Transcription
One of the best roles to break into information security right now is as a SOC analyst. If you're looking for a cyber career that has a lot of possibilities and professional growth, then SOC analysts could be what you're looking for. They're in high demand, there's a lot of opportunity for advancement, and, like I said before, it has a really good chance of being an entry-level role over other roles in the industry.
Our modern society is super connected. Whether it's my cell phone ordering coffee online or a business doing enterprise resource planning and connecting with third parties, they are all interconnected. Cyber threats have become an ever-present danger to governments, businesses, and even individuals like my Aunt Dorotha. From ransomware attacks to data breaches, the stakes are really, really high. Amidst all this threat actor activity, there's a growing need for pros who can see bad things happening and, more importantly, help contain and eradicate them.
Well, Security Operation Center, or SOC analysts, have entered the chat. Now, learning and becoming a SOC analyst can be a lot like an M. Night Shyamalan movie—complicated. There are so many learning options out there, and not all of them provide the hands-on experience that employers are looking for. So, it's easy to get overwhelmed by all the cyber education options out there, which leads me to today's sponsor, Let's Defend, who can help with that.
But before we get into Let's Defend, why would you even want to be a SOC analyst in the first place? Well, the demand for skilled SOC analysts is skyrocketing as organizations increasingly rely on technology. They all are facing a growing number of cyber threats. It's just a fact: the more attack surface you have, the more threats you have, and the more risk you have. From ransomware attacks to data breaches, they're happening with greater frequency as well. This has led to a surge in demand for pros who can do something about it.
According to a market.us survey, the global cyber market is expected to reach $271 billion by 2026. This growth is fueled by the increasing sophistication of cyber attacks and the growing awareness of the risks they pose to governments and businesses.
Right now, let's look at what actual career opportunities for the SOC analyst are, because they're vast and diverse, and you want to know that there's some growth potential for you. You can work in a variety of industries, including finance, healthcare, tech, government, etc. You can pivot through them because, honestly, looking at packets on the wire in finance versus packets on the wire in healthcare, responding to phishing emails, whether you work in manufacturing or K through 12 education, it's very, very similar.
So, there's a lot of flexibility and opportunity depending on what kind of environment you want. Finance is a little bit higher stress; K through 12 maybe doesn't pay as well, etc. You can work in different facets, including corporate security. Many large corporations, think financial services and Fortune 500 companies, have dedicated security teams that employ SOC analysts to protect their networks and data. This makes a lot of sense because you want those people as close to the situation as possible. Day in and day out, they know who the key people are, they know what systems are critical, and they can respond and be accountable.
Corporate security is a great gig. In-house cyber—you could also work for a government agency. Government agencies are kind of like corporate security, except you're a civilian. You can work with the FBI, CIA, NSA, etc. They have special cyber divisions that rely on SOC analysts to perform work and help protect the mission, whether it's at a forward operating base or in a domestic situation. There are these opportunities.
Another really popular one, and the one that I would advise you to look for, is consulting firms. A lot of these professional services firms hire people to be SOC analysts to provide expert advice and services to clients. Now, you might be like, "Oh Jerry, I don't have expert SOC advice. Why would a consulting firm hire me?" Well, remember there's a service called MDR, or managed detection and response.
Think of it as an outsourced SOC analyst role or an outsourced Security Operation Center full of SOC analysts. Essentially, I'm a business that can't afford to hire my own like the corporate security Fortune 500 people, but I can pay a portion of that to a business that outsources it. I just send all my logs and data to them, and they use SOC analysts to look at all that stuff. When they detect bad, they either take action on it for you or notify you, and you take action on it.
Because this is like consulting, firms are really encouraged to hire people who are junior level, essentially because they can pay them less. Let's be real. Because they can pay them less, the profit margins are huge for those consulting firms. But, of course, you're getting the experience and years of service, and then you can either level up, get more pay, or transition within the industry.
So, there are all great options, and they're all out there. As the cyber landscape continues to evolve, the demand for these SOC analysts is expected to grow, as you would imagine. This means that there's plenty of opportunity for career advancement and professional development.
But you might be wondering, like, what kind of impact can I have? SOC analyst sounds cool, but I want to have an impact. Well, you can protect sensitive data. Cyber attacks can lead to the theft of sensitive data like personal information, financial records, healthcare records. SOC analysts work tirelessly to protect this information from getting doxxed out there. You could protect someone from identity theft; you could prevent financial loss.
Cyber attacks can cause significant financial damage to businesses. By preventing these attacks, you can avoid costly downtime, legal expenses, and reputational harm. To personalize it, if a business gets hit so bad that they lose so much money they have to go out of business, oh, it's just a business—who cares? Well, real people work at that business, and those real people have real families that depend on those real paychecks to pay for rent, food, clothing, and life essentials.
So, not to put too much pressure on you, but you have the potential to help protect those families too. It really is high stakes. Additionally, you could save lives. If you protect critical infrastructure like healthcare systems or power grids, you can make sure that someone who needs to get a blood transfusion or needs to get diagnosed with a stroke gets what they need—not because the systems are down, but because you protected them.
Also, dude, talking about the electrical grid—imagine for a second the grid got shut down in the dead of winter for 48 hours. People could literally freeze. So, there are a lot of high-impact value adds for SOC analysts to work in.
But let's talk about the skills gap. Why isn't everybody a SOC analyst? Well, there are a lot of challenges out there. There's a lack of training, or good training. Traditional cyber training focuses on theory, concepts, practical skills, you know, multiple-choice certifications, etc. But this doesn't necessarily translate into practical hands-on skills for SOC roles, which makes it difficult to get hired or even explain in a job interview how you know how to do what they want to hire you for.
There's also a lot of technological advancements. The cyber landscape is constantly evolving. New threats—it's a cat-and-mouse game. When the tech keeps changing, if you're not staying abreast of it, if you don't have hands-on experience, your skills start to get rusty. So, that's definitely a challenge as well, and it begins to devalue your value proposition to a potential employer.
Additionally, and this one's often overlooked, there's a lack of awareness that the talent's even out there. You could be crushing it, but if you haven't developed the ability to communicate it or you don't have the tools to communicate that out to the market, then you could be great at being a SOC analyst and not get hired because nobody knows it. So, there's an issue there.
Now, if I was going to break into the workforce, GRC analyst and SOC analyst are definitely the optimal entry-level entry points. I want to focus on SOC analyst because when it comes to getting those sweet skills for SOC analyst, that's where the video sponsor, Let's Defend, comes in.
Now, I have used Let's Defend. I like Let's Defend. I think they're great. They are an online learning platform that focuses on providing hands-on training for blue team members of the cybersecurity industry. They have multiple career paths on their platform and lots of learning options, but I want to dial into the SOC analyst career path because it provides a comprehensive and practical approach to learning cybersecurity.
Now, they have hands-on labs where you'll gain practical experience in real-world scenarios, from detecting phishing attacks to responding to data breaches. Their supportive community also includes space to connect with other learners and share knowledge, which is very cool. At the end, you actually get a certificate of completion, which you can put on your LinkedIn or on your personal portfolio site.
So, what are some key features of the Let's Defend platform? Why is it so cool? Well, they have hands-on labs. Their hands-on labs are designed to simulate real-world cyber challenges. I underline, bold, and highlight "real-world." It gives you the opportunity to practice skills in a safe and controlled environment.
That includes being notified of potential incidents, working through email logs, network logs, EDR logs. You can open tickets, triage, render your findings, and quarantine a machine if you need to. It's really, really close to what a SOC analyst would experience in the field. I mean, they have a whole interface that's very similar to a SOC analyst console.
Basically, like I said before, there's a lot of community support. There's a Discord server that's pretty healthy. You can do flexible learning. Their platform is designed for asynchronous learning, so it allows you to learn at your own pace, go back and revisit some lessons that you had challenges on, or labs that you didn't quite understand. You move at your own pace.
So, for those people who have dynamic lives nowadays—maybe you've got two jobs, or you're watching kids, or whatever—because it's all browser-based, even the lab environments that are like full operating systems and stuff, you can access it from a lot of different devices. All you need is a browser and an internet connection, so it's very, very flexible. I really appreciate it.
With Let's Defend, you'll have everything you need to learn and succeed as an entry-level SOC analyst. So, let's dig into the course and labs, and I'll show you what I'm talking about.
What I think is a really valuable aspect to highlight of the SOC analyst career path is the phishing exercise labs. These labs provide you with hands-on experience in detecting and responding to a phishing attack, which are kind of the most common types of cyber threats. I would argue if you're going to work for managed detection and response as a junior analyst, they're probably going to throw you at phishing attacks first.
So, if you're getting skills in the thing that they're probably going to put you on to start, you're already ahead of the curve, and you could probably crush it in a job interview. In the phishing labs on Let's Defend, you'll be presented with a variety of phishing emails, ranging from simple scams to more sophisticated attacks. You'll learn how to identify the key indicators of the phishing attempt, like a suspicious link, unusual email address, grammatical errors, and weird reply-to spoofing.
Once you've identified it as a phishing attempt, you can then investigate further. You'll learn how to analyze, for example, email headers to track the sender's IP address and identify associated malicious websites. This will help you understand how this phishing attack works. You can see the whole life cycle of the attack, and they do offer you guidance and hints on the platform in case you're having a little bit of a challenge.
You'll also learn how to respond to those phishing incidents, like notifying and educating end users, etc. When you complete the phishing exercise labs, you'll have developed the skills and the knowledge to effectively detect and respond to those phishing attacks, which I just think is great.
Now, all of this sounds really cool. We've got the lectures, browser-based SOC analyst career path, certificate—yes, yes, yes, Jerry, let's go, rock on! How do I get there? Well, use the link in the description below to check out Let's Defend.
But hold on! Simply Cyber viewers are going to get a special 50% off discount. That's right, half off through their Black Friday campaign. It's a limited-time run, but if you use the code "SIMPLYCYBER," you will get 50% off what I already think is a reasonably priced training solution.
By taking advantage of the discount, you can save a significant amount of money, which you can then apply to other areas of your career development or simply reduce your overall burden of having to pay for your cybersecurity education. The offer is limited time, though, so I don't want you to miss it. Check the dates on when it runs, but it is a Black Friday 2024 campaign for this half-off. You can visit the Let's Defend website to learn more about it and then enroll in the SOC analyst career path if you'd like.
Now, I want to point out, if you're not ready to commit, right? You're like, "I don't know, I want to check it out." Let's Defend does have a free tier, and you can take advantage of it. You can definitely get practical skills training without a financial commitment.
Now, it is limited what they have on the site that you can access, but you can definitely try out what the learning style is, what the labs look like, and all that—right, all for free. So, you can go check that out, and then if you decide you want to move forward and get this SOC analyst career path and access to all the other stuff on the platform, they have multiple career paths.
You will have to use that Black Friday code for Simply Cyber viewers—"SIMPLYCYBER" at checkout. But remember, it is limited time. So, use the free stuff for sure, but I just don't want you to decide you want to move forward and then be like, "Oh, the code doesn't work."
All right, I hope you enjoyed it. I really did. SOC analyst is absolutely a great entry-level role for all the reasons I outlined in the video. I'm Jerry from Simply Cyber. Until next time, stay secure.