| Detail | For this role |
|---|---|
| Department | Information Technology |
| Level | Entry level |
| Reports to | SOC Lead |
| Direct reports | None |
| Experience | Fresher or up to 2 years in a security operations role |
SOC Analyst job description template
Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.
Job title: SOC Analyst
Department: Information Technology
Reports to: SOC Lead
Location: [City], [office, branch or site]
About the role
A SOC Analyst works in a security operations centre, watching for cyber threats around the clock and responding to alerts as the first line of defence. At the entry level they monitor the SIEM, triage alerts, escalate real incidents and follow response playbooks under senior guidance. A good SOC analyst separates real threats from noise, acts fast and documents every step. The role sits in the security operations team, usually on shifts, and reports to a SOC lead or security manager.
Key responsibilities
- Monitor the SIEM and security tools for alerts and suspicious activity across the estate.
- Triage alerts by real risk, filtering out false positives from genuine threats.
- Investigate suspected incidents using logs, endpoint and network data at first level.
- Follow response playbooks to contain and escalate incidents to higher tiers.
- Document each alert, investigation and action clearly for the case record.
- Watch threat intelligence feeds and apply relevant indicators to monitoring.
- Track open incidents through to closure and hand over cleanly between shifts.
- Tune noisy alert rules with senior guidance to reduce false positives.
- Support security awareness by flagging phishing and risky user behaviour.
- Learn attack techniques, tools and playbooks with support from senior analysts.
Requirements
- Graduate in computer science, IT or a related field
- Security certification such as CompTIA Security+ is an advantage
- Knowledge of networking and security fundamentals
- Fresher or up to 2 years in a security operations role
KRAs and KPIs for a SOC Analyst
Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.
| Key result area | How to measure it |
|---|---|
| Alert triage | Alerts triaged within the target time set for each severity |
| Escalation quality | Real incidents escalated correctly with no missed true positives |
| False positives | False positive rate reduced through tuning each quarter |
| Documentation | Every alert and action recorded completely in the case log |
| Shift handover | Open incidents handed over cleanly with no loss of context |
| Learning | New threat and tooling skills picked up each quarter |
Skills and tools
Tools used day to day: SIEM platform, EDR tools, Threat intel feeds, Ticketing system, Log analysis tools.
Reporting line and career path
Next roles: Senior SOC Analyst, Security Analyst, Incident Response Analyst
Interview questions for a SOC Analyst
- What do you do when the SIEM raises a suspicious login alert?
- How do you tell a false positive from a real threat?
- What is the difference between an event, an alert and an incident?
- How do you hand over an open incident at the end of your shift?
- What are common signs of a phishing attack?
- Why is documenting every step important in a SOC?
Managing a SOC Analyst in ZeniaHR
Hire and manage your information technology team in one place
Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What does a SOC analyst do?
A SOC analyst works in a security operations centre, watching for cyber threats around the clock. They monitor the SIEM, triage alerts, investigate suspected incidents at first level and escalate real ones using playbooks. They document every step and hand over cleanly between shifts, acting as the first line of defence against attacks.
What is the difference between a SOC analyst and a security analyst?
A SOC analyst focuses on monitoring and first level response, usually on shifts inside a security operations centre. A security analyst has a broader remit that can include vulnerability management, access reviews, awareness and audits. Many people start as a SOC analyst and grow into a wider security analyst or incident response role.
How do I start a career as a SOC analyst?
Build strong networking and security fundamentals, learn how a SIEM works and understand common attacks like phishing and malware. A certification such as CompTIA Security plus helps for entry roles. Many SOC analysts come from IT support or networking. Be ready for shift work, since a SOC runs day and night.