Security Operations Center Analyst
SOC 15-1212.00 · ESCO 2519 · OSCA 271131
Role snapshot
Overview
Monitors security alerts around the clock, investigating suspicious activity and escalating confirmed threats to protect an organisation's systems. Works in shifts, triaging hundreds of alerts daily and following incident response procedures when breaches are detected. This role is critical for maintaining an organization's security posture and quickly responding to potential cyber threats.
Protects an organization's digital assets and data from cyberattacks, minimizing financial losses, reputational damage, and operational disruption by proactively detecting and responding to threats.
On the job
- Monitor Security Information and Event Management (SIEM) systems for security alerts and suspicious activity
- Perform initial triage, investigation, and analysis of security incidents to determine their scope and severity
- Execute established incident response procedures, including containment, eradication, and recovery steps
- Document all incident details, analysis findings, and remediation actions for reporting and post-incident review
- Collaborate with other security teams and IT departments to address and resolve security issues
Tools & technology
Average salary
Job outlook
GrowingJob growth is expected to be above average over the next five years.
Education & training
Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field; relevant industry certifications are highly valued.
Career pathways
WHERE YOU COULD GO
CURRENT ROLE
Security Operations Center Analyst
IT Operations & Security
ADJACENT MOVES
STARTING POINTS
Who thrives here
Interest profile
investigative · ICR
People who enjoy detailed investigation, systematic problem-solving, and working with complex technical systems to protect digital assets tend to thrive in this role.
Personality characteristics
Detail-oriented
Meticulously reviews logs and alerts to spot subtle anomalies and follow procedures accurately.
Calm under pressure
Maintains composure and follows established protocols during high-stress security incidents.
Analytical thinker
Enjoys dissecting complex technical problems and identifying root causes of security events.
Methodical
Systematically follows incident response playbooks and documentation standards to ensure consistency.
Team collaborator
Works effectively with colleagues during incident investigations and seamless shift handovers.
Best for
- Individuals who thrive on protecting digital environments and solving complex technical challenges
- Those who prefer structured work environments with clear protocols and continuous learning requirements
- Professionals who can maintain vigilance and composure in a fast-paced, high-stakes operational setting
Watch out for
- Regular shift work, including nights and weekends, may impact work-life balance for some individuals
- High-pressure situations during active security incidents demand a calm and resilient approach
- Tasks can sometimes be repetitive, requiring sustained focus on alert triage and log review
A week in the life
A representative working week for a Security Operations Center Analyst — where the deep work, meetings, and admin actually land.
Similar roles
FREE ASSESSMENT
Does Security Operations Center Analyst fit you?
Measure your personality and interests, then see how this career ranks against 1,300+ others — for you personally.
Take the free assessment →