alerts and respond to incidents within security operations centers. Security Engineers design and build security systems to prevent breaches. The roles complement each other but differ in focus, skills, and responsibilities.

Do SOC analysts get paid well?

SOC analysts typically earn competitive salaries that vary based on experience, certifications, and location. Entry-level positions may start lower, but experienced analysts with certifications like CISSP or CEH can command higher wages, especially in high-demand areas or specialized environments.

Is a SOC analyst a hard job?

A SOC analyst role involves monitoring security systems, analyzing threats, and responding to incidents, which can be challenging due to the need for quick decision-making and technical skills. The job often requires knowledge of cybersecurity tools, protocols, and certifications, and may involve shift work to ensure 24/7 coverage.

What are the most commonly searched types of Soc Analyst jobs in Minnesota?

The most popular types of Soc Analyst jobs in Minnesota are:

What job categories do people searching Soc Analyst jobs in Minnesota look for?

The top searched job categories for Soc Analyst jobs in Minnesota are:

What cities in Minnesota are hiring for Soc Analyst jobs?

Cities in Minnesota with the most Soc Analyst job openings:

Infographic showing various Soc Analyst job openings in Minnesota as of August 2026, with employment types broken down into 85% Full Time, 10% Part Time, and 5% Contract. Highlights an 84% Physical, 6% Hybrid, and 10% Remote job distribution, with an average salary of $97,116 per year, or $46.7 per hour.

Cyber - Google SecOps - Manager

Deloitte

Minneapolis, MN • On-site

Full-time

Re-posted 4 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 93 frontline employees who took The Breakroom Quiz

46th of 152 rated financial services


Job description

Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:

  • Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
  • Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
  • Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
  • Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
  • Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
  • Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
  • 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
  • Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
  • Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
  • Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
  • Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
  • Experience facilitating scope or build requirement discussions with internal or external stakeholders
  • Experience with threat hunting or cyber threat intelligence fundamentals
  • Experience with data fabric technologies such as Bindplane or Cribl
  • Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Qualifications:

Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:

  • Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
  • Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
  • Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
  • Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
  • Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
  • Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
  • 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
  • Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
  • Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
  • Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
  • Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
  • Experience facilitating scope or build requirement discussions with internal or external stakeholders
  • Experience with threat hunting or cyber threat intelligence fundamentals
  • Experience with data fabric technologies such as Bindplane or Cribl
  • Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom