← Back to results

soar jobs in San Diego

$105,400 – $207,800 · Posted 1 day ago

Design and implement secure, scalable Google SecOps architectures for SIEM and SOAR deployments aligned with enterprise security policies and regulatory requirements (GDPR, PCI DSS). Lead log ingestion pipelines using data fabric technologies, develop threat detection content, translate security operations into automated SOAR playbooks, and mentor junior team members.… Requires 7+ years in security operations or threat detection engineering, hands-on experience with Google Chronicle/Siemplify, Python automation, Logstash/Gostash, ETL technologies (Cribl, Bindplane, Kafka), and familiarity with security frameworks like MITRE ATT&CK.

San DiegoLast seen today
Posted 1 day ago

Lead high-severity incident investigations, mentor L1/L2 analysts, and drive detection engineering at a cybersecurity services firm. Responsibilities include threat hunting, malware analysis, digital/network forensics, SIEM/EDR tuning (KQL, SPL, Sigma, YARA), playbook development, and automation scripting in Python/PowerShell/Bash.… This is a 5+ year senior incident responder role requiring deep hands-on expertise across the full incident response lifecycle, MITRE ATT&CK, and client-facing technical briefings.

San DiegoLast seen today
$134,500 – $265,100 · Posted 2 days ago

Lead security operations and threat detection engineering for enterprise clients using Google SecOps (Chronicle SIEM and Siemplify SOAR). Design and deploy log ingestion pipelines, develop threat detection rules, translate SOC processes into automated playbooks, and manage integrations across security platforms.… Mentor junior SOC engineers and collaborate with threat detection teams to reduce alert fatigue and scale response capabilities.

San DiegoLast seen today
$120,000 – $150,000 · Posted 25 days ago

A senior DevSecOps engineer will design and operate an automated compliance and AI-driven security platform for DoD and federal healthcare environments. The role demands expertise in DISA STIG automation, container security, RMF/FedRAMP workflows, and SIEM/SOAR integration, with responsibilities spanning secure CI/CD pipeline development, Wazuh and Elastic Stack deployment, OpenRMF automation, and LLM-assisted security operations.… The engineer will build hardened base images, maintain compliance pipelines, develop Tines SOAR workflows, and mentor others on architecture decisions.

San DiegoLast seen 5 days ago
Posted 1 month ago

Security Operations Analyst role monitoring and triaging alerts across endpoint, cloud, identity, network, and SaaS using enterprise SIEM and XDR platforms. Responsibilities include investigating alerts, performing root-cause analysis, tuning detections, owning initial response for mid-tier incidents, participating in on-call rotation, running targeted threat hunts, and contributing to playbooks and post-incident reviews.… Requires 2–5 years of hands-on SecOps, SOC, or incident response experience; proficiency with enterprise SIEM query languages, EDR tooling, and scripting in Python/PowerShell/Bash; and solid understanding of MITRE ATT&CK and network fundamentals.

San DiegoLast seen 1 month ago
$113,200 – $141,500 · Posted 1 month ago

This Cybersecurity Manager role owns vulnerability and exposure management, leads penetration testing, threat hunting, and threat intelligence programs. The position integrates AI and machine learning into security operations to enhance threat detection and anomaly identification, manages security tools and incident response, and ensures the security of AI/ML systems across the enterprise.… The candidate will develop automation scripts and SOAR workflows, conduct forensic investigations, and drive continuous improvement in the security posture. Required qualifications include 5+ years of cybersecurity experience, a relevant bachelor's degree, and an industry-recognized certification (Security+, SSCP, CCNP Security, CISSP, or equivalent).

San DiegoLast seen 1 month ago
Posted 1 month ago

Lead detection operations, incident response, and security operations maturation for a growing security team. Operate SIEM/XDR across endpoint, cloud, identity, network, and SaaS telemetry; conduct complex investigations; tune detections; and drive root-cause analysis and post-incident improvements.… Require 6+ years of hands-on security operations, detection engineering, or incident response experience with deep proficiency in SIEM/XDR query languages, EDR platforms, scripting (Python, PowerShell, Bash), and MITRE ATT&CK framework application. Mentor analysts, define playbooks and runbooks, lead threat hunts, and own SecOps metrics and operational-readiness reporting.

San DiegoLast seen 1 month ago
$200,000 – $240,000 · Posted 1 month ago

Director leading a pre-sales security engineering team responsible for technical strategy, solution design, and customer-facing support across EVOTEK's cybersecurity portfolio. The role combines deep technical security expertise with people leadership, requiring mentorship of engineers/architects, oversight of enterprise solution design and proof-of-concept engagements, and alignment of technical capabilities with sales and delivery practices.… Responsibilities include RFP response, competitive positioning, vendor management, and technical presentations spanning AI security, network security, cloud security, identity & access management, endpoint/XDR, SIEM/SOAR, zero-trust architecture, and data protection. Must understand the VAR business model and translate complex technical capabilities into business value for enterprise stakeholders.

San DiegoLast seen 1 month ago