What does a SOC analyst actually do?

Careers

When people imagine a cybersecurity job, they picture someone in a hoodie typing very fast. The reality for most defenders is different, and honestly more interesting. Meet the SOC analyst.

SOC stands for security operations centre. It is the team that watches an organisation's systems day and night, spots attacks, and responds before they become disasters. If a company were a building, the SOC would be the people watching the cameras and the alarms.

A day in the life

Most of the day revolves around alerts. Security tools fire them when something looks suspicious: a login from an unusual country, a program behaving oddly, a spike of failed passwords. The analyst's job is to decide, quickly and calmly:

  • Is this real, or a false alarm?
  • If it is real, how bad is it, and what else is affected?
  • What should happen next: close it, dig deeper, or wake someone up?

Most alerts turn out to be harmless. A manager on holiday logging in from Lisbon. An IT admin running a legitimate script. The skill is spotting the one alert that is not.

The tools

  • SIEM. A system that collects logs from everywhere into one place, so you can search and correlate them.
  • EDR. Software on laptops and servers that records what programs do, and can isolate a machine with one click.
  • Ticketing and case notes. Every investigation is written down. If it isn't written, it didn't happen.
  • Threat intelligence. Information about known attackers, their tools and their habits.

The levels

Many SOCs use tiers. Level 1 analysts triage alerts. Level 2 investigate the serious ones in depth. Level 3 hunt for threats nobody has spotted yet and improve the detections. Many people start at Level 1 and move up quickly once they show good judgement.

Skills that actually matter

  • Curiosity. "Why did that happen?" is the most useful question in the job.
  • Knowing what normal looks like. You cannot spot strange without it.
  • Writing clearly. Your notes are read by managers, lawyers and sometimes regulators.
  • Staying calm. Panic makes people delete evidence or switch off the wrong server.
  • Basics. Networking, Windows and Linux, how logins and permissions work.

Practise it before you apply

The hardest part of getting a first SOC job is experience. So get some, for free.

  • GL-04: Market Blackout. You are the on-call analyst at a stock exchange when rogue AI agents start placing fake orders. Hunt through EDR logs, preserve evidence, and contain it without crashing the market.
  • DF-01: WAFShield. Defend a web app with your own firewall rules while real attack tools hit it, without blocking real users.
  • The forensics intro series. Packet captures, logs, disk images and memory. The bread and butter of investigations.
Your first night shift. Pre-market opens at 03:00. Open Market Blackout →

Put what you learn in a short write-up and link it in your CV. Hiring managers love candidates who can show how they think.

CyberLearner.org is a free cybersecurity training platform, built on the curriculum of the International Cybersecurity Olympiad (ICO). Every lab is hands-on and runs in your browser. It is open to everyone, regardless of skill level.


TopicsSOC analystSecurity operations centreBlue teamCybersecurity careersSIEMEDRThreat huntingAlert triageIncident responseEntry-level cybersecurity jobs
Share this article LinkedIn X Facebook Email
← Back to all posts