A SOC (Security Operations Centre) Analyst defends an organisation by monitoring, detecting and responding to security threats. It's one of the most popular entry points into cyber security.
Role overview
SOC Analysts watch security tooling (SIEM), triage alerts, investigate suspicious activity and kick off incident response. The role blends networking, security fundamentals and calm, methodical analysis.
A typical day
A SOC analyst's day is driven by the alert queue: triaging what the SIEM surfaces, separating false positives from genuine threats, and pulling on the threads that look suspicious. You correlate logs, check threat intelligence, document what you find, and hand off or escalate real incidents. Shift work and a curious, methodical mindset come with the territory.
Typical responsibilities
- Monitor SIEM dashboards and triage security alerts.
- Investigate suspicious activity and reduce false positives.
- Follow the incident response process and escalate real incidents.
- Document findings and support threat hunting.
Core skills required
- Security fundamentals (CIA, defence in depth)
- Networking & log analysis
- SIEM & detection
- Incident response
- Analytical thinking
What employers look for
Employers want analysts who understand security and networking fundamentals, can read and correlate logs, stay calm under pressure, and communicate findings clearly. Security+ is the baseline expectation, hands-on familiarity with a SIEM is a strong plus, and genuine curiosity about how attacks work sets candidates apart.
Recommended learning paths (vendor-neutral)
Recommended certifications
- CompTIA Security+
- CompTIA CySA+ — on the Academy roadmap
Practical labs
Guided hands-on labs for this role are on the Academy roadmap. In the meantime, build a home lab or use free tier cloud resources to practise the skills above.
Technical interview preparation
- What is the difference between a SIEM and a SOAR?
- Walk me through the incident response lifecycle.
- How would you investigate a suspicious login alert?
Behavioural interview preparation
- Tell me about a time you spotted something others missed.
- Describe staying calm and methodical during a high-pressure incident.
Career progression
SOC Analyst (Tier 1) → Tier 2/3 Analyst → Incident Responder / Threat Hunter / Security Engineer, with CySA+, and later penetration testing or GRC as specialisations.
Typical UK salary
Typically £25,000–£35,000 starting in the UK, rising to £40,000–£55,000+ for experienced analysts and senior SOC roles.
Explore other roles
This is one of the roles in the Career Roles hub. You might also look at Help Desk Engineer, Network Engineer.
Prepare with Missiora
- AI Interview™ — run a scored mock interview for this exact role.
- Career Coach™ — get a personalised path from where you are to this role.
- Career Passport™ — evidence your skills and progress to employers.
