1

Staff Security Operations Engineer Jobs (NOW HIRING)

Why You'll Love This Role The Staff Security Operations Engineer will be a pivotal member of Cribl's Information Security team, primarily responsible for strengthening our security posture through ...

The Staff Security Operations Engineer serves as a key technical driver for migrating devices into Entra ID and as a hands-on engineering resource for the Entra ID (Azure AD) platform. Supporting ...

The Staff Security Operations Engineer serves as a key technical driver for migrating devices into Entra ID and as a hands-on engineering resource for the Entra ID (Azure AD) platform. Supporting ...

Why You'll Love This Role The Staff Security Operations Engineer will be a pivotal member of Cribl's Information Security team, primarily responsible for strengthening our security posture through ...

Security Operations Engineer

Mountain View, CA · On-site

$123.98 - $165.31/hr

# Security Operations EngineerApply**Job#: 3043920**** **Security Operations Engineer**Location ... Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing ...

Vertex Inc. is looking for a Security Operations Engineer role to strengthen our security monitoring, incident response, detection engineering, and SecOps automation capabilities. This role is ideal ...

next page

Showing results 1-20

Staff Security Operations Engineer information

See salary details

$33.5K

$137.7K

$174K

How much do staff security operations engineer jobs pay per year?

As of Sep 5, 2026, the average yearly pay for staff security operations engineer in the United States is $137,745.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $173,000.00 per year, depending on experience, location, and employer.

What is a staff security operations engineer?

Staff Security Operations Engineers are senior-level professionals responsible for overseeing and enhancing an organization's security operations. They design, implement, and maintain security systems, monitor for threats, and lead incident response efforts. Their role often involves mentoring junior team members, developing security policies, and collaborating with other departments to ensure comprehensive protection of company assets. Staff-level engineers typically have significant experience and play a key role in shaping the organization's overall security posture.

What are the key skills and qualifications needed to thrive as a staff security operations engineer?

To thrive as a Staff Security Operations Engineer, you need deep expertise in cybersecurity principles, incident response, and threat analysis, typically supported by a bachelor's degree in computer science or a related field and relevant certifications like CISSP or GIAC. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and scripting languages is essential. Strong analytical thinking, effective communication, and leadership skills help drive security initiatives and coordinate responses across teams. These capabilities are vital to proactively identify threats, minimize risks, and safeguard organizational assets in a constantly evolving threat landscape.

How does a staff security operations engineer typically collaborate with other IT and security teams within an organization?

As a Staff Security Operations Engineer, you'll frequently collaborate with diverse teams such as IT operations, incident response, and application development. Your role involves coordinating threat detection, response efforts, and sharing insights from security monitoring tools with these teams to strengthen overall defense. You'll often participate in cross-functional meetings, incident post-mortems, and architecture reviews to ensure security best practices are integrated into projects. This collaborative approach helps ensure that security measures are both proactive and responsive to evolving threats.

What is the difference between Staff Security Operations Engineer vs Security Analyst?

AspectStaff Security Operations EngineerSecurity Analyst
CredentialsCertifications like CISSP, CISA, Security+Certifications like Security+, CEH, CISSP (preferred)
Work EnvironmentHands-on security monitoring, incident response, system configurationMonitoring security alerts, analyzing threats, reporting
Employer & IndustryTech companies, financial institutions, large enterprisesVariety of industries including healthcare, finance, government

The Staff Security Operations Engineer focuses on implementing and maintaining security systems, responding to incidents, and ensuring infrastructure security. In contrast, a Security Analyst primarily monitors security alerts, analyzes threats, and reports findings. Both roles require relevant certifications and work in similar environments, but the Engineer role is more technical and hands-on, while the Analyst role emphasizes analysis and reporting.

More about Staff Security Operations Engineer jobs

What are the most commonly searched types of Staff Security Operations Engineer jobs?

The most popular types of Staff Security Operations Engineer jobs are:

What job categories do people searching Staff Security Operations Engineer jobs look for?

The top searched job categories for Staff Security Operations Engineer jobs are:

Infographic showing various Staff Security Operations Engineer job openings in the United States as of August 2026, with employment types broken down into 84% Full Time, 13% Part Time, 1% Temporary, 1% Contract, and 1% Nights. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $137,745 per year, or $66.2 per hour.

Staff Security Operations Engineer

Cribl

Remote

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

Why You'll Love This Role

The Staff Security Operations Engineer will be a pivotal member of Cribl's Information Security team, primarily responsible for strengthening our security posture through robust security operations and advanced threat detection. You will help lead security incident management, triage, and investigations, and be instrumental in developing innovative solutions to remediate current threats and proactively prevent future attacks. A key aspect of this role will be designing, implementing, and optimizing detection logic to identify sophisticated threats across our environment. You will partner closely with Product Security, IT, and Legal teams, and report to the Sr. Director, Security Engineering and Operations under the CISO.


As An Active Member Of Our Team, You Will...

  • Provide knowledge and experience in working with modern security principles e.g. SIEM, security data lakes, detection as code, EDR, zero trust networking, and other security tooling, as well as demonstrated experience with incident response and management.
  • Utilize a strong understanding of common attack frameworks (e.g., MITRE ATT&CK) and how to map detections to TTPs
  • Understanding of authentication and authorization schemes such as SAML, OpenID, OAuth2, and SCIM
  • Experience scripting/coding in at least one of the following languages: Python, NodeJS, Ruby, Bash
  • Be the go-to technical subject matter expert on security, compliance, and assurance topics
  • Communicate ideas to technical and non-technical audiences
  • Comfortable with ambiguity, have a strong analytical acumen, self-motivated, able to work cross-functionally
  • We are a remote-first company and work happens across many time-zones - you may be required to occasionally perform duties outside your standard working hours


If You've Got It - We Want It

  • Monitoring security events and alerting via our security tooling, including MSSP, SIEM, AI, and CSPM tooling, to identify and triage potential threats
  • Developing, implementing, and maintaining high-fidelity detection rules and alerts within SIEM and other security platforms (e.g., EDR, Cloud Security tools) based on threat intelligence, MITRE ATT&CK framework, and identified risks
  • Conducting continuous tuning and optimization of existing detection logic to reduce false positives and improve detection efficacy
  • Responding to issues identified by our Cribl employees
  • Acting as a security incident response lead, including leveraging and improving detection capabilities during investigations
  • Building, enhancing, and managing security playbooks, incorporating detection engineering best practices
  • Conducting security assessments of corporate assets through vulnerability testing, threat hunts, and purple team activities, with a focus on identifying detection gaps and opportunities
  • Performing both internal and external security reviews of corporate properties e.g., the corporate website and enterprise applications
  • Leading security incident response tabletop exercises
  • Continuing to evolve and champion the use of Cribl products in our security tech stack to enhance detection, analysis, and response capabilities
  • Collaborating with threat intelligence teams to integrate new indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) into detection strategies
  • Experience with SIEM platforms like Panther is a plus and its detection capabilities
  • Familiarity with Wiz and cloud native security tooling for detection in AWS, Azure, or GCP
  • Relevant certifications in cloud security or incident response (e.g., SANS GIAC certifications)
  • Proven experience in developing, deploying, and maintaining detection rules (e.g., Sigma, YARA, Splunk SPL, KQL) across various security platforms


#LI-KJ1
#LI-Remote