Menu
INTERVIEW

What a SOC analyst actually does all day

Two analysts walk through a real shift: the alerts they ignore, the ones they chase, and how much of the job is writing.

Ashwood Education · 9 min read · Sept 2026

Every week someone asks what the job is really like once the training ends. So we asked two graduates working in security operations to describe a shift, hour by hour, with nothing tidied up.

The first hour is triage, not hacking

A shift opens with the queue that built up overnight. Most alerts are noise: a failed login from a director who is travelling, a scanner someone forgot to whitelist, a certificate that expired at midnight. The skill is deciding quickly which of the hundred can be closed and which two deserve an hour.

  • Failed logins, clustered by user and location
  • Endpoint alerts where the file hash is already known
  • Anything touching a system that holds customer data

The middle of the day is writing

Nobody warns you how much of the job is writing. A good ticket explains what happened, what you checked, what you ruled out and what you recommend, in language a manager can act on. The analysts who get promoted are the ones whose tickets need no follow-up questions.

If I cannot explain the alert in three sentences, I do not understand it yet.

What the first six months feel like

Slow, then suddenly not. For the first month you check everything twice. By month three you recognise patterns and start noticing what is missing rather than what is there. That is the point the job becomes interesting.

Want to work at Ashwood?

We hire practitioners to teach and mentor each cohort.

See open roles