SOC Analyst Tier 1
The most realistic technical-adjacent on-ramp into cyber for non-coders.
What the day actually looks like.
Shift work — say 06:00–14:00 WAT to cover the European morning and US East night handoff. Triage 30–60 alerts per shift in Splunk / Microsoft Sentinel / Chronicle. 'Impossible travel: Lagos to Toronto in 10 minutes' — check VPN logs, Entra sign-ins, the device. Sandbox a phishing URL in URLscan, hash-check on VirusTotal, write a 4-line verdict, escalate or close. Repeat. Pattern recognition + writing things down clearly, on rotation.
Where the work lives.
What you actually need.
- Networking (TCP/IP, DNS, HTTP)
- Basic Windows / Linux event logs
- One SIEM (Splunk, Sentinel, QRadar, Chronicle)
- One EDR (Falcon, SentinelOne, Defender)
- Email / phishing analysis
- MITRE ATT&CK
- Ticketing (ServiceNow, Jira, TheHive)transferable
- Pattern recognitiontransferable
Editors are professional pattern matchers — spotting 'this looks off' in 100 logs is the same as a continuity error in 100 frames.
- Documentation disciplinetransferable
- Written communicationtransferable
- Calm during high alert volumetransferable
The shape of the journey.
- 1SOC Analyst T10–2 yr
- 2SOC Analyst T22–4 yr
- 3SOC T3 / Senior4–7 yr
- 4SOC Lead6–10 yr
- 5SOC Manager9–15 yr
Note. Times reflect typical paths for someone with strong communication and 10–15 hrs/week of focused study.
What it pays.
Ranges are directional. Currency: USD · annual. The local-to-remote 12–18 month jump is the practical career move. Last updated: 2025.
The cert sequence that won't bankrupt you.
TryHackMe SOC L1 path
TryHackMe$14/mo. The canonical hands-on starting point.
Security+
CompTIAOften via StationX bundles ~$340. Standard hiring filter.
Microsoft SC-200
MicrosoftDefender + Sentinel — fits Microsoft-shop banks.
BTL1 (Blue Team Level 1)
Security Blue TeamHands-on alternative to SC-200.
Splunk Fundamentals 1/2
SplunkFree official training.
CySA+
CompTIAT2 progression cert.
Working from Lagos, Abuja, or anywhere.
24/7 coverage means Nigerian timezone is an asset. Realistic Nigerian path: first job at a local SOC for 12–18 months, then jump to a remote MSSP at 2–3× the USD salary.
The good, the gritty, and who this suits.
- +Realistic foot-in-the-door — most non-coders enter cyber here.
- +Pattern recognition over coding.
- +Clear progression to T2/T3, threat hunting, IR, GRC.
- −Lowest-paid cyber role.
- −Shift work and burnout (71% of SOC analysts cited as burnout-affected, 2025 industry data).
- −AI/agentic SOC tools are automating routine triage — adapt and learn to supervise the tools.
If you can spot a continuity error across 100 frames, you can spot a malicious login across 100 alerts.
Three to five hours that beat any cert.
Become a SOC Analyst in 2024 — ROADMAP
Why watch. Step-by-step roadmap with no fluff.
How to Become a Cybersecurity Analyst
Why watch. Concrete entry-path guidance.
What does a SOC analyst do?
Why watch. Honest day-to-day from a working analyst.
Do this by Friday.
This week: subscribe to TryHackMe ($14/mo via virtual USD card) and complete the free pre-security path by Sunday. That's the only first step that matters.