Skip to main content
Defensive · SOC

Defensive / SOC → Detection Engineer

The realistic on-ramp into security. Defensive, structured, hireable. Biased toward SOC-stack certs. NOT CISSP.

Last reviewed May 2026Reviewed by a practitioner working in junior soc analyst (tier 1) hiringUpdated quarterly against live job listings
The verdict

The most hireable entry into security right now, but the work is shift-based and the alert fatigue is real.

You like structured work, can stomach nights and weekends for a couple of years, and genuinely enjoy chasing down what an alert actually means. SOC teaches detection in a way no course does.

You wanted security because it sounded prestigious. Tier 1 SOC is mostly triage and ticket-closing, and the romance wears off in a fortnight.

Phased progression

Foundations → first role → specialisation → advanced. The realistic order, not a script.

  1. 01Foundations
    0–6 months

    Literacy, lab habits, the cert that opens first conversations.

    Security+
  2. 02First paid role
    6–18 months

    Land a Junior SOC Analyst (Tier 1). Operational time, not more certs, earns the next move.

    Junior SOC Analyst (Tier 1)
    £28–38k entry SOC
  3. 03Specialisation
    1.5–3 years

    Add a specialist credential aligned to the work you're already doing.

    CySA+Splunk Core Certified User
    £42–60k mid
  4. 04Advanced
    3+ years

    Move into adjacent roles. Long-term credentials become worth their cost.

    Detection EngineerGCIA
    £65–85k detection eng (UK)

Certification sequence

Ordered by realistic relevance, not vendor marketing.

  • GCIA
  • GCIH

Practical projects

What to actually build, the portfolio that opens interviews.

  • Home SIEM with Wazuh or Sentinel + Sysmon
  • Author 5 Sigma rules with documented detections
  • Phishing triage playbook end-to-end
Detection EngineerThreat HunterIncident Responder
  • ·GRC route (lower technical bar)
  • ·Cloud route then pivot to cloud security

Realistic expectations

What no recruiter will tell you.

Misconception

That CISSP gets you in. It doesn't. CISSP is a senior-experience cert. Recruiters for L1 SOC look for Security+, BTL1, hands-on home labs and a clean explanation of an attack chain.

Honest window

Eight to fourteen months to first L1 seat with foundations already in place; cold entry from non-IT pushes that closer to two years. Then plan for another two to three years inside the SOC before L2 work is on offer — the planner's dwell ranges have been tightened to reflect that, no one credible moves out of Tier 1 in twelve months.

Where this fits

A pathway is a sequence, not a destination. Here are the roles and certs along it.

The next step

The pathway is plausible. Whether it holds for five years is a different question.

A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.