Cybersecurity · Security Operations

SOC Analyst

The front line of defense — watch for threats, triage alerts, and investigate what's really happening.

SOC Analyst ISecurity AnalystIncident Response Analyst (Jr)GRC AnalystIAM Analyst
$124,910 median · +29% — one of the fastest-growing IT occupations
SOC I ~$55,000–$75,000; GRC ~$60,000–$80,000 to start. U.S. BLS figure for Information Security Analysts (15-1212); BLS notes these roles typically require prior related experience, so treat the median as a mid-career number and verify against the live source.
Is this you? Take the free assessment

What you actually do

You work in a Security Operations Center monitoring alerts from security tools, deciding which are real, and investigating incidents before they become breaches. It's methodical, evidence-driven work: read logs, correlate events, follow the incident-response playbook, and write up clear findings. It is real, growing, and well-paid — but almost never a first job. You reach it through a support, networking, or systems rung, which is why this roadmap starts by building that foundation.

  • Work the alert queue — triage what the SIEM flagged overnight, dismiss the noise, escalate the real
  • Pivot through logs to reconstruct what a suspicious login actually did
  • Follow the incident-response runbook and document every step for the record
  • Tune a noisy detection rule so tomorrow's queue is cleaner
  • Hand off a confirmed incident with a clear written timeline

What the work feels like

CommunicationHigh
Technical depthHigh
TroubleshootingHigh
Customer contactMedium
On-callHigh
Remote-friendlyHigh

This fits you if…

  • You're investigative and like digging into a pile of clues
  • You have a protect-and-comply instinct
  • You're detail-oriented and calm under pressure

Less ideal if…

  • You want to skip the IT foundation and start in security directly
  • You dislike rules, procedure, and documentation
  • You want purely creative, build-from-scratch work
The honest downsides: 'Entry-level' listings routinely demand 2–3 years, and the gate is crowded. SOC work is shift-based with alert fatigue. The honest route in is through help desk, networking, or sysadmin first — plan for that, don't fight it.

Skills to build

IT & networking fundamentals Foundational You can't defend what you don't understand — this is the prerequisite most beginners skip.
Operating systems & logging (Windows/Linux) Foundational
Security concepts (CIA, controls, threats) Foundational
Log analysis & SIEM basics Working Read events, correlate, spot the anomaly.
Incident response process Working
Identity & access fundamentals (IAM) Working
Scripting for security automation Emerging
SIEM (Splunk / Sentinel)EDRWindows Event LogsLinux / syslogMITRE ATT&CKOkta / Entra ID

Your roadmap

An ordered path from beginner to employable. Certifications are optional checkpoints, not the point — skills and a portfolio are.

  1. 1
    Build the IT foundation

    Get comfortable with networking and systems first (see the Network Administrator or IT Support paths). Security sits on top of this — skipping it is why most beginners stall.

  2. 2
    Orient with the concepts

    Microsoft SC-900 gives you the vocabulary of security, compliance, and identity cheaply and quickly.

    Study guide: Microsoft SC-900 →
  3. 3
    Clear the gate

    Earn CompTIA Security+ — the baseline credential that unlocks SOC and analyst roles (and federal eligibility). Practice hands-on labs on TryHackMe.

    Study guide: CompTIA Security+ →
  4. 4
    Specialize into detection

    CompTIA CySA+ for threat detection and incident response, or branch toward GRC/IAM — the more accessible security rungs.

    Study guide: CompTIA CySA+ →
  5. 5
    The senior tier (years in)

    With ~5 years of experience, CISSP (technical-leadership breadth) or CISM (security management) become realistic — they're the credentials senior and federal postings name explicitly.

    Study guide: ISC2 CISSP →

Certifications for this path

A facet of the path, not the path itself — skills and a portfolio come first.

Try it this weekend

Experience entry-adjacent security work: a methodical security review of your own accounts, written up as findings.

Free 60–90 minutes Fully local — review your own accounts only; nothing installed or transmitted.

Related paths

Not sure this is the one?

Take the free 10-minute assessment and see your three strongest IT paths.

Take the IT Career Navigator →