SOC Analyst — Tier 1
Entry level · 0–2 years
The front line of security operations. You work the alert queue, decide what is real, and escalate what you cannot close.
Core skills
- Alert triage and prioritisation
- Log analysis across endpoint, network and identity
- Phishing investigation
- Incident documentation
- MITRE ATT&CK fluency
A typical day
- Working a shift queue and hitting response-time targets
- Investigating alerts and recording the reasoning
- Escalating with enough context that Tier 2 does not restart the work
- Shift handovers and daily briefings
Next step: SOC Analyst Tier 2 or Detection Engineer
SOC Analyst Path