Career roadmap
Security Analyst (SOC)
Watch, triage and escalate: the front line that decides whether an alert becomes an incident.
Before you start SOC Analyst
- Networking basics: ports, protocols, DNS
- Windows and Linux familiarity
- Attention to detail and clear writing
Foundations
Understand what you are looking at before learning the console that displays it.
Most alerts are network events. Reading them requires protocol knowledge.
- TCP/IP, common ports and services
- DNS queries as an investigation signal
- HTTP and TLS metadata
- Reading a packet capture
Knowing what normal looks like is what makes abnormal visible.
- Windows processes, services and registry
- Linux processes, cron and systemd
- Authentication logs on both
- Normal versus suspicious parent-child chains
The kill chain gives structure to what would otherwise be a list of alerts.
- Cyber kill chain and ATT&CK tactics
- Phishing and initial access
- Privilege escalation and persistence
- Lateral movement and exfiltration
Knowing which log answers which question is the core analyst skill.
- Windows event ids that matter
- Sysmon and enhanced telemetry
- Firewall, proxy and DNS logs
- Cloud audit trails
SIEM, EDR and ticketing — the three windows an analyst lives in.
- SIEM search syntax and pivoting
- EDR console investigation
- Ticketing and case management
- Threat intel lookups
BuildSet up a small lab with a SIEM, ingest logs from two hosts, and write your first five queries.
Triage and investigation
The daily work: decide fast and correctly whether an alert matters.
Speed with accuracy. A repeatable method is what interviews assess.
- Triage methodology and time-boxing
- True positive, false positive, benign true positive
- Severity assignment
- When to escalate immediately
Pivoting through data to build a timeline is the skill that gets you promoted.
- Pivoting on user, host, IP and hash
- Building an incident timeline
- Scoping: how far did it spread
- Knowing when you have enough
The highest-volume alert type in almost every SOC.
- Header analysis and spoofing indicators
- Safe URL and attachment detonation
- Identifying affected recipients
- Takedown and containment actions
Basic static and dynamic analysis, without becoming a reverse engineer.
- Hash reputation and sandboxing
- Static indicators and strings
- Behavioural analysis in a sandbox
- When to escalate to specialists
An investigation nobody can follow is an investigation that gets repeated.
- Clear case notes with evidence
- Shift handover discipline
- Escalation write-ups
- Reporting to non-technical stakeholders
BuildWork through fifty simulated alerts and write a triage decision with evidence for each.
Detection and hunting
Move from reacting to alerts to finding what the alerts missed.
Hypothesis-driven search. The step that separates analyst tiers.
- Forming a testable hypothesis
- Hunting with ATT&CK techniques
- Baselining normal behaviour
- Documenting hunts that found nothing
Turning a hunt into a rule is how a SOC gets better over time.
- Sigma rule structure
- Precision versus recall trade-offs
- Testing rules with simulated activity
- Documenting rule intent
Alert fatigue causes missed incidents. Tuning is a safety activity.
- Measuring false positive rates
- Suppression versus fixing the rule
- Allow-listing safely
- Reviewing rule performance regularly
Applying intel to your own environment rather than collecting feeds.
- IOC sweeps across the estate
- Actor TTPs and relevance filtering
- Retrospective searching
- Intel-driven hunt prioritisation
Testing your detections against real technique execution.
- Atomic Red Team execution
- Detection gap identification
- Working with offensive teams
- Coverage reporting
BuildRun three threat hunts with written hypotheses, and turn one finding into a permanent detection.
Incident response
When triage becomes an incident, the analyst is often the first responder.
Structure prevents panic. This is the most common SOC interview scenario.
- Detection through recovery lifecycle
- Roles during an incident
- Containment decisions and their cost
- Evidence preservation basics
Isolating a host is easy; deciding when to is the judgement being tested.
- Host isolation and account disable
- Blocking at network and email layers
- Balancing business disruption
- Avoiding tipping off the attacker
The scenario every organisation rehearses and every interview mentions.
- Early indicators before encryption
- Backup integrity verification
- Communication and legal obligations
- Recovery sequencing
Closing the loop so the same incident does not recur.
- Timeline and root cause
- Detection gaps identified
- Control improvements
- Metrics: time to detect and respond
How the team is measured, and which metrics create bad incentives.
- MTTD and MTTR
- Alert volume and closure rates
- Detection coverage
- Metrics that encourage rushing
BuildRun a tabletop exercise for a ransomware scenario and write the after-action report.
Certification and interviews
SOC hiring uses practical labs and scenario questions more than theory.
Security+ and a hands-on blue team certification is a strong entry combination.
- CompTIA Security+ and CySA+
- Blue Team Level 1 and similar practical certs
- Vendor SIEM certifications
- Matching certs to local job ads
Hands-on platforms are the accepted way to prove ability without experience.
- TryHackMe and Blue Team labs
- LetsDefend style alert handling
- CTF blue team challenges
- Building your own detection lab
Expect to be handed an alert and asked what you would do next.
- Walk through a suspicious login alert
- Investigate unusual outbound traffic
- Explain how you would scope a compromise
- Describe a detection you wrote
Fundamentals get tested directly: ports, protocols, and attack mechanics.
- Common ports and what runs on them
- How DNS tunnelling looks in logs
- Windows event ids for authentication
- Difference between IDS and IPS
SOC is a starting point. Know where you are heading and prepare for it early.
- Path to detection engineering
- Path to incident response and forensics
- Path to threat intelligence
- Path to red team
BuildA portfolio of investigation write-ups and published detection rules.
SOC Analyst tools on your CV
- Splunk / Elastic / Sentinel
- Sysmon
- Wireshark
- MITRE ATT&CK
- Sigma
- Atomic Red Team
- VirusTotal
- TheHive
What SOC Analyst employers ask to see
- A set of published investigation write-ups
- Detection rules you wrote and tested
- A documented threat hunt with hypothesis and outcome
- A practical blue team certification
One of the few genuine entry points into security, with unemployment around 2.7%. High volume of openings, and a clear progression into detection engineering or incident response.
Content last reviewed 2026-08-31. Guidance only — no institute or paid placement is endorsed anywhere in this book.