The scoreboard, honestly: the hard targets, how often each one is actually looked at,
and the quiet human signals that never make it onto a dashboard.
MTTR (Mean Time to Respond) for Led Incidents
The average time it takes from detecting a significant incident you're leading to its full containment and eradication.
Target · Reduce by 10% quarter-over-quarter for incidents you leadIf the average MTTR for your incidents was 4 hours last quarter, we'd expect it to be around 3 hours 36 minutes this quarter. This shows you're getting faster and more efficient at shutting down threats.
New Detection Rules Authored & Deployed
The number of high-fidelity detection rules (e.g., SIEM correlation rules, EDR custom detections) you design, test, and get deployed into production based on threat intelligence or post-incident analysis.
Target · 2+ production-ready detection rules per monthAfter a phishing campaign, you might create a new rule that flags specific email header patterns or a unique PowerShell command used by the attackers, preventing similar attacks from succeeding next time.
False Positive Reduction Rate (for new rules)
The percentage reduction in false positives for the detection rules you've implemented or significantly tuned.
Target · Achieve >90% true positive rate for new high-severity rulesYou build a new rule for a specific type of lateral movement. Initially, it triggers 50 times a day, 45 of which are legitimate admin activity. You tune it, and now it only triggers 5 times, all of them actual threats. That's a huge win for team efficiency.
Mentee Progression & Certification
The measurable improvement and professional development of the junior analysts you're mentoring, often evidenced by new certifications or increased autonomy.
Target · At least one mentee achieves a new security certification (e.g., CompTIA CySA+, GIAC GCIH) within a year of your mentorshipYou've been working with a junior analyst for six months. They successfully pass their CySA+ exam, and you've seen them confidently lead a Tier 2 incident from start to finish without needing your direct intervention.
Incident Leadership & Communication
How effectively you lead technical incident response efforts, coordinate with other teams, and communicate complex technical details to both technical and non-technical stakeholders during a crisis.
- You're the first person the team looks to during a major incident. Stakeholders consistently praise your clear, calm updates in post-incident feedback. You can explain a complex attack chain to the Head of Legal without them glazing over. Your incident summaries are concise and actionable.
Threat Hunting Proactiveness
Your ability to move beyond reactive alerts and proactively hunt for threats that might be lurking undetected in our environment, using hypothesis-driven approaches.
- You regularly present new hunting hypotheses based on recent threat intelligence. You've uncovered previously unknown suspicious activity that wasn't caught by existing detections. Your hunting efforts lead to the creation of new, valuable detection rules. You're not just waiting for the phone to ring.
Process Improvement & Documentation
Your contribution to refining and improving our SOC's playbooks, runbooks, and standard operating procedures, making them clearer, more efficient, and more robust.
- You've updated several critical runbooks after incidents, adding steps that prevent future issues. Junior analysts consistently refer to your documentation for guidance. You proactively identify gaps in our processes and propose solutions, rather than waiting for them to break.
Team Knowledge Sharing & Mentorship Impact
The extent to which you share your expertise, uplift the skills of junior team members, and contribute to a collaborative learning environment within the SOC.
- Other analysts regularly come to you for technical advice. You lead internal training sessions or 'lunch and learns' on new attack techniques or tools. You provide constructive, detailed feedback during code reviews or incident debriefs, helping others improve. You're seen as a helpful expert, not just a senior.