SOC Analyst
What a SOC analyst does hour to hour, the skills that get you hired, and the realistic route from tier 1 to detection engineering.
Cyber Security Space editorial desk · Published 4 Aug 2026 · Updated 29 Aug 2026 · 2 min read · Reviewed 29 Aug 2026
Short answer
A SOC analyst monitors security alerts from a SIEM and endpoint tooling, triages them to separate real incidents from noise, escalates confirmed incidents with documented evidence, and feeds tuning suggestions back into detection rules. It is the most common entry point into a security career.
Key takeaways
- Triage quality — not tool knowledge — is what distinguishes a strong tier 1 analyst.
- Clear written handovers are a core deliverable, because incidents cross shifts.
- Log fluency transfers across employers far better than any single SIEM product.
- The usual progression is tier 1 triage, then tier 2 investigation, then detection engineering or incident response.
What does a SOC analyst do day to day?
- Work the alert queue in priority order and record a verdict with evidence for each alert.
- Pivot across log sources — identity, endpoint, network, email — to build the sequence of events.
- Escalate confirmed incidents with a timeline the next responder can act on immediately.
- Report false positive patterns so rules can be tuned rather than muted.
- Contribute to runbooks so the same investigation is faster next time.
What skills do employers actually test?
| Skill | How it is assessed |
|---|---|
| Log reading | You are handed raw logs and asked what happened |
| Network fundamentals | DNS, TLS and HTTP questions applied to an alert |
| Operating system internals | Process trees, persistence locations, permissions |
| Written communication | A short incident summary you write during the interview |
| Triage discipline | Whether you follow evidence or jump to conclusions |
Which tools are commonly used?
- A SIEM for search and correlation, such as Splunk, Elastic or a cloud-native equivalent.
- An EDR platform for endpoint telemetry and containment.
- A ticketing or case management system where the audit trail lives.
- Threat intelligence lookups and sandboxing for indicator enrichment.
- Sigma or the platform's own rule language for detection changes.
What does the learning path look like?
STEP 01
Fundamentals
Networking, Linux and Windows administration, and where logs are produced.
STEP 02
Home SIEM
Ship logs from two virtual machines into a free-tier SIEM and hunt your own test activity.
STEP 03
Detection practice
Write and tune Sigma rules; document the false positives you create and remove.
STEP 04
Baseline certification
A vendor-neutral foundation such as CompTIA Security+ clears most screening filters.
STEP 05
Public write-ups
Publish investigations that show hypothesis, evidence and conclusion.
Frequently asked questions
- Is SOC analyst a good entry-level role?
- Yes. It is the most common first security job because it teaches log fluency, triage discipline and incident communication at volume, all of which transfer to other specialisms.
- Do SOC analysts work night shifts?
- Many 24/7 teams rotate shifts, though follow-the-sun models and business-hours-only SOCs are increasingly common. Ask about the rota pattern before accepting an offer.
- What is the difference between tier 1 and tier 2?
- Tier 1 triages alerts against runbooks and escalates. Tier 2 investigates the escalations end to end, performs deeper analysis, and drives detection improvements.
Sources
- NICE Workforce Framework for Cybersecurity — NIST / NICCSSupports: Task and skill groupings for defensive analysis roles.
Read next
Careers
Security AnalystA broader remit than the SOC: risk, controls, vulnerabilities and awareness. What the title really covers, and how to read the job advert.
Careers
How to Start a Cybersecurity CareerThe sequence that keeps working: fundamentals, one specialism, demonstrable work, then applications aimed at roles that actually hire juniors.
Careers
Free Cybersecurity Training That Is Actually UsefulFree material that teaches transferable skill rather than badge collection, grouped by what it prepares you to do.
Jobs
Security jobs boardCurrent openings across SOC, cloud, application security and GRC roles.