A SOC Analyst monitors security telemetry, triages alerts, and investigates potential incidents inside a Security Operations Center. The role sits within the detect-investigate-respond chain that defines SecOps, typically reporting to a SOC manager or shift lead. SOC Analysts execute the day-to-day monitoring and investigation work that keeps security operations running — they are primarily an execution role, not a design or strategy role.
• SIEM query writing in platforms' native query languages (KQL, SPL, or equivalent)
• MITRE ATT&CK framework knowledge for threat categorization and investigation paths
• Basic network and endpoint forensics to trace attacker actions
• Malware indicator analysis and threat intelligence correlation
• Security playbook execution and standard operating procedure adherence
• Evidence preservation techniques during active investigations
• Case prioritization based on organizational risk frameworks
• Effective shift handoff communication to maintain investigation continuity
• Escalation framing that gives incident responders the context they need
• Consulting with senior SOC analysts or the shift lead for confirmation and validation is an expected part of the role — analysts should not hesitate to loop in more experienced teammates when findings are ambiguous or when an investigation approaches the boundaries of their scope
What does a SOC Analyst do?
• Triage security alerts from SIEM, EDR, NDR, and other security tools to determine which require investigation• Investigate confirmed security incidents by analyzing logs, correlating events, and gathering evidence to understand scope and impact• Document findings in case management systems with clear timelines, evidence, and recommended actions• Escalate validated incidents to incident response teams or senior analysts when incidents exceed their scope or severity thresholds• Execute security playbooks and standard operating procedures for common incident types and investigation workflows• Participate in shift handoffs to maintain 24/7 coverage and ensure incident continuity across SOC shiftsCore skills for a SOC Analyst
Technical Skills
• Log analysis across multiple data sources (Windows event logs, syslog, application logs, network flows)• SIEM query writing in platforms' native query languages (KQL, SPL, or equivalent)
• MITRE ATT&CK framework knowledge for threat categorization and investigation paths
• Basic network and endpoint forensics to trace attacker actions
• Malware indicator analysis and threat intelligence correlation
Process and Investigation Skills
• Incident documentation discipline with chain of custody awareness• Security playbook execution and standard operating procedure adherence
• Evidence preservation techniques during active investigations
• Case prioritization based on organizational risk frameworks
Communication Skills
• Clear incident write-ups that technical and non-technical stakeholders can act on• Effective shift handoff communication to maintain investigation continuity
• Escalation framing that gives incident responders the context they need
• Consulting with senior SOC analysts or the shift lead for confirmation and validation is an expected part of the role — analysts should not hesitate to loop in more experienced teammates when findings are ambiguous or when an investigation approaches the boundaries of their scope
