SOC Fundamentals

Roles and Responsibilities of a SOC Analyst

Learning Outcome

4

Identify key technical and soft skills.

3

Differentiate between L1, L2, and L3 Analysts.

2

Describe daily SOC Analyst activities.

1

Explain SOC Analyst roles and responsibilities.

In a hospital emergency room, nurses continuously monitor patients and look for signs of trouble.

Patient monitoring = Security Monitoring

When a patient shows unusual symptoms, the nurse raises an alert and checks what may be wrong.

Unusual symptoms = Security Alert;

Checking the problem = Initial Investigation

The doctor examines the patient, reviews their condition, and determines how serious the problem is.

Doctor's examination = Alert Investigation and Threat Analysis

If the patient has a serious condition, the doctor involves a specialist for deeper treatment.

Specialist = Senior SOC Analyst / Tier 2 or Tier 3 Analyst;

Escalation = Incident Escalation

The hospital manager oversees the overall emergency operation and ensures everything runs smoothly.

Hospital manager = SOC Manager / Security Team Lead

Who is a SOC Analyst?

A SOC Analyst is a cybersecurity professional responsible for monitoring, detecting, investigating, and responding to security threats and incidents.

 

They act as a first line of defense by monitoring security systems and protecting networks, applications, systems, and data.

Importance of a SOC Analyst

Continuously monitor security events

 

 

Detect threats early

 

 

Respond quickly to incidents

Protect sensitive information

 

 

Support business continuity

 

 

Improve security posture

Purpose of a SOC Analyst

SOC Analysts help detect and respond to threats such as malware, phishing, ransomware, insider threats, and unauthorized access.

Monitor security events

 

Detect malicious activities

 

Investigate suspicious behavior

 

Reduce security risks

 

Support compliance requirements

Role in Protecting Digital Assets

SOC Analysts protect data, networks, applications, devices, and cloud resources by:

Preventing unauthorized access

Detecting malicious activities

Protecting confidential information

Supporting incident response

Core Roles of a SOC Analyst

Monitoring Security Events

Continuously monitor systems, networks, and security tools for unusual activities.

Failed login attempts

 

Unusual network traffic

 

Malware alerts

 

Unauthorized access

Detecting Threats

Analyze alerts and security events to identify threats such as:

Malware

 

Phishing

 

Brute-force attacks

 

Insider threats

Investigating Security Incidents

Analyze suspicious activities to determine the cause, scope, and impact.

Review logs

 

Examine alerts

 

Analyze network traffic

 

Collect evidence

Supporting Incident Response

Assist response teams in containing and mitigating incidents.

Identify affected systems

 

Gather incident information

 

Coordinate with response teams

 

Monitor recovery

Key Responsibilities

Security Monitoring

Monitor systems and networks for suspicious activities.

1

Alert Analysis

Review alerts and identify genuine threats.

2

Log Analysis

Analyze server, firewall, application, and security logs.

3

Threat Detection

Identify IOCs and signs of malicious activity.

4

Incident Investigation

Determine the cause and impact of incidents.

5

Incident Escalation

Escalate complex incidents to senior teams.

6

Daily Activities

Review security dashboards

Monitor SIEM alerts

Analyze logs

Investigate suspicious activities

Communicate with security teams

Security Team Hierarchy

Executive Leadership

CEO: Leads overall business strategy.

 

CFO: Manages finances and security budgets.

 

Company Owner: Sets organizational objectives and supports security initiatives.

Security Leadership

CISO: Leads cybersecurity strategy, policies, and risk management.

 

CIO: Oversees IT operations and technology investments.

 

CTO: Leads technology innovation and infrastructure.

Security Management

SOC Manager:

Manages SOC analysts

Oversees incident response

Reports security metrics

Improves SOC operations

Security Team Lead:

Coordinates daily activities

Supports analysts during investigations

Security Operations Team

SOC Analyst: Monitors and investigates security events.

Security Engineer: Designs and maintains security solutions.

Incident Responder: Handles active incidents and recovery.

Threat Hunter: Searches for hidden threats.

Penetration Tester: Tests systems for security weaknesses.

GRC Specialist: Manages Governance, Risk, and Compliance.

SOC Analyst Tier Structure

Tier 1 (L1): First point of contact for security alerts.

Monitor alerts

Perform initial investigation

Create and document ticketsa

Tier 2 (L2): Handles more complex investigations.

Analyze incidents

Validate threats

Support containment and remediation

Tier 3 (L3): Senior analysts handling advanced threats.

Investigate sophisticated attacks

Perform malware analysis

Conduct threat hunting

Skills Required for a SOC Analyst

Technical Skills

Soft Skills

Networking: IP, DNS, HTTP, protocols, and network communication

Log Analysis: Identify suspicious activities in logs

Operating Systems: Windows, Linux, and servers

Analytical thinking

Attention to detail

Problem-solving

Communication

Tools Used by SOC Analysts

Splunk,

IBM QRadar, Microsoft Sentinel

CrowdStrike Falcon, Microsoft Defender for Endpoint

Snort, Suricata

Palo Alto Networks, Fortinet,

Cisco Firepower

ServiceNow, Jira

SIEM

EDR

IDS/IPS

Firewalls

Ticketing

Challenges Faced by SOC Analysts

Alert Fatigue: Large numbers of alerts make genuine threats harder to identify.

 

 

False Positives: Alerts may indicate suspicious activity without being actual incidents.

 

 

Large Data Volumes: Massive amounts of logs require continuous analysis.

 

 

Evolving Threats: New attack techniques require analysts to stay updated.

Career Path of a SOC Analyst

Summary

5

SOC Analysts support cybersecurity and business continuity.

4

Analysts are divided into L1, L2, and L3 based on expertise.

3

SOC teams have leadership, management, and operational levels.

2

They protect digital assets and reduce cybersecurity risks.

1

SOC Analysts monitor, detect, investigate, and respond to threats.

Quiz

Which SOC Analyst tier performs the initial investigation of alerts?

 

B. L2 Analyst

C. L1 Analyst

D. SOC Manager

A. L3 Analyst

Quiz-Answer

C. L1 Analyst

Which SOC Analyst tier performs the initial investigation of alerts?

 

A. L3 Analyst

B. L2 Analyst

D. SOC Manager

Roles and Responsibilities of a SOC Analyst

By Content ITV

Roles and Responsibilities of a SOC Analyst

  • 45