Defensive / SOC → Detection Engineer
The realistic on-ramp into security. Defensive, structured, hireable. Biased toward SOC-stack certs. NOT CISSP.
The most hireable entry into security right now, but the work is shift-based and the alert fatigue is real.
You like structured work, can stomach nights and weekends for a couple of years, and genuinely enjoy chasing down what an alert actually means. SOC teaches detection in a way no course does.
You wanted security because it sounded prestigious. Tier 1 SOC is mostly triage and ticket-closing, and the romance wears off in a fortnight.
Phased progression
Foundations → first role → specialisation → advanced. The realistic order, not a script.
- 010–6 monthsFoundations
Literacy, lab habits, the cert that opens first conversations.
Security+ - 026–18 monthsFirst paid role
Land a Junior SOC Analyst (Tier 1). Operational time, not more certs, earns the next move.
Junior SOC Analyst (Tier 1)£28–38k entry SOC - 031.5–3 yearsSpecialisation
Add a specialist credential aligned to the work you're already doing.
CySA+Splunk Core Certified User£42–60k mid - 043+ yearsAdvanced
Move into adjacent roles. Long-term credentials become worth their cost.
Detection EngineerGCIA£65–85k detection eng (UK)
- 01Foundations0–6 months
Literacy, lab habits, the cert that opens first conversations.
Security+ - 02First paid role6–18 months
Land a Junior SOC Analyst (Tier 1). Operational time, not more certs, earns the next move.
Junior SOC Analyst (Tier 1)£28–38k entry SOC - 03Specialisation1.5–3 years
Add a specialist credential aligned to the work you're already doing.
CySA+Splunk Core Certified User£42–60k mid - 04Advanced3+ years
Move into adjacent roles. Long-term credentials become worth their cost.
Detection EngineerGCIA£65–85k detection eng (UK)
Certification sequence
Ordered by realistic relevance, not vendor marketing.
Practical projects
What to actually build, the portfolio that opens interviews.
- Home SIEM with Wazuh or Sentinel + Sysmon
- Author 5 Sigma rules with documented detections
- Phishing triage playbook end-to-end
- ·GRC route (lower technical bar)
- ·Cloud route then pivot to cloud security
Realistic expectations
What no recruiter will tell you.
That CISSP gets you in. It doesn't. CISSP is a senior-experience cert. Recruiters for L1 SOC look for Security+, BTL1, hands-on home labs and a clean explanation of an attack chain.
Eight to fourteen months to first L1 seat with foundations already in place; cold entry from non-IT pushes that closer to two years. Then plan for another two to three years inside the SOC before L2 work is on offer — the planner's dwell ranges have been tightened to reflect that, no one credible moves out of Tier 1 in twelve months.
Where this fits
A pathway is a sequence, not a destination. Here are the roles and certs along it.
- IT Support → Sysadmin (the honest on-ramp)
The realistic first paid technology job. No shortcuts, but the cleanest gateway into every other world.
- Enterprise IT. Windows / AD / M365
The Microsoft-shop spine. A durable, hireable lane and a direct on-ramp to security, cloud and IAM.
- Network Engineer
Underrated, stable, foundational to almost every other track.
- The realistic SOC analyst path
Most guides describe the job a SOC analyst wishes they had. Here's the one they actually do.
- When everyone passes, nobody differentiates
Exam dumps aren't mainly an ethics problem. They're a signal erosion problem. And that hurts honest candidates too.
- Why most people fail trying to leave helpdesk
It's almost never a skills problem. It's a positioning problem, a portfolio problem, and a willingness-to-be-uncomfortable problem, in that order.
The next step
The pathway is plausible. Whether it holds for five years is a different question.
A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.
A route shows what people usually do. A Career Verdict judges whether it's realistic for you.
A Career Verdict includes
Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.