SOC Analyst (Cybersecurity)
Watch for attacks, investigate security alerts, and help stop incidents as part of a Security Operations Center team.
- Time needed
- 6 to 9 months at about 2 hours a day
- Who it's for
- People comfortable with computers who enjoy investigating. IT or networking experience helps.
- Steps
- 6
-
Step 1: Networking and Linux basics
5 to 6 weeks
Learn how networks work: IP addresses, ports, DNS, HTTP, and TCP. Get comfortable on the Linux command line, because most security tools and logs live there.
- Professor Messer Free Network+ video course.
- OverTheWire: Bandit Learn the Linux command line by solving levels.
-
Step 2: Security fundamentals
4 to 5 weeks
Learn the core ideas: confidentiality, integrity, availability, common attacks, malware types, authentication, and encryption basics.
- Professor Messer Free Security+ video course.
-
Step 3: How attackers operate
3 weeks
Study the tactics and techniques real attackers use, so you can recognise them in logs. MITRE ATT&CK is the common language security teams use.
- MITRE ATT&CK Start with the Enterprise matrix. Pick five techniques and learn how each looks in logs.
-
Step 4: Logs, SIEM, and alert investigation
6 to 8 weeks
Practise investigating alerts in realistic labs: read Windows and Linux logs, search in a SIEM, and decide whether an alert is a real attack. Write short reports for each investigation.
- TryHackMe The SOC Level 1 path is a strong structured option. Some rooms are free.
- LetsDefend Simulated SOC alerts to investigate. Has a free tier.
- Blue Team Labs Online Investigation challenges. Has free challenges.
-
Step 5: Detection rules
3 to 4 weeks
Learn to write rules that catch attacks automatically. Sigma is a shared rule format that converts to many SIEMs. Read existing rules, then write your own for techniques you studied in ATT&CK.
-
Step 6: Portfolio and job applications
2 to 3 weeks
Publish three or four investigation write-ups and a few detection rules on GitHub or a blog. Explain what you found, how, and what you'd recommend. This shows employers how you think.
Want a teacher, feedback, and a real project?
SecAITech Academy runs small, practical batches where you build real work, get your code reviewed, and finish with a verifiable certificate.