Security Operations Center
What is a SOC?
A Security Operations Center (SOC) is the team, the tools and the processes that watch an organisation's systems around the clock and respond to threats. Think of it as the control room of the security world: screens of alerts, analysts asking "is this real?", and a clear plan for what happens next.
Banks, telcos, fintechs, hospitals and governments run SOCs, either in-house or through a managed security service provider (MSSP). In Nigeria, larger banks and telecom operators run their own SOCs, while many mid-sized firms buy the service from local or international providers. Global companies often run "follow-the-sun" SOCs, with teams in different time zones covering 24 hours.
SOC Tiers and Roles
| Tier | Role | Typical work |
|---|---|---|
| Tier 1 | Alert / triage analyst | Watch the queue, decide if an alert is real, follow playbooks, escalate |
| Tier 2 | Incident responder | Investigate confirmed incidents in depth, contain and remediate |
| Tier 3 | Threat hunter / senior analyst | Proactively hunt for hidden threats, tune detections, handle complex cases |
| SOC manager | Leader | Staffing, metrics, reporting to management |
| Supporting roles | Detection engineers, threat intelligence, forensics | Build detections, study attackers, dig into evidence |
Tier 1 is where most careers begin. It is the best entry point for a newcomer, and the skills you build (log reading, networking, curiosity) carry through every other security role.
SIEM: The Brain of the SOC
A SIEM (Security Information and Event Management) system collects logs from firewalls, servers, endpoints, cloud services and applications, normalises them, correlates events and raises alerts.
Popular platforms include Splunk, Microsoft Sentinel, IBM QRadar, Elastic Security and the open-source Wazuh.
Correlation example:
Rule: 10 failed logins for one account within 5 minutes,
followed by a SUCCESSFUL login from a new country
-> Alert: "Possible account takeover", severity High
Neither event alone is alarming. Together they are. That is the value of correlation. Other tools around the SIEM: EDR (endpoint detection and response), SOAR (automation of repetitive response steps) and threat intelligence feeds.
Alert Triage: What Tier 1 Really Does
Most alerts are false positives. Triage is the disciplined process of deciding quickly and consistently:
- Read the alert: what rule fired, on which asset, for which user?
- Gather context: is the asset critical? Is the user on leave or travelling? Any similar alerts?
- Enrich: check IP or file hashes against threat intelligence (VirusTotal, AbuseIPDB), look at nearby logs.
- Decide: false positive (close and document), true positive (escalate) or need more data.
- Document: write what you checked and why. Good notes save the next analyst hours.
- Escalate with a clear summary: what, where, when, evidence, suggested action.
Questions to ask: Is this normal for this user or system? Does the timing make sense? Is the source known? What is the potential impact if I am wrong?
Priority = severity of the threat x importance of the asset. A medium alert on a domain controller can outrank a high alert on a test laptop.
SOC Metrics
- MTTD (mean time to detect): how long attackers are inside before you notice.
- MTTR (mean time to respond/resolve): how long from detection to containment.
- False-positive rate and alert volume per analyst: signs of alert fatigue.
Reducing these numbers is the SOC's constant goal.
Skills That Get You Hired
- Networking basics (Module 2) and Linux (Module 3).
- Reading logs and using a SIEM query language (Splunk SPL, KQL).
- Understanding common attacks (phishing, brute force, malware, lateral movement) and frameworks like MITRE ATT&CK.
- Clear writing and calm communication under pressure.
- Curiosity and persistence, because most of the job is careful investigation.
Try It: Triage the Queue
In the editor on the right, five alerts have arrived in your SIEM queue. For each one, choose the best action. There are no tricks, but context matters.
Try it yourself
Key Takeaways
- A SOC monitors systems around the clock and responds to threats. It can be in-house or provided by an MSSP.
- Tier 1 triages alerts, Tier 2 investigates incidents and Tier 3 hunts and tunes detections. Tier 1 is the best entry point for beginners.
- A SIEM collects and correlates logs from many sources and raises alerts. Common platforms include Splunk, Sentinel, QRadar, Elastic and Wazuh.
- Triage means read, gather context, enrich, decide, document and escalate. Priority combines threat severity with asset importance.
- Key metrics are MTTD, MTTR and false-positive rate. Log reading, networking and clear writing are the core hiring skills.
Quick Quiz
1.What is the main job of a Tier 1 SOC analyst?
2.Why is correlation valuable in a SIEM?
3.How should you prioritise two alerts: a medium alert on a domain controller and a high alert on an isolated test laptop?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx