Sourcing by role
How to find a SOC analyst.
Tier 1 triage and Tier 3 threat hunting are different jobs advertised under one title. Naming the tier is the single most useful thing you can do.
Security operations has the highest turnover in the security field, and the cause is structural rather than mysterious. SOCs run around the clock, rotating night shifts take a real toll, and Tier 1 work often means triaging large volumes of alerts that turn out to be false positives.
That shapes both sourcing and retention. Concealing the shift pattern in an advert produces hires who leave within months. Naming a progression path into detection engineering or threat hunting — day-shift work using the same knowledge — is what actually keeps good analysts, and it is also the pitch that wins them from competitors.
Job titles worth searching
Grouped by what the person actually does, because searching all44 at once produces a result set you cannot triage. Decide which group you need first — that decision does more for the search than any string below.
Core SOC titles
Generic and hiding the most important variable: the tier. A Tier 1 analyst triages alerts against a runbook; a Tier 3 analyst hunts threats and builds detections. Both are advertised as 'SOC Analyst' and they are not the same job.
- SOC Analyst
- Security Operations Analyst
- Security Analyst
- Cyber Defence Analyst
- Cyber Security Analyst
- Monitoring Analyst
- Security Monitoring Specialist
Tier structure
The distinction that decides fit and pay. Tier 1 is high-volume triage on a rota, often the entry point into security. Tier 2 investigates escalations. Tier 3 hunts proactively and handles the hardest incidents. Naming the tier in an advert is the single most useful thing you can do.
- Tier 1 SOC Analyst
- Tier 2 SOC Analyst
- Tier 3 SOC Analyst
- Junior SOC Analyst
- Senior SOC Analyst
- Lead SOC Analyst
- SOC Shift Lead
Incident response and forensics
Where escalated incidents go. DFIR work requires evidence handling discipline and deeper technical knowledge than alert triage, and practitioners often come from SOC backgrounds but are a distinct and better-paid population.
- Incident Responder
- Incident Response Analyst
- DFIR Analyst
- Digital Forensics Analyst
- Malware Analyst
- CSIRT Analyst
- Cyber Incident Manager
- Breach Response Consultant
Detection engineering and hunting
The escape path from shift work, and increasingly the retention argument that keeps good analysts. Detection engineers write the rules rather than responding to them, which means normal working hours and demonstrable output.
- Detection Engineer
- Threat Hunter
- Threat Detection Engineer
- Security Content Developer
- SIEM Engineer
- Use Case Developer
- Purple Team Analyst
- Security Automation Engineer
Threat intelligence
Analysis rather than operations. Threat intelligence analysts track adversary behaviour and produce assessments, which suits people with research and writing strengths more than real-time response temperament.
- Threat Intelligence Analyst
- CTI Analyst
- Cyber Threat Analyst
- Intelligence Researcher
- OSINT Analyst
- Threat Research Engineer
- Adversary Tracking Analyst
Platform and tooling
Where SOC work becomes engineering. SIEM and SOAR platform experience is genuinely valuable and platform-specific — Splunk, Sentinel, and Chronicle experience transfer imperfectly, and organisations with heavy investment want the match.
- SIEM Analyst
- Splunk Engineer
- Sentinel Engineer
- SOAR Engineer
- Security Engineer (SOC)
- EDR Specialist
- Security Platform Engineer
Certifications and what each indicates
Blue team certifications range from foundational multiple-choice through to lab-based practical examinations. The practical ones and the platform-specific ones are what predict productivity.
| Credential | Full name | Region | What it tells you |
|---|---|---|---|
| GCIH | GIAC Certified Incident Handler | International | The most relevant SANS credential for SOC and incident response work. Expensive enough that holders usually had employer sponsorship, which itself signals investment. |
| GCIA / GCFA | GIAC Intrusion Analyst / Forensic Analyst | International | Detection analysis and forensics respectively. GCFA is the stronger signal for DFIR-focused roles. |
| BTL1 / BTL2 | Blue Team Level 1 and 2 | International | Practical, hands-on blue team certifications with lab-based examinations. Increasingly respected and far more affordable than SANS, which makes them common among self-funded candidates. |
| CySA+ | CompTIA Cybersecurity Analyst | International | Entry to intermediate, and meets some US government baseline requirements. Indicates foundational knowledge rather than operational capability. |
| Security+ | CompTIA Security+ | International | The common entry credential and a DoD 8570 baseline. Very widely held, so it filters almost nothing beyond the absolute entry level. |
| Splunk / Sentinel | Vendor platform certifications | International | Platform-specific and genuinely useful where the organisation runs that SIEM, since query language fluency reduces ramp time substantially. |
| Clearance | Security clearance | Varies | Required for government and defence SOCs. Already-cleared analysts are heavily recruited and command a premium given sponsorship cost and delay. |
| CISSP | Certified Information Systems Security Professional | International | Requires five years of experience and is managerial in emphasis. Frequently listed on SOC adverts where it is inappropriate — a junior analyst cannot hold it. |
Where SOC analysts actually are
Published detection content is the clearest capability signal in defensive security. A GitHub repository of Sigma rules, YARA signatures, or KQL hunting queries demonstrates blue team depth that no certification list conveys, and it is public, dated, and attributable.
Practical training platforms have become the main proving ground for this discipline. LetsDefend, CyberDefenders, and Blue Team Labs publish completion and ranking data, which identifies analysts practising on their own time — a strong motivation signal, particularly for early-career candidates whose CVs are otherwise hard to distinguish.
Managed security service providers are the most under-searched pool. Their analysts see far more incident variety across many client environments than in-house teams typically encounter, and many want to move in-house for depth rather than breadth. For conferences, Blue Team Con and the SANS summits attract defenders specifically, while BSides events run locally in most cities.
Boolean search strings
Written to be pasted as-is. Each one is built around an intent rather than a platform, since the useful question is what you are trying to find, not which site you happen to be on.
LinkedIn profiles, direct X-ray
Google (LinkedIn)site:linkedin.com/in/ ("SOC analyst" OR "security operations" OR "incident response") (GCIH OR Splunk OR Sentinel OR BTL1) "{city}"Works reasonably well, since SOC analysts list certifications and SIEM platforms in headlines and many are early-career and building visibility deliberately. LinkedIn no longer indexes titles and locations, so the certification and platform terms carry the search.
Detection engineers with public rules
Googlesite:github.com ("sigma" OR "detection-rules" OR "YARA" OR "KQL" OR "SPL") ("detection" OR "hunting") -awesome -tutorialPublished detection content is the strongest blue team signal available. Someone contributing Sigma rules or KQL hunting queries has demonstrable capability that no certification list conveys.
Analysts ready to leave shift work
Google("SOC analyst" OR "security operations") ("shift work" OR "night shift" OR "burnout" OR "leaving SOC" OR "day role") -jobsShift rotation is the largest cause of turnover in security operations. A detection engineering or day-shift role pitched on schedule converts unusually well against SOC competitors.
SIEM platform specialists
Google("Splunk" OR "Microsoft Sentinel" OR "Chronicle" OR "QRadar" OR "Elastic Security") ("SPL" OR "KQL" OR "use case" OR "content development") -jobs -vendorQuery language fluency is what makes a SOC analyst productive quickly, and it is platform-specific. Naming the platform your client runs finds people who need no ramp time.
Blue team community and CTF participants
Google("BTL1" OR "Blue Team Labs" OR "LetsDefend" OR "CyberDefenders" OR "blue team CTF") ("completed" OR "ranked") -jobsPractical blue team platforms publish completion and ranking data. Analysts practising on their own time are demonstrably motivated, and this is a strong early-career filter.
Managed service provider analysts
Google("MSSP" OR "managed security" OR "managed detection") ("SOC analyst" OR "security analyst") "{city}" -jobs -salesMSSP analysts see far more incident variety across many client environments than in-house analysts do, and many want to move in-house for depth over breadth. A strong and under-searched pool.
Conference speakers on defensive security
Google("speaker" OR "talk") ("BSides" OR "SANS Summit" OR "FIRST" OR "Blue Team Con") 2024..2026 -jobsBlue Team Con and SANS summits attract defensive practitioners specifically, and BSides events run locally in most cities, which makes regional speaker lists genuinely useful.
Analysts writing incident writeups
Google("threat hunt" OR "incident writeup" OR "detection engineering") ("how we" OR "lessons" OR "we detected") -jobs -vendorAnalysts who write up hunts or incidents reveal investigative reasoning directly. Excluding 'vendor' is essential, since security content marketing dominates these phrases.
Mistakes that cost the most time
Not naming the tier in the advert
Tier 1 triage against a runbook and Tier 3 threat hunting are different jobs requiring different people and paying differently. Advertising both as 'SOC Analyst' produces a shortlist mixing candidates who cannot do the work with candidates who will find it beneath them. Naming the tier is the single most useful improvement available.
Concealing the shift pattern
Security operations centres run around the clock, and shift rotation is the largest cause of turnover in the field. Candidates who discover a rotating night schedule after accepting leave quickly, and word travels in a well-connected community. State the rotation plainly — some candidates actively prefer nights for the premium and the quiet.
Requiring CISSP on junior roles
CISSP requires five years of documented experience, so asking for it on an entry-level SOC role is impossible by definition. This is a well-known irritant in the security community and marks the advert as written by someone outside the field, which suppresses applications well beyond the specific role.
Ignoring detection engineering as a retention path
The main reason good analysts leave security operations is that shift work has no obvious end. Detection engineering, threat hunting, and automation offer day-shift progression that uses the same knowledge. Employers who make that path explicit retain analysts who would otherwise leave for any role with regular hours.
Overlooking MSSP analysts
Analysts at managed security service providers see far more incident variety across many client environments than in-house analysts typically do, and many want to move in-house for depth rather than breadth. It is a large, experienced, and consistently under-searched population.
Screening on certification count
Certifications in this field vary enormously in rigour, and stacking acronyms says little. Published detection content, hunt writeups, and practical platform completions demonstrate capability that a certification list does not. For blue team roles specifically, a GitHub repository of Sigma rules outweighs almost any credential.
Common questions
- What job titles should I search for when hiring a SOC analyst?
- Search the tier and the specialisation rather than the generic title. Tier 1, Tier 2, and Tier 3 SOC Analyst describe genuinely different jobs. For escalated work, Incident Responder, DFIR Analyst, and CSIRT Analyst. For the engineering side, Detection Engineer, Threat Hunter, SIEM Engineer, and Security Content Developer. For analysis rather than operations, Threat Intelligence Analyst and CTI Analyst. Platform-specific titles such as Splunk Engineer or Sentinel Engineer matter where the organisation has heavy investment in one SIEM.
- What is the difference between Tier 1, Tier 2, and Tier 3 SOC analysts?
- Tier 1 analysts triage incoming alerts against documented runbooks, closing false positives and escalating what needs deeper investigation. This is high-volume, often shift-based, and a common entry point into security. Tier 2 analysts investigate those escalations, correlating across data sources and determining scope and impact. Tier 3 analysts handle the most complex incidents, hunt proactively for threats the tooling missed, and often build detections. The skill and pay differences are substantial, so naming the tier in an advert prevents a mixed and unusable shortlist.
- Why is turnover so high in security operations centres?
- Shift work, primarily. SOCs operate around the clock, and rotating night shifts take a genuine toll that no salary fully offsets. The secondary cause is alert fatigue — Tier 1 work can mean triaging large volumes of alerts, most of which are false positives, which becomes monotonous quickly. The retention answer that works is a visible progression path into detection engineering, threat hunting, or automation, all of which use the same knowledge during normal working hours. Employers who make that path explicit keep analysts who would otherwise leave.
- Which certifications matter for SOC and blue team roles?
- The GIAC family is the most respected, particularly GCIH for incident handling and GCIA for intrusion analysis, though the cost means holders usually had employer sponsorship. Blue Team Level 1 and 2 are practical, lab-based, and far more affordable, which makes them common among self-funded candidates and a good signal of motivation. CySA+ and Security+ indicate foundational knowledge. Vendor SIEM certifications are genuinely useful where the platform matches. CISSP requires five years of experience and is inappropriate on junior adverts.
- Where can I find SOC analysts outside LinkedIn?
- Published detection content is the strongest signal — GitHub repositories with Sigma rules, YARA signatures, or KQL hunting queries demonstrate real blue team capability. Practical training platforms such as LetsDefend, CyberDefenders, and Blue Team Labs publish completion and ranking data, which identifies analysts practising on their own time. Blue Team Con and SANS summits attract defensive practitioners specifically, and BSides events run locally in most cities. Managed security service providers are a large, experienced, and under-searched pool.
The method behind the strings
Sourcing, in full.
Full Stack Recruiter devotes its first seven chapters to search: Boolean fundamentals, search engines beyond Google, research sources, contact discovery, and responsible public-source research. The titles change by role; the method under them does not.