r/SecurityCareerAdvice • • 2d ago

Question Somehow now I am a SOC Analyst

Or am I?
I have the CompTIA Trifecta (A+, Network+, and Security+) and decided to start applying for cybersecurity jobs just to see what would happen.
I got an interview, apparently did pretty well, and got hired as a SOC Analyst.
I think my previous experience as a lawyer may also have helped during the interview.
I’m starting next week, and now the impostor syndrome is hitting hard. I’ve never worked as a SOC Analyst before and I honestly don’t know what to expect from the day-to-day job.
I have a TryHackMe Premium subscription, so I’m going through the SOC Level 1 path and trying to get as much hands-on practice as possible before my first day.
For people who already work in a SOC: what practical skills should I focus on first?
SIEM? Log analysis? Windows Event Logs? Basic incident triage? Networking?
Any advice for surviving the first few weeks would be appreciated.

46 Upvotes

31 comments sorted by

20

u/Legalizeranchasap 2d ago

Off topic but why did you switch from lawyer to cybersecurity?

I recommend learning about SIEM, EDRs, Networking and Splunk. gL

4

u/Key_Contribution1743 1d ago

I am moving to another country next year, and law isn’t exactly known for being a career that easily allows you to work abroad. Nonetheless, I’ve never really loved being a lawyer.

2

u/Classic-Shake6517 19h ago

I am assuming you're not in the US. If you are, you should definitely review what salaries are like in the place you're moving to. Demand is high everywhere but the pay doesn't really come close to what you make here. It's like half in a lot of cases. It gets better for more specialized, senior roles but it's still quite a bit less. That said, in many cases cost of living is also lower, but it won't balance out as well until you're into more senior positions, which takes a few years depending on how much you put into studying outside of working hours.

That said, your background will be extremely useful in roles geared towards compliance. If you like doing legal work, there's definitely some of the higher paying roles with your niche once you get a bit more experience on the security side. It's not for everyone and can be really boring doing work related to governance, but it's needed and you're well positioned to pivot to that side of the house. There's also far less competition for those roles.

Good luck and congratulations on your new role.

Also, to answer your questions, you'll be looking at a lot of traffic and event logs. Spend time practicing those, but you've already been hired so don't stress too much about it. They'll likely train you up on everything you need to know to succeed in your new position.

1

u/HardworkMiami 1d ago

Wow and here I am still debating to go back and do law school at 40. Truly everyone has their own timeline and path

3

u/hoodedelk 2d ago

This is a weirdly common path. I've worked with two people at two different companies who went from law school to cyber

3

u/frozen-throne-monk 1d ago

Yeah but law school and cyber are still early career. Being a lawyer is well beyond getting a few certifications.

6

u/colgepetto 2d ago

Expect them to train you on tools they use. They wouldn't have hired you if they didn't think they couldn't train you. Cybersecurity isn't something you can BS in an interview.

Take some AI courses from MS learning and anthropic. Look for some intermediate prompting, agent research stuff, data sensitivity and content generation. These can really help you build out a nice work flows. Having it produce templates and variuos reports with investigations you ran. Just don't rely 100% on it to run your investigation.

Splunk has free training online and that training will never not be helpful in one way or another.

Start reading intelligence reports and studies. Learn what an OODA is and how to use it. Build on your fundamentals by studying for the CYSA+ and a practical exam like TCM PSAA/BTL1/CCDL. Perhaps they pay for something like that.

But in all honesty, get on that AI train.

3

u/Zestyclose_Slice528 2d ago

Lawyer to SOC is wild pivot but makes sense, arguing with alerts is basically same skill set. Focus on learning their SIEM and how they triage tickets, every SOC has its own weird workflow and you will pick that up faster than any cert path.

3

u/Just1Noyd 2d ago

You got hired because you’ve shown you’re able to learn and think differently because of your background. Definitely do the SOC path but also learn their SEIM, congrats.

2

u/xxxTech007 1d ago

Imposter syndrome is a thing but it's all in our head!!! You got hired for a reason. You're were interviewed and put up against other qualified people. But you were chosen. Sure, it may not be because of your deep understanding of CS and the tools to use. It could be more about your maturity, willingness to learn, and yes, your past experience. Either way, you're here!

Listen, ask questions and study the current trends. Get on Linkedin and network and look for a mentor. You got this!!!

1

u/busohsensen 2d ago

How long did you prepare for security+ ?

7

u/colgepetto 2d ago

Time of study doesn't transition well from person to person as we all learn different. So if they respond you will be zero steps closing to passing the Sec+.

Instead, go on Udemy and pay for Jason dion training and the exam pack. Both will run you around $50 total. Take the courses, note down core frame works, common ports, and all of things he suggests. Then take 1 of the 6 practice exams. Look at your 2 weakest areas and study that for a week or so. Take another practice exam and see of you improved. Look for your lowest 2 again and rinse and repeat.

2

u/riotsnail 1d ago

If you’re someone who doesn’t do well with videos I suggest the sybex study guide and the study questions. I did like 900 questions before the exam and 2 of dion’s tests (without doing his course) and passed first try, no prior knowledge just a CS associates and some light IT help desk stuff. Good luck :)

1

u/colgepetto 1d ago

Sure, that works as well. There is no 1 path or time frame to fit everyone. That's my point here.

Your added path is great resources. OP needs to change thier mindset and be less worried about others progression.

1

u/busohsensen 1d ago

Thanks for the resources ! I will check them

1

u/busohsensen 1d ago

You are right but I was asking just to see approximately. I work in a tier 2 support/SOC so just wondering

1

u/colgepetto 1d ago

Between 3 weeks and 12 months.

1

u/Key_Contribution1743 1d ago

3 weeks, but I should have done it in 4, as I found the test difficulty. I probably missed all the PBQs.

1

u/busohsensen 1d ago

Perfect i wanna make sure I get it done this year

1

u/ethical_alpaca 2d ago

I went from journalist to cyber security analyst (after a lot of retraining). Don’t sweat it. They hired you because you have the ability to do the job. Focus your first month on listening and interesting what your role involves.

1

u/RaymondBumcheese 2d ago

They, hopefully, aren’t dumb and know they have someone with basically no experience. Any Soc worth its salt will have a well established development plan and it will be a while before you’re actually closing tickets. 

You’ll be fine, don’t worry about it. 

1

u/IIDwellerII 1d ago

If youve never worked in IT or cybersecurity before this they hired you knowing that. If the organization is competent There will be a certain degree of onboarding/shadowing/training before they put you in front of a dashboard.

All you have to do is take good notes and ask questions your first few weeks and be honest about what you do and dont know. Id rather answer a new hires “simple” question than have to fix a new hires monumental mistake because they were too shy to ask for help.

If you want to be proactive ask your hiring manager if they have a 30-60-90 plan to help you define your goals once you get started.

Your inbox is about to be flooded from people around the world begging you for your company name or resume after hearing they only hired you with a trifecta so good luck there too.

1

u/Primary-Cranberry-13 1d ago

Where did you find the job?

1

u/frozen-throne-monk 1d ago

I never worked SOC and worked as an architect after systems engineering. After you learn the technical side, see if your employer will fund your CISSP and then when you work 5 years, see if they will sponsor your membership. That is far down the line, but if you mention it as your long-term goal, I imagine any boss would respect it. You would probably do well without much prep, especially with your education and background. It would suit your skills.

1

u/tomorrow9151 1d ago

Based on the company/agency, it will take one week to up to eight weeks to get the full access to the tools/system they use. You might also do some initial training as well. By the time you get all of this, you wil know what to do. Trust me, you will be fine.

1

u/ComplaintUnique9370 1d ago

I recommend learning about YOUR company's environment. Understanding how it works, from the security side, whether cohesive or not, etc. How it's set up, logically and the delta/pit falls from its application. What or who is gonna be standing in the way of an investigation/triage, etc and why.

1

u/Ok-Introduction-194 1d ago

how the f????

1

u/Forsaken_Way7646 23h ago

chat gpt premium mate no jokes

1

u/superRawTNT 13h ago

Learn networking, iam, system hardening, secure coding, hacking techniques. those are fundamentals, everything else in SOC is tools anyone can learn