IT Operations & Security

Security Operations Center Analyst

SOC 15-1212.00 · ESCO 2519 · OSCA 271131

REA INV ART SOC ENT CON This role See your match →

Role snapshot

Overview

Monitors security alerts around the clock, investigating suspicious activity and escalating confirmed threats to protect an organisation's systems. Works in shifts, triaging hundreds of alerts daily and following incident response procedures when breaches are detected. This role is critical for maintaining an organization's security posture and quickly responding to potential cyber threats.

Protects an organization's digital assets and data from cyberattacks, minimizing financial losses, reputational damage, and operational disruption by proactively detecting and responding to threats.

On the job

  • Monitor Security Information and Event Management (SIEM) systems for security alerts and suspicious activity
  • Perform initial triage, investigation, and analysis of security incidents to determine their scope and severity
  • Execute established incident response procedures, including containment, eradication, and recovery steps
  • Document all incident details, analysis findings, and remediation actions for reporting and post-incident review
  • Collaborate with other security teams and IT departments to address and resolve security issues
Security Operations Center Analyst at work

Tools & technology

SplunkIBM QRadarMicrosoft SentinelElastic Stack (ELK)Endpoint Detection and Response (EDR) platformsNetwork Intrusion Detection Systems (NIDS)Ticketing systems (e.g., Jira, ServiceNow)

Average salary

$95K
MEDIAN SALARY Annual · USD
$70K Bottom 10%
$130K Top 10%

Job outlook

Growing

Job growth is expected to be above average over the next five years.

Education & training

Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field; relevant industry certifications are highly valued.

Career pathways

WHERE YOU COULD GO

Senior Security Operations Center Analyst
Incident Response Specialist
Threat Hunter

CURRENT ROLE

Security Operations Center Analyst

IT Operations & Security

ADJACENT MOVES

Security Engineer
Junior Security Analyst
Network Administrator
Systems Administrator
It Support Specialist

STARTING POINTS

Who thrives here

Interest profile

I

investigative · ICR

People who enjoy detailed investigation, systematic problem-solving, and working with complex technical systems to protect digital assets tend to thrive in this role.

Personality characteristics

Detail-oriented

Meticulously reviews logs and alerts to spot subtle anomalies and follow procedures accurately.

Calm under pressure

Maintains composure and follows established protocols during high-stress security incidents.

Analytical thinker

Enjoys dissecting complex technical problems and identifying root causes of security events.

Methodical

Systematically follows incident response playbooks and documentation standards to ensure consistency.

Team collaborator

Works effectively with colleagues during incident investigations and seamless shift handovers.

Best for

  • Individuals who thrive on protecting digital environments and solving complex technical challenges
  • Those who prefer structured work environments with clear protocols and continuous learning requirements
  • Professionals who can maintain vigilance and composure in a fast-paced, high-stakes operational setting

Watch out for

  • Regular shift work, including nights and weekends, may impact work-life balance for some individuals
  • High-pressure situations during active security incidents demand a calm and resilient approach
  • Tasks can sometimes be repetitive, requiring sustained focus on alert triage and log review

A week in the life

A representative working week for a Security Operations Center Analyst — where the deep work, meetings, and admin actually land.

8am9am10am11am12pm1pm2pm3pm4pm5pm6pm
Mon
Shift handover and daily briefing
Monitor SIEM for security alerts and events
Investigate suspicious activity and potential incidents
Document incident findings and update tickets
Tue
Team stand-up and threat intelligence review
Triage and analyze incoming security alerts
Incident response: containment and initial remediation
Wed
Perform vulnerability scan review and reporting
Security tool maintenance and tuning
Collaborate with IT for security control implementation
Thu
Incident review meeting with senior analysts
Threat hunting and proactive security analysis
Security awareness training module development
Fri
Generate daily and weekly security reports
Knowledge sharing and personal development
End-of-shift handover
Deep work Meeting External Social Admin

FREE ASSESSMENT

Does Security Operations Center Analyst fit you?

Measure your personality and interests, then see how this career ranks against 1,300+ others — for you personally.

Take the free assessment →