Transcription
Hey there! Chances are that if you're watching this video, it's most likely because you're interested in a cyber security career as a SOC analyst.
Whether you're not working in tech at all right now or if you're trying to switch from your current role in tech, the SOC analyst role is one of the most widely known positions in cyber security, and it's where a lot of people start their journey.
When we talk about different cyber security roles, typically we break it into two categories. First, we have the defense, and those are the people that are responsible for defending our networks. Then we have the offensive side, and those are the people that are actually trying to find weaknesses or gaps in our security controls.
The SOC analyst job is a defensive cyber security job, but let's break it down more. If the term SOC is new to you, it stands for Security Operations Center, and this is basically the department or the team that's responsible for protecting an organization's network from cyber threats. Sometimes we even call the office or the area where this team works the SOC.
So then, knowing that, a SOC analyst is a person who works in the Security Operations Center on a team to monitor, analyze, and respond to security issues. The main goal of SOC analysts is to prevent attacks on a network. They monitor the network for signs of an attack with a variety of tools and technologies.
Typically within a SOC, you have tiers, which means that you have level 1, 2, and 3. Typically, that just means that level three has more knowledge and more responsibility within the SOC. That means that a junior level, or a tier one, or a level one, is going to have anywhere from no experience up to two or three years of experience.
It's also not uncommon for a SOC to operate 24 hours per day and seven days per week, which means that people working these jobs are working shifts, or they might staff people from around the world so that they can cover the entire day.
As you might already know or be guessing at this point, the Security Operations Center, where the SOC is, is extremely important for organizations to stay secure. One of the things that I get asked about all the time is a salary range.
So let's take a look at an example of a salary range for a SOC analyst. One website that I went to for salaries is called salary.com. If we go ahead and scroll down here, I searched for SOC analyst, and you can see here that the range is anywhere from eighty-three thousand dollars up to one hundred eighteen thousand dollars, with the average or the median being ninety-eight thousand dollars.
So that is some substantial pay for this job. Now, obviously, it's going to vary because it's going to depend on things like experience, education, skills, what that company needs, and what they can afford to pay, right? But that's a pretty nice range there, if you ask me.
I also brought Glassdoor just so you can see another website. I did the search for the United States, just like I did with the other search. This is saying on average eighty-nine thousand, so it's a little bit lower than the other one said, but you're getting pretty similar ranges here.
So you're getting anywhere from seventy-two thousand on the most likely range up to a maximum of one hundred thirty-six thousand. This range is a little bit wider than the previous one, but the average is a little bit different. Keep in mind these websites are going to vary, but the idea is the same: these kinds of jobs pay really, really well.
All right, so now that you know how much money you can make, let's talk about some free training options that you can use to improve your knowledge and build important skills. Keep in mind that these training options aren't ranked in order of importance, but they're all important skills that SOC analysts can have.
All right, let's take a look at the options. Okay, so this is the first option, and this is from Splunk. If you don't know what Splunk is, it's a SIM tool, which basically allows you to correlate and aggregate a bunch of data in one location.
So if you had a whole bunch of different servers or systems or anything like that, they're all generating audit events. You can bring them all into this one system, this one console, and you can look at all of that information on one screen or on multiple screens, create dashboards, create reports, do all that kind of really cool stuff.
It is a very, very valuable skill to have. So if we scroll down here, you can see that it starts talking about all the kinds of different free training that you can do. What is Splunk? Introduction to Splunk, using fields, intro to dashboards, scheduling reports and alerts, visualization—all of these different things that you can do, and they're all under the free training option.
Then, of course, if you click "find free training," then it's going to give you a little bit more information about how you can sign up and enroll for the different training. But this is one great option that is so, so important, especially with a tool like Splunk.
Splunk is one of those tools where it's so expensive that you, as an individual, are not going to go out and buy Splunk. It's just not going to happen, right? It's a pretty pricey tool, even for a lot of companies, but it is a really important skill set to have.
All right, the second option is from Qualys. If you're not familiar with Qualys, they make a lot of vulnerability management kind of tools, and they're really popular in the space. If we go ahead and scroll down in their training center here, we can see some things that are offered from them.
So they're going to have things like vulnerability management training. Now, that's really important in a SOC analyst role because that is going to be a major part of your job. You can see they have different levels; they have basically a learning path that's laid out for you, and you can learn a lot about just vulnerability management in general.
It doesn't have to necessarily mean that you're going to go out and use their tool, but a lot of the vulnerability management stuff between the different tools and vendors operates very similarly. It's just like with SIM tools. If you go and use a different SIM tool, you're going to have an understanding of how that new program works or how a SIM tool works. You just have to figure out how to use that new tool.
It's the same with vulnerability management and really any tool in the same category. So this is a really great option, and you can just go here and click on the different trainings and then enroll as well.
I hope you enjoyed the video so far. If you are, make sure to leave a like, comment, and subscribe. That way, YouTube knows you enjoy the content.
Also, let's take a second to talk about Cyber Training Pro and the career services and training that's offered over there. Are you tired of overpaying for cyber security training? Are you interested in training from industry professionals? Are you looking for cyber security career services?
If you answered yes to any of those questions, then cybertrainingpro.com is the perfect platform for you. At Cyber Training Pro, we're a one-stop shop for all your cyber security needs. We can train you for industry certifications or just improve your overall knowledge and skills in a certain area.
Unlike other platforms, we don't stop there. We can also coach you throughout your career, practice your interview skills, or create a high-performing resume with our career services. Cybertrainingpro.com isn't just another training platform. Students get exclusive access to our private community, where we go beyond training courses to provide additional content, tips and tricks, and engagement with both other students and staff.
Look, by the year 2025, there could be as many as 3.5 million job openings in cyber security. There's so much opportunity. Why not maximize your career potential with a platform that cares about your success? Come join us at cybertrainingpro.com and start building your future today.
Okay, the next option I want to show you is about the MITRE ATT&CK framework. Now, if you don't know what this is, I highly recommend you go check it out because this is really important too.
But essentially, it breaks down different attack techniques, procedures, and things like that that attackers are going to use, so you can understand how it works, how you can prevent it, and all of those related pieces of information.
So it is crucial to understand how this can be used and different things that are in here. You have things like reconnaissance and resource development, initial access, execution, how attackers move through your networks—all that kind of stuff.
So I just want to show you this first so you understand what this is, but this is going to be really important if you work in a SOC. Now, if we go to the training page here, you can see there's a few different training options that you can go after.
So we'll just click on this fundamentals badge training here, this course, and you can see this takes us to Cybrary. A lot of the training is actually through Cybrary, but you can just create a free account, and you can actually learn this stuff.
This is really, really useful information. I can't stress that enough because it's going to help you in a SOC as far as attributing attacks, identifying attacks, and understanding prevention measures that you can put into place. It's just extremely important.
Now, the next option is from Coursera, and it's created by Cisco. It's called the Security Operations Center, or SOC course. I bring this up because typically with Coursera, they have kind of this free trial period where you can sign up, and you get a trial period that you can access the content and go through it.
So you have to be careful in Coursera, especially if you don't want to pay for anything, right? It's really important. But you can scroll down here, and you can see the different things that are going to be covered in here.
Again, it's from Cisco, so you know it's going to be some good quality. But you have an introduction to the Security Operations Center, so you're going to find out what a SOC is, basically a little bit more in depth, security operations center processes and services, so how things operate within a SOC, SOC deployment models and types.
There are all kinds of different deployment models that you can use and configurations of how your SOC is set up. Staffing and effective SOC team—if you're starting out, this might not necessarily be something that's going to help you because you're not going to be hiring people, right? Most likely.
But it is useful to understand that security events data and SOC analyst tools—that's obviously going to be a good one. Learn about some of the tools that are in there, developing key relationships with internal and external stakeholders. Relationships are huge in any security role, not just a SOC role.
Understanding SOC metrics, understanding SOC workflow and automation—so really, really nicely laid out course. It is from Coursera, so again, you have to be careful, especially if you don't want to pay for the course because you're only going to get a free trial, and then it's going to kick in and charge you if you don't cancel it or get out of that.
But again, this is another really useful free option. Wireshark is another really useful tool that's used in Security Operations Centers and all kinds of cyber security and IT roles. Basically, it lets you analyze packets.
So if you can capture a packet of data on a network, you can see what's happening with that packet, who's sending it, who's receiving it, and what's inside of that packet—so what's in the payload. It is a tremendously valuable tool, and it's really important for a SOC analyst job. You're going to need to know this tool for sure.
Now, if you go to the Wireshark website and click on "learn," they do have some of this YouTube stuff and Wireshark University. You can just go on here, and you can click on these and see the different trainings. Click on this one, and you can see it's got a bunch of different YouTube videos on there.
So it's going to give you a lot of the fundamentals as far as Wireshark. Obviously, there are other options out there, other resources for Wireshark, and really a lot of these other tools that might not be free, but this is another really good option, and you're definitely going to want to know how to use Wireshark.
Question of the day: which training option from this video are you going to use to study? Are you going to use a different method? Let me know down in the comments section below.
The SOC analyst role is not a great place to start your cyber security career, but also some people spend their entire career there because things are always changing and evolving. If you like the technical aspects of cyber security, you can definitely find yourself a good SOC analyst role, and these training options are a good place to start.
If you're looking for more training or career service options, make sure to check out Cyber Training Pro. As always, make sure to leave a like, comment, and subscribe. Check out the description for more resources related to this video, and I'll see you next time.