Jobs · Information Technology · Texas

Cybersecurity Operations Center Engineer

Texas Health and Human Services · Austin, TX · Today
Information Technology$7k–$12k/moFull-time

Date: Aug 20, 2026

Location: Austin, TX 78751 (701 W 51st St)

About the role

The Cybersecurity Analyst III (Cybersecurity Operations Center Engineer) performs senior‑level cybersecurity engineering work with emphasis on security operations engineering, security platform administration, detection engineering, automation, orchestration, and cybersecurity infrastructure integration. The role supports agency on‑premises and cloud environments by designing, implementing, maintaining, and enhancing security technologies used to protect systems, applications, hosts, networks, cloud services, and data. The position also participates in incident response and serves as a critical technical resource for security monitoring and threat detection.

Responsibilities

  • Security Operations Engineering & Platform Administration (35%): Administer, maintain, and optimize enterprise cybersecurity technologies; design, implement, and support SIEM, EDR/XDR, SOAR, threat‑intelligence, identity‑protection, cloud security, email security, network security, and vulnerability‑management platforms; manage configurations, data‑ingestion pipelines, integrations, scalability, availability, and operational health; develop logging standards and telemetry‑collection strategies; perform platform upgrades and lifecycle maintenance.
  • Detection Engineering & Security Automation (25%): Design, develop, and maintain security detections, correlation searches, behavioral analytics, dashboards, reports, and threat‑hunting content; create automation workflows and orchestration solutions; develop MITRE ATT&CK‑aligned use cases; enhance alert quality through tuning, enrichment, and suppression; manage detection‑as‑code and content processes; apply scripting to automate repeatable tasks.
  • Security Integration & Data Engineering (20%): Integrate security technologies and data sources into monitoring platforms; collaborate with infrastructure, cloud, identity, networking, and application teams to onboard new systems; develop data normalization, enrichment, correlation, and reporting solutions; ensure visibility across cloud, endpoint, network, application, middleware, database, and authentication systems; identify telemetry gaps and implement improvements.
  • Engineering Strategy & Collaboration (10%): Evaluate emerging security technologies; participate in architecture reviews, project consultations, and cybersecurity planning; support incident response with subject‑matter expertise; provide technical guidance and mentorship to analysts, engineers, and project teams.
  • Other Duties (10%): Perform additional cybersecurity engineering activities such as special projects, proof‑of‑concept evaluations, process improvements, operational‑readiness initiatives, audit support, and agency modernization efforts.

Knowledge, Skills, and Abilities

  • Security Operations Center architecture, processes, and monitoring methodologies.
  • Experience with SIEM, SOAR, EDR/XDR, NDR, IPS/IDS, NGFW, threat intelligence, cloud security, identity security, and vulnerability‑management technologies.
  • Enterprise logging, event collection, correlation, and security‑analytics principles.
  • Automation technologies, scripting, APIs, and systems‑integration practices.
  • Cloud computing architectures, IAM, networking, operating systems, and enterprise security controls.
  • Familiarity with MITRE ATT&CK framework, threat landscapes, and defensive engineering concepts.
  • Understanding of security frameworks and standards such as NIST Cybersecurity Framework, NIST 800‑53, CIS Controls, and Texas state requirements (TAC Chapter 202).
  • Proficiency in security‑platform administration, detection engineering, scripting, data analysis, troubleshooting, technical documentation, and technology evaluation.
  • Ability to design, implement, and maintain enterprise monitoring capabilities; process large security data sets; analyze complex environments; develop scalable solutions; communicate to technical and non‑technical audiences; collaborate across teams; manage multiple projects simultaneously.

Qualifications

  • Preferred: Bachelor’s degree in information‑technology security, computer information systems, computer science, management information systems, or a related field (education and experience may be substituted).
  • Minimum 5+ years of experience in IT, cybersecurity engineering, SIEM administration, security operations, detection engineering, systems/network administration, or related disciplines.
  • Experience working in a Security Operations Center (SOC) and with at least one SIEM platform.
  • Experience with security‑operations automation.
  • Preferred certifications (one or more): CISSP, Microsoft SC‑200, GIAC GMON, GIAC GCDA, GIAC GCED, Splunk Enterprise Security Admin, Splunk Core Power User, CompTIA CySA+.
  • U.S. citizenship or permanent residency; must be legally authorized to work in the U.S. without sponsorship.
  • Willingness to commute to the Austin office and work onsite.

Benefits

  • 100% paid employee health insurance for full‑time eligible employees.
  • Defined benefit pension plan.
  • Generous time‑off benefits.
  • Opportunities for career advancement.
  • Additional benefits detailed on the “Benefits of Working at HHS” webpage.

Pay

Salary range: $7,015.16 – $11,864.50 per month (pay frequency: monthly). Salary determined in accordance with budgetary limits and HHSC Human Resources Manual.

Schedule

Full‑time, exempt position. Day shift (first shift) with regular/temporary telework as applicable.

Similar jobs