CAREER PATH

SOC Analyst

The hands-on, front-line counterpart to Cloud Security Architect — watching Sentinel and Defender, and knowing what to do when something lights up.

6 clusters 3 domains ~50 hours SC-200 aligned

Drag to rotate · click a node to jump straight into that domain

Who this is for

No prior security operations experience required — this is designed as an entry point into security work.

How this path works
Each cluster below links to its real lesson page. Go in order the first time through — later clusters assume the ones before them. Once you've done a full pass, use it as reference.

The path — in order

Identity & Security

01
Most incidents trace back to identity somehow.
Domain 4 · Identity & Security
02
The signals a SOC analyst reviews daily.
Domain 4 · Identity & Security

Security Operations

03
The SIEM/SOAR platform this role lives inside.
Domain 11 · Security Operations
04
Unified detection across endpoint, identity, and email.
Domain 11 · Security Operations
05
KQL queries and the actual investigation process.
Domain 11 · Security Operations
06
Tuning alerts so real threats don't get lost in noise.
Domain 11 · Security Operations

Certification this path maps to

SC-200: Security Operations Analyst Associate

Where this leads

Security Engineer is the natural next step into hands-on implementation. Cloud Security Architect is the long-term senior path.

Start the path → See other career paths