📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

FASTEST way to become a SOC Analyst and ACTUALLY get a job (Updated 2025)

UnixGuy | Cyber Security15:22

Transcription

The number one reason why candidates can't get a cyber security job is not the lack of recognized certifications. It's not the economy, and it's definitely not AI. It is, however, the lack of experience.

But how can we get this experience without having a job? None of us were born with experience, yet somehow hundreds of individuals manage to land their first cyber security job every single day. So how do they do it?

Well, someone in my Discord server managed to do exactly that. He landed an entry-level remote cyber security job with one of the biggest vendors in the world, and he did it without having any IT experience. I want to show you exactly how he did it.

Oh, and by the way, there is a huge discount and giveaway in this video. Trust me, you don't want to miss this one.

Now, to hide the identity of the member of my Discord server, let's call him Mike. Honestly, he's been one of my favorite people in the Discord server. He's in his early 20s, he lives in AUST, Australia, and he works in hospitality. But he wanted a career change; he wanted to do something different.

Now, he looked into cyber security, but the problem is he was following the crappy advice online that tells you that you need to cram and do a bunch of random multiple-choice based question exams that are extremely boring and cost a lot of money. Not only that, but he was also under the impression that cyber security is simply not accessible as an entry-level job. In fact, he thought that he needed to work as a network engineer first.

Now, of course, none of that is true. Network engineering is a completely different career path than cyber security. If you've been watching my videos, you know that I post success stories from all over the world from individuals who followed advice in my videos and managed to land their first cyber security job without having to do any multiple-choice based exams and without having to work as network engineers or even in help desk.

Now, it's not easy, but if you follow the advice in my videos and work hard, there is no reason why you can't reach your goal.

As Mike started to follow one of the road maps in my videos, he began to gain real hands-on cyber security skills that gave him the confidence he needed to start applying to cyber security jobs. Naturally, he got some rejections, as we all do, but he also managed to land an interview.

This is where things got really interesting. He posted about it on Discord asking for advice, and I asked him to send me the job description. As soon as I saw the job description, I immediately recommended that he do the SOC analyst learning path from Let's Defend.

Now, he had two weeks before his interview, so he had limited time. Therefore, I told him to take leave from his current job so he could spend all his time doing this training course.

I've recommended Let's Defend before in my videos, and as you know by now, I only recommend courses that I've personally done and vetted that are hands-on, practical, and have skills relevant to the cyber security market.

I work in consulting, and I help organizations hire cyber security professionals. I interview cyber security candidates every single week as part of my job, and I know what the market requires. Trust me, it's not those random boring multiple-choice exam stuff that everyone seems to follow.

After I sent him that link, I reached out to Let's Defend and asked them if it was okay that I showcase some of their products in my video. They've agreed, but not only that, they even generously agreed to sponsor this video and have given us a crazy exclusive discount for this YouTube channel.

They gave us a 55% discount on all their annual plans using a discount code that I will leave in the description box of this video and in a pinned comment. This discount is only valid for two weeks after the release date of this video, so please hurry up if you want to make use of it.

Not only that, but if you're a student, on top of that discount, you can get a further 50% discount if you have a student email, which honestly makes it a no-brainer.

Now, let's take a look at the SOC analyst learning path. As you can see, it consists of 25 big modules. The first module alone, which is SOC fundamentals, was the one module that Mike managed to finish in the two weeks that he had to prepare for his interview.

As you can see on the screen, he said that the majority of the interview questions were literally from this module alone. So trust me when I tell you that the training courses I recommend are exactly what organizations are looking for in the cyber security industry.

Now, the SOC fundamentals will take you through what a SOC is, the different types of SOCs, what we mean by SIEM, log management, EDR, threat intelligence, and common mistakes. This is really your introduction to the world of SOC, which, if you're not familiar with it yet, stands for Security Operations Center.

This is the center where we have individuals we refer to as SOC analysts. Sometimes we refer to them as cyber analysts. They detect and analyze cyber security attacks and respond to these attacks. Having SOC is fundamental to any business that wants to operate because it will give them that visibility and readiness to detect and respond to cyber attacks.

Now, as with every single training course that I recommend, Let's Defend is fully practical and hands-on, meaning they have labs that you can practice on. The great thing about this is you don't need a really powerful laptop or computer to access these labs. Instead, you can simply access them via your web browser, which is really convenient.

For example, if we click on "Investigate Web Attacks," as you can see, there is a lab environment. We can simply connect to the lab environment. As the lab is launching, we can read through the description. This lab will show you how to investigate a web attack, how to conduct digital forensics, and incident response.

There is even a walkthrough. As you can see here, you will get to practice and follow the lab, but then you will need to answer questions based on your work in this lab. On the right-hand side, you can see a scoreboard of other students who are doing the same lab as you.

Now, just looking at the topics in this SOC analyst learning path, it covers pretty much everything you need to be a SOC analyst. It starts you from absolute zero all the way to getting you to detect, analyze, and respond to cyber attacks. It even teaches you SIEM, such as Splunk and other industry tools that you will run into on the job.

Now, Mike has been following advice in my videos, and therefore this was not the first hands-on practical training course that he has done, so he was able to jump straight into it. But if you haven't done any training courses before and you have no degree and no technical background whatsoever, and you're starting from absolute zero, then I recommend that you first start with the Let's Defend module called Cyber Security for Students.

This learning path will give you all the fundamental background that you need, starting with network fundamentals, Windows fundamentals, Linux for Blue Team, network protocols, cryptography, malware analysis, traffic analysis with Wireshark, how to investigate with SIEM. It will even take you through the principles of remote work so that it prepares you for a remote job as a SOC analyst.

It even has a module on how to job hunt, how to look for a cyber security job, which is fantastic for a beginner. So I recommend you do that first, then you do the SOC analyst learning path.

If you haven't done any cyber security training before, honestly, this is perfect for someone who's done something like the Google Cyber Security Certificate or CompTIA Security+ or perhaps for someone who's done GRC Mastery and is working in GRC but wants to add some technical hands-on skills. This will be a fantastic start for you because it will give you those technical hands-on skills that will enable you to be comfortable when you undertake SOC analyst training courses.

But wait, this is training. Remember, at the beginning of the video, I told you the reason why individuals get rejected is because they don't have experience. So the question is, can we add this training as experience in our resume, or is there something else that we can do that we can add as experience in our resume?

Well, what I'm about to show you will solve this problem for you. I found an option within Let's Defend that we can add as experience that most people don't even know about. But before we do that, let me quickly show you how we can add the Let's Defend SOC analyst learning path as a training course in our resume.

I want you to go to ChatGPT and type "Add Let's Defend SOC analyst learning path to my resume in one bullet point" and give me three options. As you can see, ChatGPT will give you three different options on how to add this as a bullet point. Simply copy the one that you like and add it to your resume.

In my case, this is the line that I will add to my resume. Now, if you want this resume template, you can download it for free from UnixGuy.com/free.

Now, if we want to add experience to our resume that can prove that we indeed can work in a SOC, we can detect incidents, and we can respond to them in a professional environment, then this incredible option in Let's Defend will let you do exactly that.

So from the Let's Defend website, just click on "Practice," and there you will have access to a live SOC environment run by Let's Defend that you can access and practice on. This is designed and run exactly like a real SOC environment, except it is for learning purposes. So you can safely practice, and you can learn from your mistakes without having to worry about breaking things in the real world.

Now, let's have a look at some of the things that we can practice in this SOC environment. As you can see, there is a main channel, investigation channel, and closed alerts. In the main channel, it's showing you all the tickets or all the alerts that were detected. This is what you see in a SOC environment; you usually get assigned tickets to investigate and analyze.

As you can see, the tickets are rated as medium, high, and critical. If we click on one of the tickets, as you can see, we can take an action, which is "Take Ownership." This means that this will be a ticket that you can investigate.

On the left, there is log management, case management, endpoint security, email security, threat intelligence, and a sandbox. For example, when you pick a ticket, you take ownership of that ticket. You might see some IP addresses, so you go to log management and search for these IP addresses. You investigate the incident, and perhaps you do some testing in the sandbox or look at some of the threat intelligence information, and then you close that ticket exactly as you would do in a professional environment.

Now, if this sounds too hard for you or it sounds foreign to you, this is perfectly normal because you're not supposed to jump straight into this. Instead, you're supposed to do the SOC analyst learning path first. That will teach you those skills and give you a chance to practice on labs.

But then you can come to the SOC environment and practice these things. Honestly, I really wish I had something like this when I was starting because when I first found myself in a Security Operations Center as a junior analyst, it was nerve-wracking. You want to investigate things, you want to learn, but at the same time, you're not really sure what you're doing.

So we always had to go and ask senior analysts for help and guidance, and sometimes they were too busy and just simply didn't have time for us. The fact that you can do this in a lab environment that's similar to the real world will give you the confidence you need to not only do well in the interview but also do really well on the job.

Now, to add it to a resume, I will use ChatGPT again just to make life easier and also to teach you how to use ChatGPT to improve your resume. I want you to type "Add one month of practice in Let's Defend SOC monitoring as experience as a bullet point" and give me three options.

Now, I said one month; I'm just making an assumption that you will practice for one month using the SOC monitoring lab. But you might decide to spend longer, or maybe you just spend two weeks. It's all up to you; I'm just showing you an example.

As we did before, we will pick the best option from the answers and then add it to our resume. Now, just a caveat with this: we're not trying to trick hiring managers into thinking that we work in a company. They know that this is a lab environment, but it will simply make your resume stand out because you've not only learned the subject but you've spent time putting those learnings into practice in a real environment.

Now compare that to someone who spent the last two years doing random multiple-choice exams, learning random things, and doing random projects, and never really challenged themselves in anything that resembles the real world. It will give you a huge competitive advantage when it comes to applying and landing your first cyber security job.

But now you might be wondering, what if I want to work in GRC, or what if I want to work in red teaming or penetration testing? Do I really need to do SOC analyst training? To be honest, the answer is it depends.

If you've never worked in cyber security before, I always recommend you approach your learning and training from a generalist point of view. Meaning, I want you to acquire a broad set of skills that will qualify you for a large number of jobs so you can maximize your chances of getting your foot in the door and landing that first cyber security job.

Because the first job will always be the hardest one to get. Once you get your foot in the door, things get a lot easier, and you can switch your specializations later. Therefore, I always recommend that you acquire SOC analyst skills, GRC skills, and yes, even some basic entry-level penetration testing skills.

Combining those will just maximize the number of jobs that you can apply to, but it will also make you really attractive to small to medium-sized businesses because they tend to hire generalists with a broad set of skills. They want you to do more than one task; they don't always have the luxury of having a dedicated SOC team or a dedicated GRC team. They want you to know a little bit of everything, which can be a fantastic learning opportunity.

However, if you're someone who's already experienced, perhaps you've been working in red teaming or you've been working in GRC, I still think doing SOC analyst training is worthwhile because it will just make you more well-rounded as a cyber security professional.

In fact, this is what I've personally done. I worked in incident response and digital forensics, and now I do GRC and strategy work and architecture. But I've also done some penetration testing training. All of this knowledge combined made me a real effective leader, and it came in really handy in consulting because different companies will have different problems.

Just having that hands-on skills will make you a lot more efficient, but it will also give you real confidence because you know your stuff.

Now, if you're not sure how to use SOC analyst skills as part of a structured learning plan that will get you to land your first cyber security job, then I've got you covered. I've created this video that has a step-by-step plan where you build your skills from zero, including adding SOC analyst skills as part of a comprehensive plan that will get you to land your first cyber security job in the cheapest and fastest way possible.

Check it out, and I'll see you there.