Security Operations

SOC Analyst Career Roadmap

Investigate security alerts using SIEM, EDR, identity, cloud, network, and endpoint evidence, then improve detections and response.

Beginner to IntermediateFlexible roadmap5 target roles
CAREER ROADMAP VIDEOHow to Become a SOC Analyst: Skills, Tools, AI & 12-Week Roadmap
Open on YouTube ↗
ROLE EXPECTATIONS

What this career actually involves

SOC Analysts turn alerts into investigations by gathering evidence, building timelines, determining scope, escalating incidents, improving detections, and using automation or AI only with human validation.

Who this path is for

  • Beginners building a practical security-operations pathway.
  • IT support or network professionals moving into cybersecurity.
  • Security learners building SIEM, EDR, investigation, and detection skills.
SOC AnalystEntry to Mid-LevelSecurity Operations AnalystEntry to Mid-LevelSIEM AnalystEntry to Mid-LevelMDR AnalystEntry to Mid-LevelCyber Defense AnalystEntry to Mid-Level
SKILLS EMPLOYERS ARE ASKING FOR

Skill demand for this career

Percentages show how often each skill appears across relevant current opportunities for this career.

Loading current skill demand…
CANONICAL CAREER SKILLS

Core capabilities

📡

Network & Log Analysis

Understand traffic, logs, and common telemetry sources.

🔎

SIEM Investigation

Query and correlate security events.

🖥️

Endpoint Investigation

Use EDR/XDR evidence to understand process and device activity.

👤

Identity Investigation

Analyze sign-ins, MFA, privilege, and account changes.

🎯

Detection Engineering

Map threats and improve detection logic.

🚨

Incident Response

Scope, contain, escalate, document, and learn.

🤖

Responsible AI Assistance

Use AI for enrichment or summarization while validating evidence.

TEST YOUR SKILLS

Relevant knowledge checks

Finding quizzes that match this career path...

TOOLS & PLATFORMS

Tools that support the work

Microsoft Sentinel / KQL

SIEM querying and investigation.

Splunk / Elastic / Wazuh

Alternative SIEM/search platforms for lab practice.

EDR / XDR

Endpoint and identity investigation.

Wireshark

Packet-level network evidence.

MITRE ATT&CK

Threat behavior mapping and detection context.

SOAR / Scripting

Automation for repeatable enrichment and response steps.

REAL WORKFLOW

How the work typically flows

01

Triage the Alert

Understand source, severity, entities, context, and expected behavior.

02

Collect Evidence

Query SIEM, endpoint, identity, cloud, network, and email telemetry.

03

Build a Timeline and Scope

Determine what happened, when, who/what was affected, and confidence.

04

Respond and Escalate

Contain or escalate based on procedure and business impact.

05

Improve Detection

Document lessons, tune rules, create hunts, and improve playbooks.

DEVELOPMENT ROADMAP

Build capability in stages

Stage 1

Networking, OS, and Logs

Build foundations in network traffic, Windows/Linux, identity, and telemetry.

OutcomeUnderstand where investigation evidence comes from.
Stage 2

SIEM and Alert Triage

Learn queries, correlation, alert context, and investigation notes.

OutcomeTurn alerts into evidence-based cases.
Stage 3

Endpoint, Identity, and Cloud Investigation

Use EDR/XDR and cloud/identity telemetry.

OutcomeInvestigate across modern enterprise systems.
Stage 4

Detection, Hunting, and Response

Map behaviors, write detections, hunt, and support incident response.

OutcomeMove beyond closing alerts.
Stage 5

Automation, AI, and Portfolio

Automate repeatable steps and document a complete incident case.

OutcomeShow responsible use of automation and AI.
WORKPLACE SCENARIO

SOC Investigation Lab

Fictional workplace scenario
Problem

A suspicious sign-in alert may represent normal travel, credential misuse, session theft, or a broader compromise.

Objective

Collect identity, endpoint, network, and cloud evidence before deciding and escalating.

PORTFOLIO PROJECT

Suspicious Sign-In Investigation

Investigate a simulated suspicious-login alert using identity, endpoint, network, and SIEM evidence, then document scope, response, and detection improvements.

SIEM Query Workbook

Queries used for identity, endpoint, network, and related-event investigation.

Incident Timeline

Chronological evidence with source and confidence.

Incident Report

Scope, impact, containment, recommendations, and unresolved questions.

Detection Rule

Rule logic mapped to observed behavior.

Threat Hunt

A hypothesis-driven search for related activity.

SOAR / AI Validation Note

What was automated or AI-assisted and how the result was verified.

PORTFOLIO EVIDENCE

What you should be able to show

SIEM Query Workbook

Shows investigative fluency.

Incident Report

Shows evidence-based reasoning.

Detection Rule

Shows defensive engineering.

Threat Hunt

Shows proactive analysis.

Automation / AI Validation Note

Shows controlled use of assistance.

INTERVIEW PREPARATION

Translate learning into an interview story

How do you investigate a suspicious login?

Check user, device, location, MFA, IP, privilege, recent activity, and correlated events.

What makes a good SIEM query during an incident?

Start from a question, identify entities/time range, normalize fields, pivot, and preserve evidence.

How do you use AI safely in a SOC?

Use it for assistance, preserve source evidence, validate conclusions, and keep human ownership.

RELATED CAREERS

Adjacent paths to compare