Defensive / SOC → Detection Engineer
The realistic on-ramp into security. Defensive, structured, hireable. Biased toward SOC-stack certs. NOT CISSP.
The most hireable entry into security right now, but the work is shift-based and the alert fatigue is real.
You like structured work, can stomach nights and weekends for a couple of years, and genuinely enjoy chasing down what an alert actually means. SOC teaches detection in a way no course does.
You wanted security because it sounded prestigious. Tier 1 SOC is mostly triage and ticket-closing, and the romance wears off in a fortnight.
Phased progression
Foundations → first role → specialisation → advanced. The realistic order, not a script.
Salary figures are POST practitioner estimates, not survey data.
- 010–6 monthsFoundations
Literacy, lab habits, the cert that opens first conversations.
Security+ - 026–18 monthsFirst paid role
Land a Junior SOC Analyst (Tier 1). Operational time, not more certs, earns the next move.
Junior SOC Analyst (Tier 1)£28–38k entry SOC - 031.5–3 yearsSpecialisation
Add a specialist credential aligned to the work you're already doing.
CySA+Splunk Core Certified User£42–60k mid - 043+ yearsAdvanced
Move into adjacent roles. Long-term credentials become worth their cost.
Detection EngineerGCIA£65–85k detection eng (UK)
- 01Foundations0–6 months
Literacy, lab habits, the cert that opens first conversations.
Security+ - 02First paid role6–18 months
Land a Junior SOC Analyst (Tier 1). Operational time, not more certs, earns the next move.
Junior SOC Analyst (Tier 1)£28–38k entry SOC - 03Specialisation1.5–3 years
Add a specialist credential aligned to the work you're already doing.
CySA+Splunk Core Certified User£42–60k mid - 04Advanced3+ years
Move into adjacent roles. Long-term credentials become worth their cost.
Detection EngineerGCIA£65–85k detection eng (UK)
Certification sequence
Ordered by realistic relevance, not vendor marketing.
Practical projects
What to actually build, the portfolio that opens interviews.
- Home SIEM with Wazuh or Sentinel + Sysmon
- Author 5 Sigma rules with documented detections
- Phishing triage playbook end-to-end
- ·GRC route (lower technical bar)
- ·Cloud route then pivot to cloud security
Realistic expectations
What no recruiter will tell you.
That CISSP gets you in. It doesn't. CISSP is a senior-experience cert. Recruiters for L1 SOC look for Security+, BTL1, hands-on home labs and a clean explanation of an attack chain.
Eight to fourteen months to first L1 seat with foundations already in place; cold entry from non-IT pushes that closer to two years. Then plan for another two to three years inside the SOC before L2 work is on offer — the planner's dwell ranges have been tightened to reflect that, no one credible moves out of Tier 1 in twelve months.
What this is based on
Practitioner assessment checked against published external evidence.
Last reviewed: September 2026 · UK market · Confidence: indicative
Where this fits
A pathway is a sequence, not a destination. Here are the roles and certs along it.
- IT Support → Sysadmin (the honest on-ramp)
The realistic first paid technology job. No shortcuts, but the cleanest gateway into every other world.
- Enterprise IT. Windows / AD / M365
The Microsoft-shop spine. A durable, hireable lane and a direct on-ramp to security, cloud and IAM.
- Network Engineer
Underrated, stable, foundational to almost every other track.
- The realistic SOC analyst path
Most guides describe the job a SOC analyst wishes they had. Here's the one they actually do.
- When everyone passes, nobody differentiates
Exam dumps aren't mainly an ethics problem. They're a signal erosion problem. And that hurts honest candidates too.
- Why most people fail trying to leave helpdesk
It's almost never a skills problem. It's a positioning problem, a portfolio problem, and a willingness-to-be-uncomfortable problem, in that order.
The next step
The pathway is plausible. Whether it holds for five years is a different question.
A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.
A route shows what is possible. A Career Verdict makes the call.
Career Verdict
Helpdesk → Security Architect
- 01The callA clear judgement on whether your route is realistic, and under what conditions.
- 02Where the route breaksThe most likely point to stall, and why it happens in practice.
- 03What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Career Verdict
- The callA single written judgement on whether the route is realistic for you.
- Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
- Where you standThe strongest and weakest parts of your current position, named.
- Salary realityWhat this route actually pays, set against what you've been told it pays.
Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.
Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.