Skip to content
Cyber Recrut

Becoming a SOC analyst: skills and first roles

How to become a SOC analyst: what the job really involves, the skills to build, the paths in, the home lab, and how to land your first role in a SOC.

Published on 7 min read

The SOC is one of the most common ways into cybersecurity. It is also a job that is often poorly described: neither a passive monitoring room nor a role reserved for experts. This guide explains what a SOC analyst actually does, the skills to build, the paths that lead there and how to land a first role.

The job, day to day

A SOC (Security Operations Center) monitors an organisation's systems to detect attacks and respond to them. Analysts receive alerts from a SIEM, an EDR or other detection tools, and have to decide quickly what they mean.

A typical day looks like this:

  • Triaging alerts: false positive, legitimate but unusual behaviour, or a real incident.
  • Investigating: going through the logs to reconstruct what happened on a host or an account.
  • Escalating: handing an incident to the next tier or to the incident response team, with a clear ticket.
  • Documenting: recording what was checked, so the next shift can pick it up without losing time.
  • Improving: flagging noisy rules, suggesting tuning, enriching the playbooks.

The work is usually done as a team, sometimes in shifts or with on-call duties. That is worth looking at closely before you apply; more on it below.

Tier 1, 2, 3: what to expect

Most SOCs organise analysts into tiers. Titles differ from one organisation to the next, but the logic is similar.

TierWhat you are givenWhat is expected of you
Tier 1Monitoring, first-pass triage, following playbooksRigour, method, clear tickets, knowing when to escalate
Tier 2Investigating escalated incidents, correlating several sourcesClose reading of logs, EDR fluency, investigative reasoning
Tier 3Complex incidents, threat hunting, detection rulesKnowledge of attack techniques, detection engineering, mentoring

A first role is most often at Tier 1, sometimes Tier 2 if you come from a closely related technical job. Starting at Tier 1 is nothing to worry about: it is where you learn to read a real environment, and moving up depends mostly on your curiosity and the quality of your investigations.

The skills to build

Job ads often list a long string of tools. In practice, teams are mostly looking for solid foundations and a way of reasoning. A tool takes a few weeks to learn; reasoning takes much longer.

Technical foundations

  • Systems: how Windows and Linux work, processes, services, scheduled tasks, accounts and permissions.
  • Active Directory: authentication, privileged groups, logon events. A large share of corporate incidents go through it.
  • Networking: TCP/IP, DNS, HTTP, proxies, firewalls. Being able to spot unusual outbound traffic.
  • Logs: knowing where the information lives, what a log shows and, above all, what it does not.

SOC-specific skills

  • SIEM queries: filtering, aggregating, pivoting from one indicator to the next. The language (SPL, KQL or another) matters less than the logic.
  • Reading an EDR: following a process tree, spotting a suspicious command line.
  • Attack techniques: phishing, credential theft, lateral movement, persistence. The MITRE ATT&CK framework helps structure what you know.
  • Triage: deciding fast and justifying the decision. Escalating everything is as much a problem as escalating nothing.

The skills people forget

Writing matters a great deal. A good ticket says in a few lines what happened, what was checked and what remains to be done. Add the ability to say "I don't know, I'll check", staying calm during an incident, and enough English to read documentation and technical reports.

Paths into the SOC

There is no single route. SOC teams welcome varied profiles, as long as the foundations are there.

  1. A degree in IT or cybersecurity: from a technical diploma to an engineering or master's degree. Work-study programmes are an excellent accelerator, because they give you real-world experience early.
  2. A move from a technical role: system and network administrators, support technicians, operations engineers. You already know an IT estate, its tools and its incidents; what is left is to adopt the attacker's and defender's view.
  3. A move from a non-technical role: possible, but longer. Plan for serious training, a lot of personal practice, and aim first for Tier 1 roles or organisations that train their people.

If you are in the second or third case, our article on hiring career changers shows what employers look at on their side.

Practise: the home lab and training platforms

Nothing replaces practice, and it is what sets you apart from other candidates with a similar background. The good news: you can build it at home.

Building a home lab

A modest setup is enough to start:

  • an Active Directory domain controller and one or two Windows workstations as virtual machines;
  • a log collection tool or a SIEM with a free edition;
  • advanced logging on the Windows hosts;
  • a few simulated attacks that you run yourself and then try to detect.

Write up what you do: what you attacked, what you saw in the logs, what you missed. That documentation becomes excellent material for interviews.

Training platforms

CTF and defensive training platforms offer investigation, log analysis and forensics scenarios. Favour the defensive categories (log analysis, forensics, detection) over offensive challenges alone, and write up what you solve. If attacking is what draws you, our guide to becoming a pentester covers that path.

Certifications

A certification can help you get past a filter and shows a learning effort, but it does not replace practice. Pick one aligned with the role you want, ideally with a hands-on exam. Our article on cybersecurity certifications helps you sort through them.

Landing your first role

Where to apply

  • MSSPs and managed service providers: they regularly hire Tier 1 analysts and give strong exposure to varied environments.
  • In-house SOCs at large organisations: usually more structured, with established playbooks and supervision.
  • Work-study and internships: a very effective way in if you are still studying.
  • Adjacent roles: second-line support, security tooling administration, IT operations. They can be a stepping stone to an internal SOC move.

A CV that shows practice

Highlight your home lab, your write-ups and what you can actually do, rather than a list of tools. Our guide to writing a strong cybersecurity CV walks through the method, with rewrite examples.

Preparing for interviews

Expect a scenario: an alert, a few logs, and the question "what do you do?". Your method is assessed more than the right answer. Practise reasoning out loud, stating hypotheses and saying what you would check next. Our guide to acing a technical cybersecurity interview and our incident response interview questions give you realistic scenarios.

Questions to ask before you accept

A first SOC role shapes much of your progression. Before signing, ask:

  • What hours, rotations and on-call duties, and how are they compensated?
  • How does onboarding work: pairing, training, documentation?
  • What is the path from Tier 1 to Tier 2, and on what criteria?
  • Is the SOC drowning in false positives, and is tuning work under way?
  • Will I eventually get to do threat hunting or write detection rules?

Pay varies widely with tier, region, sector and the weight of on-call duties. Compare offers on all of these criteria, not salary alone.

In short

Becoming a SOC analyst takes solid foundations in systems, networking and logs, a real investigative method and good writing. Tools come after. Build a home lab, document your practice, aim for a first role that will help you grow, and choose it knowing the working conditions.

Aiming for a SOC role? Join the Cyber Recrut network for free: our shortlisted candidates prove their skills on hands-on labs, which lets motivated profiles stand out for what they can actually do. See how we work.

Related articles