Careersbeginnercareer guide

SOC Analyst

What a SOC analyst does hour to hour, the skills that get you hired, and the realistic route from tier 1 to detection engineering.

Cyber Security Space editorial desk · Published 4 Aug 2026 · Updated 29 Aug 2026 · 2 min read · Reviewed 29 Aug 2026

Short answer

A SOC analyst monitors security alerts from a SIEM and endpoint tooling, triages them to separate real incidents from noise, escalates confirmed incidents with documented evidence, and feeds tuning suggestions back into detection rules. It is the most common entry point into a security career.

Key takeaways

  • Triage quality — not tool knowledge — is what distinguishes a strong tier 1 analyst.
  • Clear written handovers are a core deliverable, because incidents cross shifts.
  • Log fluency transfers across employers far better than any single SIEM product.
  • The usual progression is tier 1 triage, then tier 2 investigation, then detection engineering or incident response.

What does a SOC analyst do day to day?

  • Work the alert queue in priority order and record a verdict with evidence for each alert.
  • Pivot across log sources — identity, endpoint, network, email — to build the sequence of events.
  • Escalate confirmed incidents with a timeline the next responder can act on immediately.
  • Report false positive patterns so rules can be tuned rather than muted.
  • Contribute to runbooks so the same investigation is faster next time.

What skills do employers actually test?

SkillHow it is assessed
Log readingYou are handed raw logs and asked what happened
Network fundamentalsDNS, TLS and HTTP questions applied to an alert
Operating system internalsProcess trees, persistence locations, permissions
Written communicationA short incident summary you write during the interview
Triage disciplineWhether you follow evidence or jump to conclusions

Which tools are commonly used?

  • A SIEM for search and correlation, such as Splunk, Elastic or a cloud-native equivalent.
  • An EDR platform for endpoint telemetry and containment.
  • A ticketing or case management system where the audit trail lives.
  • Threat intelligence lookups and sandboxing for indicator enrichment.
  • Sigma or the platform's own rule language for detection changes.

What does the learning path look like?

  1. STEP 01

    Fundamentals

    Networking, Linux and Windows administration, and where logs are produced.

  2. STEP 02

    Home SIEM

    Ship logs from two virtual machines into a free-tier SIEM and hunt your own test activity.

  3. STEP 03

    Detection practice

    Write and tune Sigma rules; document the false positives you create and remove.

  4. STEP 04

    Baseline certification

    A vendor-neutral foundation such as CompTIA Security+ clears most screening filters.

  5. STEP 05

    Public write-ups

    Publish investigations that show hypothesis, evidence and conclusion.

Frequently asked questions

Is SOC analyst a good entry-level role?
Yes. It is the most common first security job because it teaches log fluency, triage discipline and incident communication at volume, all of which transfer to other specialisms.
Do SOC analysts work night shifts?
Many 24/7 teams rotate shifts, though follow-the-sun models and business-hours-only SOCs are increasingly common. Ask about the rota pattern before accepting an offer.
What is the difference between tier 1 and tier 2?
Tier 1 triages alerts against runbooks and escalates. Tier 2 investigates the escalations end to end, performs deeper analysis, and drives detection improvements.

Sources

Read next

  • Careers

    Security Analyst

    A broader remit than the SOC: risk, controls, vulnerabilities and awareness. What the title really covers, and how to read the job advert.

  • Careers

    How to Start a Cybersecurity Career

    The sequence that keeps working: fundamentals, one specialism, demonstrable work, then applications aimed at roles that actually hire juniors.

  • Careers

    Free Cybersecurity Training That Is Actually Useful

    Free material that teaches transferable skill rather than badge collection, grouped by what it prepares you to do.

  • Jobs

    Security jobs board

    Current openings across SOC, cloud, application security and GRC roles.