JPJobPrepfull-stack interview
RoadmapsJS CompilerStar on GitHub

Career roadmap

Security Analyst (SOC)

Watch, triage and escalate: the front line that decides whether an alert becomes an incident.

Time
4-7 months part-time
Entry bar
IT support or networking background is enough. The most accessible security role.
Stages
5 · 25 topics
0/25 studied0%

Before you start SOC Analyst

  • Networking basics: ports, protocols, DNS
  • Windows and Linux familiarity
  • Attention to detail and clear writing

Foundations

4-5 weeks · 0/5 topics

Understand what you are looking at before learning the console that displays it.

  1. Most alerts are network events. Reading them requires protocol knowledge.

    • TCP/IP, common ports and services
    • DNS queries as an investigation signal
    • HTTP and TLS metadata
    • Reading a packet capture
  2. Knowing what normal looks like is what makes abnormal visible.

    • Windows processes, services and registry
    • Linux processes, cron and systemd
    • Authentication logs on both
    • Normal versus suspicious parent-child chains
  3. The kill chain gives structure to what would otherwise be a list of alerts.

    • Cyber kill chain and ATT&CK tactics
    • Phishing and initial access
    • Privilege escalation and persistence
    • Lateral movement and exfiltration
  4. Knowing which log answers which question is the core analyst skill.

    • Windows event ids that matter
    • Sysmon and enhanced telemetry
    • Firewall, proxy and DNS logs
    • Cloud audit trails
  5. SIEM, EDR and ticketing — the three windows an analyst lives in.

    • SIEM search syntax and pivoting
    • EDR console investigation
    • Ticketing and case management
    • Threat intel lookups

BuildSet up a small lab with a SIEM, ingest logs from two hosts, and write your first five queries.

Triage and investigation

5-6 weeks · 0/5 topics

The daily work: decide fast and correctly whether an alert matters.

  1. Speed with accuracy. A repeatable method is what interviews assess.

    • Triage methodology and time-boxing
    • True positive, false positive, benign true positive
    • Severity assignment
    • When to escalate immediately
  2. Pivoting through data to build a timeline is the skill that gets you promoted.

    • Pivoting on user, host, IP and hash
    • Building an incident timeline
    • Scoping: how far did it spread
    • Knowing when you have enough
  3. The highest-volume alert type in almost every SOC.

    • Header analysis and spoofing indicators
    • Safe URL and attachment detonation
    • Identifying affected recipients
    • Takedown and containment actions
  4. Basic static and dynamic analysis, without becoming a reverse engineer.

    • Hash reputation and sandboxing
    • Static indicators and strings
    • Behavioural analysis in a sandbox
    • When to escalate to specialists
  5. An investigation nobody can follow is an investigation that gets repeated.

    • Clear case notes with evidence
    • Shift handover discipline
    • Escalation write-ups
    • Reporting to non-technical stakeholders

BuildWork through fifty simulated alerts and write a triage decision with evidence for each.

Detection and hunting

4-6 weeks · 0/5 topics

Move from reacting to alerts to finding what the alerts missed.

  1. Hypothesis-driven search. The step that separates analyst tiers.

    • Forming a testable hypothesis
    • Hunting with ATT&CK techniques
    • Baselining normal behaviour
    • Documenting hunts that found nothing
  2. Turning a hunt into a rule is how a SOC gets better over time.

    • Sigma rule structure
    • Precision versus recall trade-offs
    • Testing rules with simulated activity
    • Documenting rule intent
  3. Alert fatigue causes missed incidents. Tuning is a safety activity.

    • Measuring false positive rates
    • Suppression versus fixing the rule
    • Allow-listing safely
    • Reviewing rule performance regularly
  4. Applying intel to your own environment rather than collecting feeds.

    • IOC sweeps across the estate
    • Actor TTPs and relevance filtering
    • Retrospective searching
    • Intel-driven hunt prioritisation
  5. Testing your detections against real technique execution.

    • Atomic Red Team execution
    • Detection gap identification
    • Working with offensive teams
    • Coverage reporting

BuildRun three threat hunts with written hypotheses, and turn one finding into a permanent detection.

Incident response

3-5 weeks · 0/5 topics

When triage becomes an incident, the analyst is often the first responder.

  1. Structure prevents panic. This is the most common SOC interview scenario.

    • Detection through recovery lifecycle
    • Roles during an incident
    • Containment decisions and their cost
    • Evidence preservation basics
  2. Isolating a host is easy; deciding when to is the judgement being tested.

    • Host isolation and account disable
    • Blocking at network and email layers
    • Balancing business disruption
    • Avoiding tipping off the attacker
  3. The scenario every organisation rehearses and every interview mentions.

    • Early indicators before encryption
    • Backup integrity verification
    • Communication and legal obligations
    • Recovery sequencing
  4. Closing the loop so the same incident does not recur.

    • Timeline and root cause
    • Detection gaps identified
    • Control improvements
    • Metrics: time to detect and respond
  5. How the team is measured, and which metrics create bad incentives.

    • MTTD and MTTR
    • Alert volume and closure rates
    • Detection coverage
    • Metrics that encourage rushing

BuildRun a tabletop exercise for a ransomware scenario and write the after-action report.

Certification and interviews

3-4 weeks · 0/5 topics

SOC hiring uses practical labs and scenario questions more than theory.

  1. Security+ and a hands-on blue team certification is a strong entry combination.

    • CompTIA Security+ and CySA+
    • Blue Team Level 1 and similar practical certs
    • Vendor SIEM certifications
    • Matching certs to local job ads
  2. Hands-on platforms are the accepted way to prove ability without experience.

    • TryHackMe and Blue Team labs
    • LetsDefend style alert handling
    • CTF blue team challenges
    • Building your own detection lab
  3. Expect to be handed an alert and asked what you would do next.

    • Walk through a suspicious login alert
    • Investigate unusual outbound traffic
    • Explain how you would scope a compromise
    • Describe a detection you wrote
  4. Fundamentals get tested directly: ports, protocols, and attack mechanics.

    • Common ports and what runs on them
    • How DNS tunnelling looks in logs
    • Windows event ids for authentication
    • Difference between IDS and IPS
  5. SOC is a starting point. Know where you are heading and prepare for it early.

    • Path to detection engineering
    • Path to incident response and forensics
    • Path to threat intelligence
    • Path to red team

BuildA portfolio of investigation write-ups and published detection rules.

SOC Analyst tools on your CV

  • Splunk / Elastic / Sentinel
  • Sysmon
  • Wireshark
  • MITRE ATT&CK
  • Sigma
  • Atomic Red Team
  • VirusTotal
  • TheHive

What SOC Analyst employers ask to see

  • A set of published investigation write-ups
  • Detection rules you wrote and tested
  • A documented threat hunt with hypothesis and outcome
  • A practical blue team certification

One of the few genuine entry points into security, with unemployment around 2.7%. High volume of openings, and a clear progression into detection engineering or incident response.

Content last reviewed 2026-08-31. Guidance only — no institute or paid placement is endorsed anywhere in this book.