The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Associate SOC Analyst (L1)
1-2 yearsSkills to master
- Mastering Tier 1 alert triage, playbook adherence, basic SIEM navigation, and clear escalation procedures. It's about getting the fundamentals absolutely solid.
You're ready to move on when
- Consistently closing 40+ Tier 1 alerts per shift with high accuracy.
- Demonstrating a clear understanding of basic attack types (phishing, malware).
- Proactively asking questions and showing a keen interest in deeper investigations.
- Reliably following all documented procedures without constant supervision.
- 2
IT Helpdesk / Network Operations Centre (NOC) Analyst
2-3 yearsSkills to master
- Building a strong foundation in IT systems, networking, and troubleshooting. Understanding how infrastructure works is a huge advantage when you're investigating security incidents.
You're ready to move on when
- Solving complex network or system issues independently.
- Demonstrating a strong interest in security aspects of IT operations.
- Taking initiative to learn about security tools and concepts in your spare time.
- Successfully completing a CompTIA Security+ or similar foundational security certification.
- 3
Junior Penetration Tester / Security Consultant
1-2 yearsSkills to master
- Understanding the attacker's mindset, common vulnerabilities, and exploitation techniques. This perspective is invaluable for a defender.
You're ready to move on when
- Successfully identifying and exploiting vulnerabilities in test environments.
- A strong desire to switch to a defensive role and apply offensive knowledge to protect systems.
- Good understanding of incident response principles, even if from an offensive context.