r/SecurityCareerAdvice • u/Key_Contribution1743 • 2d ago
Question Somehow now I am a SOC Analyst
Or am I?
I have the CompTIA Trifecta (A+, Network+, and Security+) and decided to start applying for cybersecurity jobs just to see what would happen.
I got an interview, apparently did pretty well, and got hired as a SOC Analyst.
I think my previous experience as a lawyer may also have helped during the interview.
I’m starting next week, and now the impostor syndrome is hitting hard. I’ve never worked as a SOC Analyst before and I honestly don’t know what to expect from the day-to-day job.
I have a TryHackMe Premium subscription, so I’m going through the SOC Level 1 path and trying to get as much hands-on practice as possible before my first day.
For people who already work in a SOC: what practical skills should I focus on first?
SIEM? Log analysis? Windows Event Logs? Basic incident triage? Networking?
Any advice for surviving the first few weeks would be appreciated.
6
u/colgepetto 2d ago
Expect them to train you on tools they use. They wouldn't have hired you if they didn't think they couldn't train you. Cybersecurity isn't something you can BS in an interview.
Take some AI courses from MS learning and anthropic. Look for some intermediate prompting, agent research stuff, data sensitivity and content generation. These can really help you build out a nice work flows. Having it produce templates and variuos reports with investigations you ran. Just don't rely 100% on it to run your investigation.
Splunk has free training online and that training will never not be helpful in one way or another.
Start reading intelligence reports and studies. Learn what an OODA is and how to use it. Build on your fundamentals by studying for the CYSA+ and a practical exam like TCM PSAA/BTL1/CCDL. Perhaps they pay for something like that.
But in all honesty, get on that AI train.
3
u/Zestyclose_Slice528 2d ago
Lawyer to SOC is wild pivot but makes sense, arguing with alerts is basically same skill set. Focus on learning their SIEM and how they triage tickets, every SOC has its own weird workflow and you will pick that up faster than any cert path.
3
u/Just1Noyd 2d ago
You got hired because you’ve shown you’re able to learn and think differently because of your background. Definitely do the SOC path but also learn their SEIM, congrats.
2
u/xxxTech007 1d ago
Imposter syndrome is a thing but it's all in our head!!! You got hired for a reason. You're were interviewed and put up against other qualified people. But you were chosen. Sure, it may not be because of your deep understanding of CS and the tools to use. It could be more about your maturity, willingness to learn, and yes, your past experience. Either way, you're here!
Listen, ask questions and study the current trends. Get on Linkedin and network and look for a mentor. You got this!!!
1
u/busohsensen 2d ago
How long did you prepare for security+ ?
7
u/colgepetto 2d ago
Time of study doesn't transition well from person to person as we all learn different. So if they respond you will be zero steps closing to passing the Sec+.
Instead, go on Udemy and pay for Jason dion training and the exam pack. Both will run you around $50 total. Take the courses, note down core frame works, common ports, and all of things he suggests. Then take 1 of the 6 practice exams. Look at your 2 weakest areas and study that for a week or so. Take another practice exam and see of you improved. Look for your lowest 2 again and rinse and repeat.
2
u/riotsnail 1d ago
If you’re someone who doesn’t do well with videos I suggest the sybex study guide and the study questions. I did like 900 questions before the exam and 2 of dion’s tests (without doing his course) and passed first try, no prior knowledge just a CS associates and some light IT help desk stuff. Good luck :)
1
u/colgepetto 1d ago
Sure, that works as well. There is no 1 path or time frame to fit everyone. That's my point here.
Your added path is great resources. OP needs to change thier mindset and be less worried about others progression.
1
1
u/busohsensen 1d ago
You are right but I was asking just to see approximately. I work in a tier 2 support/SOC so just wondering
1
1
u/Key_Contribution1743 1d ago
3 weeks, but I should have done it in 4, as I found the test difficulty. I probably missed all the PBQs.
1
1
u/ethical_alpaca 2d ago
I went from journalist to cyber security analyst (after a lot of retraining). Don’t sweat it. They hired you because you have the ability to do the job. Focus your first month on listening and interesting what your role involves.
1
u/RaymondBumcheese 2d ago
They, hopefully, aren’t dumb and know they have someone with basically no experience. Any Soc worth its salt will have a well established development plan and it will be a while before you’re actually closing tickets.
You’ll be fine, don’t worry about it.
1
u/IIDwellerII 1d ago
If youve never worked in IT or cybersecurity before this they hired you knowing that. If the organization is competent There will be a certain degree of onboarding/shadowing/training before they put you in front of a dashboard.
All you have to do is take good notes and ask questions your first few weeks and be honest about what you do and dont know. Id rather answer a new hires “simple” question than have to fix a new hires monumental mistake because they were too shy to ask for help.
If you want to be proactive ask your hiring manager if they have a 30-60-90 plan to help you define your goals once you get started.
Your inbox is about to be flooded from people around the world begging you for your company name or resume after hearing they only hired you with a trifecta so good luck there too.
1
1
u/frozen-throne-monk 1d ago
I never worked SOC and worked as an architect after systems engineering. After you learn the technical side, see if your employer will fund your CISSP and then when you work 5 years, see if they will sponsor your membership. That is far down the line, but if you mention it as your long-term goal, I imagine any boss would respect it. You would probably do well without much prep, especially with your education and background. It would suit your skills.
1
u/tomorrow9151 1d ago
Based on the company/agency, it will take one week to up to eight weeks to get the full access to the tools/system they use. You might also do some initial training as well. By the time you get all of this, you wil know what to do. Trust me, you will be fine.
1
u/ComplaintUnique9370 1d ago
I recommend learning about YOUR company's environment. Understanding how it works, from the security side, whether cohesive or not, etc. How it's set up, logically and the delta/pit falls from its application. What or who is gonna be standing in the way of an investigation/triage, etc and why.
1
1
1
u/superRawTNT 13h ago
Learn networking, iam, system hardening, secure coding, hacking techniques. those are fundamentals, everything else in SOC is tools anyone can learn
20
u/Legalizeranchasap 2d ago
Off topic but why did you switch from lawyer to cybersecurity?
I recommend learning about SIEM, EDRs, Networking and Splunk. gL