Cybersecurity · Security Operations
SOC Analyst
The front line of defense — watch for threats, triage alerts, and investigate what's really happening.
What you actually do
You work in a Security Operations Center monitoring alerts from security tools, deciding which are real, and investigating incidents before they become breaches. It's methodical, evidence-driven work: read logs, correlate events, follow the incident-response playbook, and write up clear findings. It is real, growing, and well-paid — but almost never a first job. You reach it through a support, networking, or systems rung, which is why this roadmap starts by building that foundation.
- •Work the alert queue — triage what the SIEM flagged overnight, dismiss the noise, escalate the real
- •Pivot through logs to reconstruct what a suspicious login actually did
- •Follow the incident-response runbook and document every step for the record
- •Tune a noisy detection rule so tomorrow's queue is cleaner
- •Hand off a confirmed incident with a clear written timeline
What the work feels like
This fits you if…
- ✓You're investigative and like digging into a pile of clues
- ✓You have a protect-and-comply instinct
- ✓You're detail-oriented and calm under pressure
Less ideal if…
- −You want to skip the IT foundation and start in security directly
- −You dislike rules, procedure, and documentation
- −You want purely creative, build-from-scratch work
Skills to build
Your roadmap
An ordered path from beginner to employable. Certifications are optional checkpoints, not the point — skills and a portfolio are.
- 1Build the IT foundation
Get comfortable with networking and systems first (see the Network Administrator or IT Support paths). Security sits on top of this — skipping it is why most beginners stall.
- 2Orient with the concepts
Microsoft SC-900 gives you the vocabulary of security, compliance, and identity cheaply and quickly.
Study guide: Microsoft SC-900 → - 3Clear the gate
Earn CompTIA Security+ — the baseline credential that unlocks SOC and analyst roles (and federal eligibility). Practice hands-on labs on TryHackMe.
Study guide: CompTIA Security+ → - 4Specialize into detection
CompTIA CySA+ for threat detection and incident response, or branch toward GRC/IAM — the more accessible security rungs.
Study guide: CompTIA CySA+ → - 5The senior tier (years in)
With ~5 years of experience, CISSP (technical-leadership breadth) or CISM (security management) become realistic — they're the credentials senior and federal postings name explicitly.
Study guide: ISC2 CISSP →
Certifications for this path
A facet of the path, not the path itself — skills and a portfolio come first.
A zero-prerequisite curriculum (Linux, SQL, Python, SIEM concepts) — with 30% off Security+ on completion, feeding the gate directly.
View study guide →A gentle, low-cost first look at security, compliance, and identity concepts.
View study guide →The recognized baseline security cert and a DoD 8570/8140 requirement — the one that gets you past filters.
View study guide →The defensive-analyst next step: threat detection and incident response for SOC roles.
View study guide →Cisco's SOC-analyst associate cert (formerly CyberOps Associate) — the alternative analyst rung, strongest in Cisco-tooling SOCs.
View study guide →The SOC-operations professional cert (formerly CyberOps Professional) — forensics or threat-hunting depth between the analyst rungs and the summit.
View study guide →The senior security credential — experience-gated (5 years), but the one management and federal roles ask for by name.
View study guide →The management-track summit: security governance, risk, and program leadership rather than hands-on defense.
View study guide →Try it this weekend
Experience entry-adjacent security work: a methodical security review of your own accounts, written up as findings.
Related paths
Not sure this is the one?
Take the free 10-minute assessment and see your three strongest IT paths.
Take the IT Career Navigator →