Updated by
Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

A SOC analyst investigates security alerts, works out what the evidence shows and helps a team respond. Your career can grow toward deeper investigations, detection engineering or leadership. The route depends on the work you take on and the organisation you join.
Start by comparing the responsibilities in current SOC analyst jobs. A junior title, a senior title and a tier number can mean different things across employers. The useful question is what you'd be expected to handle independently and where you'd have support.
What does a SOC analyst do?
A security operations centre brings together people, processes and tools to identify and respond to suspicious activity. An analyst might review an endpoint alert, investigate a reported email, examine identity logs or explain an unresolved case to the next shift.
Microsoft's security operations analyst role description includes triage, incident response, threat hunting and detection engineering. A particular job may cover only part of that work. Read the responsibilities before assuming you'll spend the day on any one activity.
Consider this fictional example. An alert reports an unusual sign-in to a finance employee's account. You check whether authentication succeeded, identify the device and source, and examine activity around the session. You compare that with the employee's expected access and the organisation's known remote-access arrangements.
If the evidence suggests unauthorised access, you escalate or carry out response actions permitted by the team's procedures. If it supports an ordinary explanation, you record why. When evidence is missing, your notes should make that uncertainty visible. The output is a reasoned assessment that another person can check and continue.
How SOC analyst tiers work
Tier labels describe a team's division of work. They aren't a universal qualification system or a promise that you'll be promoted after a set number of years. SANS describes a tiered model involving initial triage, deeper investigation and advanced analysis; responsibilities can overlap.
For a detailed comparison, our guide to L1, L2 and L3 SOC analyst responsibilities follows a fictional investigation across the team and includes a copyable escalation note.
Tier 1: Triage and escalation
Initial triage involves reviewing the alert, gathering relevant context, assessing urgency and deciding whether you can resolve the case within your authority. Useful habits include checking timestamps, identifying the affected account or device and documenting what you examined. Ask who reviews your early investigations and how you reach an experienced colleague during a difficult shift.
Tier 2: Deeper investigation
Escalated work can involve correlating evidence across systems, establishing the scope of an incident and coordinating response. The step up is broader ownership of an investigation. Writing a useful script can help, but so can finding a missing data source or communicating a containment decision clearly.
Tier 3: Advanced analysis and improvement
Senior analysts may tackle complex investigations, develop detections, conduct hunts and mentor colleagues. SANS's SOC role guidance also notes that a third tier may not exist in every team. Some employers place these responsibilities in separate specialist roles.
Ask what distinguishes the advertised levels in that organisation. A list of years beside a title tells you less than examples of the decisions, incidents and improvement work the role owns.
Skills to build and demonstrate
Build enough networking and operating-system knowledge to understand the evidence you're reading. Practise explaining a DNS lookup, an authentication attempt and a process starting on a device. When you examine a record, identify its source, timestamp, fields and collection limits.
Learn a query language in the environment you can access. For a Microsoft-focused role, the SC-200 credential page identifies Microsoft Sentinel, Defender tooling and Kusto Query Language among the relevant knowledge areas. Other employers use different systems. Choose a learning environment you can investigate in, then learn how the same questions translate to another platform.
For guided practice, inspect the syllabus before choosing a course. Hack The Box's SOC analyst path covers monitoring, traffic analysis, incident handling and reporting. Check its prerequisite knowledge and current access terms rather than assuming every module is suitable for your starting point.
Communication deserves deliberate practice. Write a short case note containing the question, evidence, assessment, actions and next owner. Then ask someone to explain what happened using only your note. If they can't tell which findings are confirmed, revise it.
For automation, begin with a bounded task such as parsing a lab log or formatting a report. Test missing fields, unexpected inputs and failures. Keep credentials and confidential employer data out of public repositories. A small, explainable tool is a better portfolio item than a large script you can't safely operate.
How to get your first SOC analyst job
Choose roles you could take
Make a shortlist using location, work rights, working hours and required experience. Read the distinction between required and preferred qualifications. An entry-level tag helps you find candidates for review; it doesn't establish that the employer accepts applicants with no experience.
You can browse roles tagged entry-level, then check each original description. Include internships, graduate programmes or internal transfers when they fit your circumstances. For a wider starting plan, read our guide to getting into cybersecurity.
Map requirements to evidence
For each important requirement, record something you can demonstrate, a gap to address or a question to clarify. If the employer asks for investigation experience, a relevant lab report can show your approach, but label it as a lab. It doesn't become production experience because it used realistic logs.
Previous work can supply useful examples. IT support may give you experience with accounts, tickets and escalation. Networking or systems work may give you troubleshooting and infrastructure context. A different background can provide evidence of clear communication and careful decision-making, alongside the technical preparation you still need. None of these routes guarantees an offer or a fixed transition time.
Produce one clear investigation example
Use an authorised training environment or a supplied exercise. Keep the scope small enough to explain from beginning to end. Your write-up should let a reviewer see what you investigated and why your conclusion follows.
A practice report could use these prompts:
- What question did the exercise ask you to answer?
- Which records did you inspect, and what time window did they cover?
- What did you find, and which alternative explanation did you consider?
- What couldn't you establish from the available evidence?
- What would the next analyst need to check?
These are prompts for your own work, not a claim that you've handled a real incident. Include a small, readable extract or diagram when it helps, and remove confidential or personal information before sharing it.
Prepare to explain your decisions
Practise describing your project aloud without reading a tool list. Be ready to explain an incorrect assumption you corrected and how you handled missing information. Our SOC analyst interview questions and sample answers include a fictional log exercise and worked shift handoff for this practice.
Choosing certifications for a SOC career
A certification has its own learning objectives and eligibility rules. A job has the employer's requirements. Compare them separately before committing time or money.
ISC2 Certified in Cybersecurity has no work-experience requirement and is aimed at foundational knowledge. That makes it an option to investigate when you're starting out; it doesn't remove an employer's experience requirement.
Microsoft Security Operations Analyst Associate is an intermediate, Microsoft-focused credential associated with SC-200. Consider it when the target work uses that environment and you can practise the relevant tasks. A vendor credential isn't a substitute for explaining an investigation.
For Security+, CySA+ or a practical blue-team qualification, compare the current official outline with the jobs on your shortlist. Note whether a credential is required, preferred or absent from each description. Include exam attempts, training, renewal and access costs in your decision. An advertised exam price alone doesn't tell you the full commitment.
CISSP has a different experience requirement. ISC2's current rules specify five years of qualifying experience across at least two domains, with a possible one-year waiver for an eligible degree or credential. Passing the exam without the required experience can lead to Associate of ISC2 status; it does not make you a CISSP. Check the full rules against your own experience before planning around it.
If you're already employed, ask which learning would support the work your team needs and whether there's a training budget. Choose the next credential around a concrete gap, rather than collecting a prescribed stack before applying anywhere.
How to assess SOC analyst pay
Compare advertised compensation for roles you could accept in the same market. Keep the currency, pay period, location, seniority and employment type visible. Separate base salary from bonus, equity, overtime and shift allowances. A contractor's hourly rate isn't directly comparable with an employee's annual base salary.
For an advertised range, ask what determines placement within it and whether it covers multiple locations or levels. Check the expected hours, overnight coverage and on-call arrangements alongside the money. Two offers with the same base salary can involve quite different commitments.
Our SOC job listings provide individual descriptions to inspect. Check the original employer posting and pay details where supplied. A range in one listing doesn't establish a market average, and an absent salary isn't zero pay.
Treat a clearance or specific tool requirement as part of that role's eligibility and responsibilities. Don't add a fixed premium to an assumed salary. Compare suitable roles and ask the employer about the actual package.
Choosing a team and assessing shift work
Ask how the SOC covers nights, weekends and leave. Establish whether the job uses fixed shifts, rotating shifts, on-call work or some combination. Get the expected location and working hours clear before accepting an offer; remote work can still involve country restrictions and overnight coverage.
An internal SOC supports its organisation, while a managed service may involve work across customer environments. OffSec's role overview describes the collaboration and documentation involved in SOC work. The employer category alone won't tell you how well a particular team is staffed or supported.
Useful questions include:
- Who is available when an analyst needs help during an overnight shift?
- How are unresolved cases handed over, and who owns the next action?
- What training and supervised work would I receive when joining?
- How does the team review noisy detections and gaps in visibility?
- How much time is available for learning and improvement work?
- What changes when someone moves to the next level?
Ask for examples of how the team handles these situations. A promise of progression is more useful when the manager can explain the responsibilities, assessment and available opportunities.
Moving beyond your current level
Agree with your manager what the next role requires, then keep evidence of relevant work you are authorised to discuss. That could include an investigation you carried further, a detection you improved or a handoff process you helped make clearer. Explain your contribution and its limits.
For a detection improvement, record the problem, the change and how the team checked it against both relevant malicious behaviour and legitimate activity. Fewer alerts alone don't show better detection. For an investigation, explain how your evidence changed the assessment or next action.
Progress also depends on the organisation's needs and available roles. Becoming a stronger analyst doesn't create a vacancy or guarantee an immediate pay increase. Use the agreed criteria to decide whether the current team offers the work and support you're seeking.
Where SOC experience can lead
Detection engineering focuses on building and maintaining detections. Incident response and digital forensics involve deeper investigation and evidence work. Threat hunting starts with a question about activity that may not have generated an alert. Leadership adds responsibility for people, priorities and communication. These are possible directions, with different preparation needs.
Security engineering, cloud security and other adjacent roles can draw on SOC experience, but require their own technical depth. Read the target role's duties and identify what you haven't yet done. NIST's NICE Framework components describe cybersecurity work through roles, tasks, knowledge and skills, which can help you make that comparison.
To compare the day-to-day work and preparation, read our SOC analyst vs security engineer guide, including a practical exercise for both roles.
You can also continue developing as an analyst. Advancement doesn't require choosing management, and you don't need to wait for a particular tier number to explore a specialism.
Working with automation and AI
Treat generated summaries, queries and suggested detections as outputs to verify. Check them against source records, test queries on known examples and follow your employer's rules for confidential information. Actions that could interrupt an account or device need the appropriate response authority.
When evaluating a job, ask which automation the team uses, what analysts check and how failures are handled. That gives you something concrete to prepare for. A forecast about AI replacing a whole tier doesn't tell you the responsibilities of the role you're considering.
Your next step
Open a few current SOC analyst roles and choose ones compatible with your circumstances. Compare their responsibilities with evidence you can already show. Pick one useful gap to work on, then produce an example you can explain and improve.
If you have an interview approaching, use the SOC interview practice guide. Keep your preparation tied to the work the employer needs and your own truthful experience.


