What you'll learn this week
- What a Security Operations Centre is, who works in one, and what they do all day
- The tiers of a SOC, and where a new analyst starts
- The alert lifecycle — the loop that is the actual job
- The metrics a SOC lives and dies by, and how they distort behaviour
- Confirm your lab and Wazuh stack, ready to work as an analyst
- Triage your first real alerts and write them up properly
A note on this course. This is the applied half. The Beginners course taught you what attacks are and how to defend; here you do the daily work of the people who watch, detect and respond. It assumes you can already use a Linux and Windows command line, read logs, and explain the attack chain. If any of that is shaky, say so now — this course moves fast and builds on it from Week 2.
The room, and the job
A Security Operations Centre is the team — and often the physical room — responsible for watching an organisation's systems, detecting attacks, and responding to them. It is the human side of everything the Beginners course automated: the SIEM produces alerts; the SOC is who reads them, decides what they mean, and acts.
Strip away the wall of screens from the stock photos and the job is this: someone has to be watching, someone has to decide whether an alert is real, and someone has to do something about the real ones — around the clock, because attackers do not keep office hours.
That is the work. Not glamorous, frequently repetitive, occasionally urgent, and genuinely important. An organisation with excellent tools and no SOC has a very expensive alarm nobody answers.
What an analyst does all day
The honest picture, because it is not what films suggest:
- Triage alerts. The SIEM raises alerts; you decide which are real, which are noise, and which need escalation. This is most of the job, most days.
- Investigate. When an alert looks real, you dig — what happened, how far it went, what to do. The skill this whole course builds.
- Respond. Contain and remediate confirmed incidents, or hand them to whoever does.
- Tune. Reduce false positives so the alerts that remain are worth reading. Continuous, and the mark of a good analyst.
- Hunt. Proactively look for threats that did not trigger an alert — the advanced end.
- Document. Write up what you found, so others can act and so the next analyst understands. Underrated and constant.
Notice how much of that is judgement and writing, not clicking. The tools are learnable in weeks; the judgement about what an alert means, and the ability to explain it, is what takes a career and what makes you employable.
Why SOCs exist
An organisation of any size generates more security-relevant events than any person could watch, across more systems than anyone could log into. The Beginners course showed why: logs are scattered, local, temporary, and voluminous. A SIEM solves the collection; a SOC solves the attention.
And attacks do not stop at 5 p.m. A great deal of serious activity happens at night, on weekends, on public holidays — precisely because attackers know nobody is watching. So SOCs run in shifts, around the clock, which is why the job involves rotas and why "24/7 monitoring" is a service organisations pay real money for.
In-house, MSSP, and where you might work
Two common shapes, both relevant to your job prospects:
- In-house SOC — the organisation runs its own, for itself. Common in banks, telcos, large enterprises.
- MSSP — a Managed Security Service Provider runs a SOC that watches many client organisations at once. Much of the SOC hiring in Nigeria is here, including at companies like the one that built this course. An MSSP analyst watches several clients' environments from one console, which is demanding and an excellent way to see a lot, fast.
Either way, the skills are the same, and they are the skills of this course.
Try it now
No tools yet — orient to the work.
Search for a real SOC analyst job posting, Nigerian if you can find one. Read what it asks for.
- What tools does it name? (SIEM, EDR, specific products.)
- What does it expect you to do — the responsibilities?
- What does it list as required versus nice-to-have?
Keep it. By Week 12 you will be able to do most of what it describes, and comparing this course's work against a real posting is the clearest map of where you are heading — and what to put on a CV.