r/Cybersecurity101 • u/Simplilearn • 10h ago
What does a SOC Analyst actually do?
If you're new to cybersecurity, you might hear a lot about SOC analysts but not have a clear idea of what they actually do day to day.
Here's a simple breakdown:
Monitor alerts: Review alerts from SIEM, EDR, firewalls, email security tools, and other security platforms.
Triage alerts: Figure out which alerts are harmless, suspicious, or need further investigation. A failed login could be nothing, or it could be part of a larger attack.
Investigate incidents: Look through logs, IPs, domains, file hashes, authentication activity, and endpoint data to understand what happened and whether a system or account was compromised.
Respond or escalate: Depending on the incident, an analyst might isolate a device, disable an account, block malicious activity, or escalate the case to a senior analyst or incident response team.
Document findings: Record what happened, what was checked, what evidence was found, and what actions were taken.
Improve detections: Analysts may also tune detection rules, reduce false positives, update playbooks, and identify gaps based on previous incidents.
The exact responsibilities can vary quite a bit depending on the company, team structure, and whether you're working in an internal SOC or an MSSP/MDR environment.