What you'll actually do
- Monitor security alerts from SIEM, EDR, and network tools
- Triage and investigate alerts using defined playbooks
- Escalate confirmed incidents to Tier 2/3 or IR team
- Document all incident investigation activities
- Participate in threat hunting activities
- Maintain and update SOC playbooks and runbooks
Skills you need
SIEM alert triage and investigationKnowledge of common attack techniques (MITRE ATT&CK)Network traffic analysisEDR / endpoint investigationLog analysis (Windows Event Logs, Syslog)Written and verbal incident communication
Tools & platforms
Splunk / Microsoft Sentinel / QRadar (SIEM)CrowdStrike / SentinelOne / Defender (EDR)Wireshark / Zeek (network analysis)VirusTotal / AnyRun (malware analysis)TheHive / XSOAR (SOAR)
Certifications to Target
1CompTIA Security+
2CompTIA CySA+
3BTL1 (Blue Team Labs Level 1)
4GCIH (GIAC Certified Incident Handler)
Who Is a Good Fit?
- → IT Support / Helpdesk staff
- → Fresh IT/CS/Networking graduates
- → System Administrators
- → Anyone with a passion for threat hunting
Career Growth Path
1
SOC Analyst Tier 1 → Tier 2 → Tier 32
→ Threat Intelligence Analyst3
→ Incident Response Analyst4
→ SOC Lead / MSSP Manager