Home › HRMS › Job roles › Information Technology › SOC Analyst
Information Technology · Entry level

SOC Analyst job description

A SOC Analyst works in a security operations centre, watching for cyber threats around the clock and responding to alerts as the first line of defence. At the entry level they monitor the SIEM, triage alerts, escalate real incidents and follow response playbooks under senior guidance. A good SOC analyst separates real threats from noise, acts fast and documents every step. The role sits in the security operations team, usually on shifts, and reports to a SOC lead or security manager.

DetailFor this role
DepartmentInformation Technology
LevelEntry level
Reports toSOC Lead
Direct reportsNone
ExperienceFresher or up to 2 years in a security operations role

SOC Analyst job description template

Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.

Job title: SOC Analyst

Department: Information Technology

Reports to: SOC Lead

Location: [City], [office, branch or site]

About the role

A SOC Analyst works in a security operations centre, watching for cyber threats around the clock and responding to alerts as the first line of defence. At the entry level they monitor the SIEM, triage alerts, escalate real incidents and follow response playbooks under senior guidance. A good SOC analyst separates real threats from noise, acts fast and documents every step. The role sits in the security operations team, usually on shifts, and reports to a SOC lead or security manager.

Key responsibilities

  • Monitor the SIEM and security tools for alerts and suspicious activity across the estate.
  • Triage alerts by real risk, filtering out false positives from genuine threats.
  • Investigate suspected incidents using logs, endpoint and network data at first level.
  • Follow response playbooks to contain and escalate incidents to higher tiers.
  • Document each alert, investigation and action clearly for the case record.
  • Watch threat intelligence feeds and apply relevant indicators to monitoring.
  • Track open incidents through to closure and hand over cleanly between shifts.
  • Tune noisy alert rules with senior guidance to reduce false positives.
  • Support security awareness by flagging phishing and risky user behaviour.
  • Learn attack techniques, tools and playbooks with support from senior analysts.

Requirements

  • Graduate in computer science, IT or a related field
  • Security certification such as CompTIA Security+ is an advantage
  • Knowledge of networking and security fundamentals
  • Fresher or up to 2 years in a security operations role

KRAs and KPIs for a SOC Analyst

Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.

Key result areaHow to measure it
Alert triageAlerts triaged within the target time set for each severity
Escalation qualityReal incidents escalated correctly with no missed true positives
False positivesFalse positive rate reduced through tuning each quarter
DocumentationEvery alert and action recorded completely in the case log
Shift handoverOpen incidents handed over cleanly with no loss of context
LearningNew threat and tooling skills picked up each quarter

Skills and tools

SIEM monitoringAlert triageLog analysisIncident playbooksEndpoint and network basicsThreat intelligence basicsClear documentationAlertnessDiscipline

Tools used day to day: SIEM platform, EDR tools, Threat intel feeds, Ticketing system, Log analysis tools.

Reporting line and career path

SOC LeadSOC Analyst
Moves up from: IT Support Engineer, Network Administrator, Fresher
Next roles: Senior SOC Analyst, Security Analyst, Incident Response Analyst

Interview questions for a SOC Analyst

  1. What do you do when the SIEM raises a suspicious login alert?
  2. How do you tell a false positive from a real threat?
  3. What is the difference between an event, an alert and an incident?
  4. How do you hand over an open incident at the end of your shift?
  5. What are common signs of a phishing attack?
  6. Why is documenting every step important in a SOC?

Managing a SOC Analyst in ZeniaHR

Hire and manage your information technology team in one place

Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What does a SOC analyst do?

A SOC analyst works in a security operations centre, watching for cyber threats around the clock. They monitor the SIEM, triage alerts, investigate suspected incidents at first level and escalate real ones using playbooks. They document every step and hand over cleanly between shifts, acting as the first line of defence against attacks.

What is the difference between a SOC analyst and a security analyst?

A SOC analyst focuses on monitoring and first level response, usually on shifts inside a security operations centre. A security analyst has a broader remit that can include vulnerability management, access reviews, awareness and audits. Many people start as a SOC analyst and grow into a wider security analyst or incident response role.

How do I start a career as a SOC analyst?

Build strong networking and security fundamentals, learn how a SIEM works and understand common attacks like phishing and malware. A certification such as CompTIA Security plus helps for entry roles. Many SOC analysts come from IT support or networking. Be ready for shift work, since a SOC runs day and night.