SOC Analyst
Monitor, investigate, and respond to security alerts as the first line of defense on a security operations team.
What They Do
A SOC (Security Operations Center) Analyst watches over an organization's systems and networks, looking for signs of trouble. When an alert fires — an unusual login, a suspicious file, a spike in outbound traffic — the analyst is the one who checks whether it's a false alarm or the start of an incident.
It is one of the most common entry points into cybersecurity because it rewards curiosity and pattern-recognition more than years of experience, and it exposes you to nearly every other specialty — detection engineering, incident response, threat hunting, and forensics all grow out of SOC work.
Core Skills
Your Roadmap
The stages of this career path, in order.
- Completed IT Fundamentals
- Completed Networking
- Completed Linux
- Completed Security Fundamentals
-
You are here
SOC Analyst
- Upcoming Detection Engineering
Start here
Resources chosen for this career path, roughly in the order they help most.
Prove it with a project
Hands-on work for this career path -- something to show, not just something to read.
Build a Mini SOC
Set up a small lab, collect logs, and monitor activity.
Conduct a Web Application Security Assessment
Simulate adversary behavior safely and evaluate detection.
Investigate a Phishing Attack
Analyze a scenario and document findings professionally.
Complete a Risk Assessment
Write detection rules and test them against log data.
Certifications worth considering
Certifications can support your career journey, but they are not a substitute for practical skills or experience.
Find your community
People learning and working in this space in Vietnam.
Where this leads
- Typical entry roles: SOC Analyst (Tier 1), Security Monitoring Analyst
- Adjacent positions: Incident Responder, Threat Hunter, Detection Engineer
- Common progression: Tier 1 -> Tier 2/3 Analyst -> Detection Engineering or Incident Response -> Security Engineering





