Skip to main content
RoleCybersecurity

Security Operations Analyst

Triage in Sentinel, run playbooks, investigate XDR incidents. Tier-2 SOC for Microsoft estates.

POST verdict

The natural mid-tier seat between SOC analyst and detection engineer. Take it if you've earned it, don't take it as a sideways move from helpdesk.

Domain
Cybersecurity
Entry
£32–52k
Senior
£95–135k
Pick this if
  • You've done at least eighteen months of solid SOC work
  • You enjoy investigations more than triage
  • You can write a detection rule that survives a tuning cycle
  • You're comfortable being a senior voice on the floor
Skip this if
  • You're moving sideways from a tier-1 SOC just to get off shifts
  • You don't enjoy mentoring junior analysts
  • You want to stop responding to alerts, the seat still has some of that
  • Your investigations close cleanly with clear handoffs
  • Your tuning suggestions stick after detection review
  • You're trusted to brief leadership on incidents
  • You're the analyst other analysts ask before raising tickets
The bit you're probably underestimating

The role only earns its keep at orgs with a real detection engineering function above it. Without one, you'll be a glorified senior SOC analyst with extra meetings and no career runway. Diligence the team structure before you accept: is there detection engineering, threat hunting and IR as separate functions, or is this title the entire ladder above tier 1? If it's the latter, you've hit the ceiling on day one.

Hover any chip for the calibrated meaning. Ratings are directional, not absolute.

Senior SecOps / Defender Engineer; ceiling tracks your detection-engineering depth.

  • +SOC analyst
  • +Azure admin
  • +Junior SOC
  • That SecOps in Microsoft shops is purely tooling, content quality still decides outcomes.
  • Defender Engineer
  • Detection Engineer
  • Incident Responder

Listed because the graph connects them to this role, not because you need all of them. Most practitioners pick one or two.

  • Microsoft Sentinel

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

You've read about the role. The harder question is whether it's the right one for you.

A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.