Security Operations Remote Jobs in Texas (US)
This page tracks remote security operations openings that are location-eligible for Texas.
This page tracks remote security operations openings that are location-eligible for Texas.
Open jobs
312
Hiring companies this week
9
Salary sample
$95,000 - $199,500
Jobs added last hour
0
312 Jobs
241 Companies
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Role Description The Security Operations Center (SOC) Analyst I is a frontline cyber defender responsible for monitoring security tools and dashboards to identify indicators of compromise across networks, endpoints, and cloud‑hosted systems in mission‑critical environments. The role focuses on triaging and analyzing alerts from SIEM and other monitoring platforms, distinguishing true incidents from benign activity and escalating confirmed threats to senior analysts or incident responders. SOC Analyst I staff support basic threat detection, documentation of security events, and coordination with IT and security teams for initial containment, while contributing to tuning rules, improving playbooks, and maintaining awareness of common attack techniques and vulnerabilities. - Monitor SIEM platforms and log analysis tools to triage security alerts across network, system, and application layers, identifying potential indicators of compromise. - Investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services to identify potential threats and determine whether escalation is warranted. - Apply standard incident response playbooks and procedures, including initial containment steps, evidence preservation, and effective handoff to Tier II or incident response teams. - Review vulnerability scanning outputs and apply basic risk prioritization concepts to recognize misconfigurations and exploitable weaknesses in enterprise environments. - Document security events and incidents with accurate case records and concise reports that support post‑incident review and continuous improvement activities. - Follow security frameworks and best practices relevant to highly regulated government or enterprise environments, including access control, monitoring, and logging requirements for mission‑critical systems. - Participate in rule tuning and playbook improvements, providing feedback on false positives, emerging patterns, and common attack vectors, malware behaviors, and phishing techniques. Qualifications - Bachelor’s Degree in Computer Science, Information Assurance, Cybersecurity, or a related field, or equivalent relevant experience (aligned to Operations Security Planner I standard). - Typically 1–3 years of hands‑on experience in IT support, networking, or cybersecurity operations roles, including exposure to security monitoring or incident response. - Proficiency with SIEM platforms and log analysis tools for monitoring and triaging security alerts across multiple layers (network, system, application). - Ability to investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services, with foundational knowledge of common attack vectors and malware behaviors. - Familiarity with basic incident response processes, including initial containment, evidence preservation, and structured escalation to Tier II or incident response teams. - U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment. - Strong written and verbal communication skills, with attention to detail in documenting incidents and maintaining accurate case records. Preferred Qualifications - Experience with at least one enterprise SIEM (e.g., Splunk, QRadar, Azure Sentinel) and creation or tuning of correlation rules. - Foundational cybersecurity certification such as CompTIA Security+, CySA+, or equivalent vendor‑neutral credential. - Exposure to 24x7 operations or shift‑based monitoring environments supporting large, complex networks. - Familiarity with vulnerability scanning tools and outputs, and with standard security frameworks used in highly regulated government or enterprise environments. Compensation Ranges Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees. EEO Requirements It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment. Physical Requirements The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions. Disclaimer The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Role Description The Security Operations Center (SOC) Analyst II serves as a mid‑level cyber defender responsible for continuous monitoring, investigation, and response to security events across enterprise networks, endpoints, and cloud environments in a highly regulated government setting. This Tier 2 role handles alerts escalated from Tier 1, performing deeper analysis, driving containment and mitigation recommendations, and supporting coordinated remediation for mission‑critical systems. The analyst helps operate and tune SOC technologies such as SIEM, EDR/XDR, IDS/IPS, and threat intelligence platforms while improving playbooks, use cases, and procedures to enhance detection fidelity and reduce false positives. - Conduct in‑depth analysis of security alerts escalated from Tier 1, correlating logs, network traffic, endpoint telemetry, and threat intelligence to determine incident scope, impact, and root cause. - Operate and tune SIEM, EDR/XDR, IDS/IPS, and related SOC tooling to improve detection fidelity, reduce false positives, and enhance visibility across on‑premises and cloud environments. - Execute Tier 2 incident response activities, including containment and mitigation recommendations, coordination with infrastructure and application teams, and support for digital evidence collection and documentation. - Review and apply emerging cyber threat intelligence, including indicators of compromise and adversary TTPs, to update rules, playbooks, and monitoring use cases aligned to frameworks such as MITRE ATT&CK. - Maintain accurate and detailed case records in ticketing and case‑management systems, supporting 24x7 operations with clear handoffs, status reporting, and after‑action inputs. - Support compliance‑driven operations in a highly regulated government environment by following established SOPs, incident handling processes, and security control requirements for mission‑critical systems. - Collaborate with and mentor Tier 1 analysts by providing guidance on triage techniques, escalation criteria, and best practices for investigating suspicious activity. Qualifications - Bachelor’s Degree in Computer Science, Information Assurance, Cybersecurity, or a closely related field, or equivalent relevant experience. - Typically 3–5 years of prior experience in a SOC, cyber incident response, or closely related security operations role handling Tier 1/Tier 2 investigations. - Demonstrated hands‑on experience operating and tuning SIEM, endpoint security (EDR/XDR), IDS/IPS, and related SOC tools in enterprise environments. - Strong analytical skills in log analysis, network traffic review, and endpoint telemetry, with the ability to determine incident scope, impact, and probable root cause. - Familiarity with cyber threat intelligence concepts, indicators of compromise, and adversary TTPs, and experience applying these within monitoring and detection use cases. - U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment. - Ability to work effectively as part of a 24x7 SOC operation, including clear written and verbal communication for case documentation and handoffs. Preferred Qualifications - Experience with leading SIEM and endpoint security platforms such as Splunk, Microsoft Sentinel, Microsoft Defender, or similar tools. - Industry certifications such as Security+, CySA+, GCIH, or equivalent SOC/incident response credentials. - Prior experience supporting federal or other highly regulated environments requiring U.S. citizenship and eligibility for a clearance or public trust. - Familiarity with frameworks such as MITRE ATT&CK and NIST 800‑series as they relate to SOC use cases, detection engineering, and incident handling. Compensation Ranges Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees. EEO Requirements It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment. Physical Requirements The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions. Disclaimer The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
Cook Children's Health Care System is headquartered in Fort Worth, Texas and is comprised of numerous centers, hospitals, and practices. Since 1918 as a single
Role Description The Cybersecurity Incident Response Analyst Senior (“Senior IR Analyst”) is a member of the Cybersecurity team within the Office of the CISO, focused on protecting sensitive data, applications, and critical systems through effective detection and response to security threats. - Responsible for detecting, responding to, and mitigating security incidents within the organization’s environment to minimize immediate and future risk. - Applies a comprehensive approach across preparedness, mitigation, response, and recovery to ensure the protection of data, preservation of assets, and overall security of information systems. - Conducts in-depth investigations of security events, analyzes response activities, and continuously evaluates and enhances incident response processes. - Identifies, analyzes, and reports potential and active threats across enterprise networks to safeguard systems and sensitive information, leveraging defensive tools, threat intelligence, and data from multiple sources. Qualifications - Bachelor’s degree in computer science, information systems, cybersecurity, or a related field. - Minimum of 5 years of experience in cybersecurity operations, incident response, or security monitoring within an enterprise environment. - Demonstrated hands-on experience investigating and responding to security incidents across network, endpoint, and/or cloud environments. - Experience working with security technologies, such as SIEM, EDR, SOAR, intrusion detection/prevention systems, and case management tools. - Experience performing incident triage, analysis, containment, and remediation activities in a production environment. - Experience developing or executing incident response procedures, playbooks, or runbooks. Benefits - Equal employment opportunities without regard to race, color, religion, sex, age, national origin, physical or mental disability, pregnancy, protected veteran status, genetic information, or any other protected class in accordance with applicable federal laws.
We make it easy to secure your cloud transformation. Get fast, secure, and direct access to apps without appliances.
• Develop the vision and operating structure for the SecOps Technical Success team in the Americas, India, and Israel • Collaborate with global Customer Success leadership to align SecOps goals with the corporate strategy • Build strong, lasting relationships with key stakeholders for our top customer accounts • Oversee the development of tailored customer success plans for our Strategic accounts • Use a strong technical background to address technical challenges and ensure customer value realization.
Role Description As a Tier 2 Security Operations Analyst, you are the investigative backbone of Ostra's managed SOC. You take ownership of escalated alerts and incidents across our clients' environments, driving them from detection through root-cause analysis and containment. You go beyond triage: - Investigate and classify incidents. - Own escalated alerts and incidents across client environments; classify them, determine severity, and analyze data and systems to establish cause, scope, and impact. - Lead response and containment. - Act as an incident handler for sensitive and need-to-know incidents, applying CSIRT best practices and Ostra's incident response model; coordinate with clients and external parties to drive incidents to closure. - Threat hunt. - Proactively hunt for novel and evasive threats using sound hunt methodology. - Engineer and tune detections. - Understand, monitor, and optimize SIEM detection rules and SOAR playbooks; continuously improve detection accuracy, reduce false positives, and accelerate or automate response. - Author and maintain playbooks. - Develop, document, and maintain playbooks and standard operating procedures (SOPs) for recurring incidents and tasks so the SOC can respond consistently and quickly. - Produce and apply threat intelligence. - Ingest threat data from open and closed sources, correlate it against client context to produce actionable intelligence, and take appropriate action to mitigate risk. - Communicate with clients. - Clearly explain technical findings, risk, and recommended actions to client stakeholders; deliver timely, well-written incident updates and reports within SLA. - Mentor Tier 1 analysts. - Guide and upskill Tier 1 analysts, review their work, and help raise the overall quality and speed of the SOC. - Improve continuously. - Refine processes and procedures to improve speed and accuracy, and contribute to a culture of measurable improvement. - Provide on-call escalation. - Serve as an escalation point during a rotating on-call schedule, supporting a global SOC and off-hours coverage as required by the business. Qualifications - 3–5 years of hands-on experience as a SOC analyst, incident responder, or security-focused network analyst, ideally in a fast-paced or multi-client environment. - Demonstrated experience investigating and escalating security incidents beyond initial triage—establishing root cause, scope, and impact. - Working knowledge of TCP/IP and common network protocols, Windows event logs, *nix audit logs, and IDS/IPS alerting. - Hands-on experience with core security tooling categories: SIEM, SOAR, EDR/XDR, next-generation firewalls (NGFW), IDS/IPS, HIDS/HIPS, antivirus, and vulnerability scanners. - Proficiency with at least one SIEM query language and the ability to build, tune, and troubleshoot detections. - Proficiency in at least one common scripting language (PowerShell, Bash, Python, or similar) to automate analysis and response. - Solid understanding of the MITRE ATT&CK framework and experience building use cases and SOPs around relevant TTPs. - Familiarity with the NIST Cybersecurity Framework and the ability to apply its principles in practice. - Strong technical writing skills—able to document processes, procedures, and incident findings clearly for varied audiences. - Excellent problem-solving skills and comfort working through ambiguity and incomplete information. - Self-motivated, dependable, and able to deliver end-to-end results in a high-tempo environment. - Bachelor's degree in a related field, or equivalent practical experience. - Willingness to participate in a rotating on-call schedule and provide off-hours support as needed. Preferred Qualifications - Prior experience at a managed security service provider (MSSP) or in a multi-tenant SOC. - Relevant certifications (preferred, not required): CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA, GCFA), or CISSP. - Cloud security experience across AWS, Azure, Google Cloud, and/or Microsoft 365. - Experience developing new detection use cases and SOAR automations from scratch. - Experience working with a geographically distributed team across multiple time zones. - Expert-level understanding of common and emerging security threats, vulnerabilities, and attacker tradecraft. Benefits - A people-first culture built on trust and authenticity. - Competitive pay and comprehensive benefits. - Professional growth opportunities in a fast-evolving industry. - A mission-driven company protecting good businesses from cyber threats. Equal Opportunity Statement Ostra Security is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment decisions are made based on qualifications, merit, and business needs—without regard to race, color, religion, gender, gender identity, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic. FLSA Status Exempt Salary Grade $95,000 – $120,000 base, commensurate with experience (plus benefits) Position Type Full-time Remote Location Candidates residing in Minnesota will be given preference based on business needs and team alignment.
• Lead the Supplier Security Due Diligence & Monitoring Service and oversee day-to-day service delivery. • Manage and develop a team responsible for supplier security contracting support and risk-based decision making. • Review and interpret supplier security assessment outcomes and monitoring results to guide contractual negotiations. • Provide guidance on acceptable contractual security positions, fallback language, compensating controls, and alternative risk mitigation approaches. • Ensure consistent application of enterprise security requirements across supplier agreements. • Oversee documentation and tracking of contractual exceptions, deviations, and risk accommodations. • Escalate contractual positions that exceed established risk tolerances through appropriate governance and risk acceptance processes. • Partner closely with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier issues. • Establish and maintain operational metrics, service-level objectives, reporting, and quality management practices. • Lead continuous improvement efforts designed to improve scalability, consistency, and stakeholder experience.
• Serve as a primary responder for Cyber Operations client systems, taking ownership of client configuration issues and tracking through resolution • Act as a point of escalation for other Engineers (Associate Engineer) and provide guidance and mentoring. • Advise best practice on SIEM and Enterprise Security products to both technical and relatively non-technical personnel • Provide remote consulting services via interactive client sessions to assist with implementation of multiple product vendors and technologies • Implement and configure discipline software and appliance-based products in large enterprise environments • Develop and maintain content and reporting • Provide escalation support to Tier 1 and 2 for Authorized Support Customers, following processes and interacting appropriately with both customers and partners when required • Perform knowledge transfers to clients regarding security and system configuration awareness • Performs other duties as assigned • Complies with all policies and standards
Securitas’ mission is to protect homes, workplaces, and communities by providing the security services they need to protect their assets, safeguard their people, and maintain their ability to generate profits. Core values - Integrity, Vigilance, and Helpfulness Employees come from diverse backgrounds, bringing distinctive skills and perspectives.
Role Description The Deputy Regional Director of Security Operations (Deputy RDSO) supports the delivery of a large-scale, 24/7 physical security operations program for a multinational datacenter client across the AMER region. This role serves as a regional execution leader, working in close partnership with Regional Director(s) of Security Operations (RDSOs) to drive consistent, compliant, and high-performing operations. - Translate strategic direction into operational execution. - Drive performance, reinforce standards, and identify risks across the field. - Operate in a highly collaborative, fast-paced environment. - Manage complexity across multiple teams and stakeholders. In this role, you will partner with Regional Director(s) of Security Operations to help deliver consistent, high-performing security operations across assigned areas within the AMER region. - Work closely with Regional Security Managers (RSMs), site leaders, and internal partners. - Ensure operations align with client expectations, program standards, and contractual requirements. - Communicate directly and regularly with the client and execute client-driven tasks. - Drive the day-to-day execution of regional security operations. - Support and guide RSMs and site leadership to maintain strong performance across guarding operations, safety, and service delivery. - Drive and support adherence to SOPs, KPIs, SLAs, and compliance standards. - Review operational data and performance metrics to identify trends, risks, and gaps. - Play a key role in site stabilization efforts, new site launches, transitions, and overall operational readiness. - Support regional initiatives and continuous improvement efforts. - Participate in incident response and escalation management as needed. - Contribute to executive-ready reporting, dashboards, and client communications. This role operates in a fast-paced, 24/7 environment and requires flexibility to support after-hours operations during critical events. Qualifications - Bachelor’s degree in business, security, or a related field. - 8+ years of progressive leadership experience in physical security or account management. - Experience leading teams. - Experience supporting multi-site or regional operations in a 24/7 environment is strongly preferred. - Strong communication skills. - Sound judgment in high-pressure situations. - Process-driven approach. Requirements - Travel approximately 50% of the time. - Passion for travel and a valid passport. - Reliable means of communication. - Reliable means of transportation (public or private) to get to/from work. - Legal right to work in the country where the position is located. - Ability to speak, read, and write in English proficiently. Benefits - Base salary of $180,000 to $200,000. - 100% coverage of medical benefits. - Dental and Vision insurance. - Company-paid life and AD&D insurance. - Voluntary short-term disability and long-term disability. - Employee assistance program. - 4 floating holidays. - 10 paid holidays. - 3 weeks’ vacation every year. - Paid Family Leave - up to 12 weeks a year in accordance with State law.
Our mission is to enable effortless credit based on true risk.
• Work closely with system owners to ingest new log feeds for security monitoring • Enhance and maintain our Detection and Response platforms • Build in workflows with AI analysis to automatically investigate and triage issues • Be on the frontlines of Incident Response, actively investigating issues and protecting Upstart • Build common response workflows to expedite investigation and response using AI and SOAR Technology
Role Description This project will optimize the agency's CrowdStrike SIEM and related CrowdStrike services to improve threat detection, monitoring, and response capabilities. The contractor will expand and tune telemetry, integrate additional high-value log sources, enhance security dashboards, and support the rollout of additional CrowdStrike services. The effort will increase visibility into endpoint and security risk, improve signal quality and correlation, and provide security leadership with clear insight into security operations effectiveness and overall risk posture. Expected Outcomes - Expanded and optimized CrowdStrike SIEM telemetry coverage - Integration of additional high-value log sources - Improved dashboards for operational and executive visibility - Enhanced detection fidelity and monitoring effectiveness - Clearer insight for leadership into endpoint risk and security operations performance Duties to Be Performed - Assess current CrowdStrike SIEM configuration, telemetry coverage, and log ingestion - Enable and tune additional CrowdStrike telemetry to improve visibility and signal quality - Identify and integrate new high-value log sources into CrowdStrike SIEM - Develop and refine security dashboards aligned to SOC and executive use cases - Assist with technical enablement and rollout of additional CrowdStrike services - Validate data quality, parsing, and correlation within the SIEM - Coordinate with Security Operations, IT Operations, and system owners - Identify gaps, risks, and improvement opportunities in monitoring and detection - Provide weekly status updates and monthly executive-level progress summaries - Deliver supporting documentation and recommendations to sustain improvements Deliverables - Summary of work performed and capabilities delivered - Documentation supporting all telemetry enablement, log integrations, and dashboard implementations - Measurable improvements in monitoring, detection, or visibility - Recommendations for future enhancements or next-phase efforts Qualifications - Demonstrated skill with documentation, reporting, and knowledge transfer - Experience with Stakeholder Engagement and Executive Communication - Experience in SIEM Detection Engineering and Alert Optimization - Experience in Log Source Integration and Data Normalization - Hands-On Experience with CrowdStrike SIEM and Dashboard Development - Hands-On Experience with SIEM and Dashboard Development
302more opportunities are still waiting for you.Log in now and take your next shot before someone else does.
Cloud, Cyber Security, Apache, DNS, Linux, SMTP