Skip to main content
RoleCybersecurity

SOC Analyst

Often searched as cyber security analyst.

Triaging alerts on rotation, writing tickets, chasing false positives.

In UK job ads, "cyber security analyst" usually maps to SOC analyst, junior security analyst, or a monitoring/detection seat. POST keeps SOC Analyst as the canonical role because it describes the actual work, shift-based alert triage on a SIEM, more precisely than the generic title recruiters reach for.

POST verdict

The easiest seat to land in cyber, and the hardest one to stay sane in past year two. Worth it if you'll move on deliberately.

Domain
Cybersecurity
Entry
£32–52k
Senior
£95–135k
Pick this if
  • You want into security and have nothing better than a Security+ on your CV
  • Shift work doesn't break you (and you've actually checked, not just assumed)
  • You're aiming at detection engineering, IR or threat hunting within two years
  • You can write a clear ticket under time pressure, that's half the job
Skip this if
  • You picture yourself doing offensive work and just see SOC as a step, the gap is wider than you think
  • You need a 9-to-5, most SOCs run 24/7 rotations and you'll feel it
  • You're allergic to repetitive triage, the first eighteen months are mostly that
  • You spot the false positives that everyone else tickets and closes blindly
  • You start writing detections, not just consuming them
  • Your tickets read like an analyst wrote them, not a script
  • You volunteer for purple-team exercises and IR shadowing when they come up
The bit you're probably underestimating

Two things wear people down here, and the bootcamps don't tell you about either. First, the queue is endless. Closing a hundred tickets a week feels productive for a month, then it feels like running on a treadmill. Second, the night shifts compound. By month eighteen your sleep is wrecked, you've stopped studying outside work, and the move to detection engineering you planned has quietly evaporated. Plan the exit before you sign the contract.

Hover any chip for the calibrated meaning. Ratings are directional, not absolute.

Moderate at T1; clear ladder via detection engineering or IR.

  • +IT support
  • +Network admin
  • +Self-taught + Security+
  • That it's a glamorous 'hacker' job, most days are queue work.
  • Detection Engineer
  • Incident Responder
  • Threat Hunter

Listed because the graph connects them to this role, not because you need all of them. Most practitioners pick one or two.

Practitioner assessment checked against published external evidence.

Last reviewed: September 2026 · UK market · Confidence: established

Where this fits

Roles connect to pathways, certs and other roles. Use one to test the next.

The next step

You've read about the role. The harder question is whether it's the right one for you.

A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.