Skip to content

Skills you need to be a soc analyst

8 skills a hiring manager would actually test for, each with the level this role expects and what it is used for. Not a syllabus — the shape of the job.

Build my path to this role

Upskili checks what you can already do, then sequences only what is missing. No account needed.

What the role requires

Ordered by how much the job depends on it. The bar is the proficiency expected of a competent soc analyst — not mastery, and not a passing acquaintance.

  • SIEM (e.g., Splunk, Sentinel)

    Essential

    Triages, investigates, and correlates security events from logs.

    Strong
  • Incident response frameworks (NIST/SANS)

    Essential

    Containment, eradication, and recovery during live security incidents.

    Strong
  • Network traffic analysis (Wireshark, Zeek)

    Essential

    Identifies C2 traffic, exfiltration, and lateral movement in pcaps.

    Strong
  • EDR (CrowdStrike, Defender for Endpoint)

    Important

    Performs host-based threat hunting and malware analysis.

    Strong
  • MITRE ATT&CK framework

    Important

    Maps adversary TTPs to detections and incident reports.

    Strong
  • Email security analysis (Proofpoint, MDO)

    Important

    Analyzes phishing headers, payloads, and user-reported threats.

    Strong
  • Scripting (Python, PowerShell)

    Useful

    Automates log parsing and repetitive triage tasks.

    Working
  • Cloud security basics (AWS, Azure)

    Useful

    Investigates alerts from cloud-native security tools.

    Working

An order worth learning it in

A list of ten skills is the same unhelpful answer a catalogue gives, just sorted. This is where to actually start.

1

Start here

Essential to the role, and reachable from a standing start. Everything below rests on these.

  • Incident response frameworks (NIST/SANS)
  • Network traffic analysis (Wireshark, Zeek)
  • EDR (CrowdStrike, Defender for Endpoint)
  • MITRE ATT&CK framework
  • Email security analysis (Proofpoint, MDO)
2

Then this

The rest of what the role is assessed on. Harder, and it builds on the foundation above.

  • SIEM (e.g., Splunk, Sentinel)
3

What sets you apart

Not what gets you hired, but what separates doing the job from being trusted with it.

  • Scripting (Python, PowerShell)
  • Cloud security basics (AWS, Azure)

You almost certainly have some of this already.

That is the point of starting from the role rather than a course. Upskili checks what you can do, then builds a path across only the gap.

See my path to soc analyst