◆ Cybersecurity

What a soc analyst
really does.

20 tasks, each one witnessed by the sources that watched the job — and behind every one, a prompt you can use tonight.

20evidenced tasks
190,650in the US (2025)
$129,180median pay / year
9systems it runs on
This is what one task looks like here
Implement security measures to protect data
Deploy host hardening, file integrity monitoring, and role-based acces…3 sources agree

The shape of the day

tap a movement to see its tasks

Which one is you, right now?

Pick the moment · no score, no sign-up
Which moment is me right now?
Whichever you pick, the task behind it opens below.

The work, task by task

20 tasks
Hands on the work12
Implement security measures to protect data+
Deploy host hardening, file integrity monitoring, and role-based access for the analytics cluster that holds client financial feeds, document the implemented controls and rollout schedule for sign-off by the SOC manager by Monday.
jdonetwiki3 agree
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Design and implement security policies+
Draft enforceable security policies for remote access, third-party data handling, and privileged accounts tied to our risk register, circulate to legal and the head of trading for comments, and finalize by next Friday.
jdwiki2 agree
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Ensure compliance with relevant laws and standards+
Review the current services and data flows, map applicable national and sectoral laws plus ISO standards to each processing activity, flag gaps with citations, and produce a one-page remediation plan and deadline for the compliance lead by Friday.
jdwiki2 agree
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Analyse financial risk+
Run a financial risk analysis on the quarterly trading book: pull positions and prices from the last 90 days, compute VaR and stress scenarios by sector, flag exposures above 5% of NAV, and produce a one-page briefing for the risk committee by Thursday.
esco
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Stock market+
Produce a concise market note on the top five equities by volume: gather price, volume and news for the last 30 days, calculate momentum and relative strength, highlight drivers and tradeable signals, and deliver a one-page memo to the desk before market open Monday.
esco
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Coordinate implementation of computer system plan with establishment personnel and outside vendors.+
Coordinate the system upgrade plan with the facility manager, the vendor lead at SecureNet, and our network team so rollout windows, resource owners, and rollback steps are agreed, then circulate the signed timeline and contact list by Wednesday morning.
onet
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Manage vulnerabilities and system hardening+
Run a review of current host configurations, list the top five exploitable weaknesses and proposed hardening steps with estimated downtime, then hand the remediation plan to the server team and security engineer for scheduling next week.
jd
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Help users install and learn security products+
Prepare a short how-to and troubleshooting sheet for the desktop security suite, schedule two one-hour training sessions for traders and support on Thursday and Friday, and collect three common user issues to update the FAQ.
jd
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Grow the practice4
Watch and assess2
Work with people1
Keep the record1

What the work runs on

named inside the evidenced tasks
5 tasksApache Hadoopstores and indexes large risk-register datasets and historical incidents to inform policy drafting
5 tasksApache Hivequery and analyse large, structured datasets of processing activities to locate where regulated data is handled
4 tasksApache Kafkastreams telemetry from sensors to detection engines and supports real-time alerting and tuning
3 tasksAnsibleautomates consistent hardening and agent deployment across the cluster
2 tasksAmazon Redshiftaggregates scan results and telemetry for analysis and reporting across the pipeline
1 taskAmazon Elastic Compute Cloud EC2provisions and configures compute instances where hardening and monitoring agents are installed
1 taskAJAXbuilds interactive, responsive training pages and troubleshooting tools for end-user guidance
1 taskApache Cassandrastores and shares the collaboration action items and meeting history across teams for fast access and updates

The same task, four heights

this page is height one
ExecuteDo today's task, with fewer mistakesyou are here → ImproveMake it easy for the next person to acceptin the atlas → DecideWork out the right move when it is unclearin the atlas → BecomeLearn the pattern so it stops coming backin the atlas →

Can AI actually do this job?

the honest answer

It can

where it genuinely helps
  • Explain the theory behind the work
  • Draft, tidy and structure your writing
  • Rehearse a hard conversation before you have it
  • Build a study plan that fits your gaps

It cannot

where it stops, completely
  • Be in the room where a soc analyst actually works
  • Carry the responsibility when the call is wrong — that weight stays yours
  • Notice what no one wrote down: the hesitation, the thing left unsaid
  • Live with the outcome

What the work pays

two countries, two different measures

United States

this exact occupation · BLS 2025
  • $129,180 a year — the middle: half earn more, half earn less
  • The lowest tenth earn near $75,090; the top tenth near $199,850
  • 190,650 people employed in this occupation

Where the evidence lives

open any of it yourself

Close to this work

4 nearby
CybersecurityCybersecurity Analyst20 evidenced tasks CybersecurityPenetration Tester20 evidenced tasks CybersecuritySecurity Engineer20 evidenced tasks CybersecurityDigital Forensics Analyst20 evidenced tasks

Questions people actually ask

You’ll split time between monitoring alerts, investigating incidents, and fixing problems. Mornings often start with reviewing overnight security logs from AWS services and EC2 instances, and checking dashboards for anomalies.

Afternoons go to hands-on tasks: running scans, updating signatures, coordinating with vendors, and documenting incidents. Expect meetings with network or dev teams about Apache Kafka, Hadoop, or Redshift data flows and patch schedules.

You’ll see Amazon Web Services (AWS) and EC2 daily for cloud hosts, plus data platforms like Amazon Redshift, Apache Hadoop, Hive, Kafka, and Cassandra when investigating data flows. Use Ansible for automation and system hardening.

Also monitor AJAX-driven web apps for malicious traffic, and track virus reports to update endpoint protection. Familiarity with logs from these exact systems speeds up investigations.

Use AI to summarise logs, suggest triage steps, or write repeatable queries — but never let it decide isolation or deletion. Treat AI outputs like a junior analyst: verify with raw logs from EC2, Kafka, or Hadoop before acting.

Avoid pasting sensitive data (passwords, PII, full logs) into third-party AI. Keep incident response playbooks and Ansible scripts under version control and human review.

The U.S. Bureau of Labor Statistics (BLS) reports 190,650 employed in related roles and a median annual wage of $129,180. The lowest tenth earn about $75,090 and the top tenth about $199,850, per BLS 2025 data.

Use those numbers as a market snapshot. Actual offers vary by company size, cloud complexity (lots of AWS/Redshift/Hadoop work usually pays more), and location.

Begin with Linux, networking, and basic cloud skills: set up an AWS Free Tier account and launch an EC2 instance, explore S3, and try simple Redshift queries. Follow with log analysis — collect syslogs and inspect them.

Learn Ansible for automation and practice with small Hadoop or Kafka clusters (local or cloud). Study security fundamentals: incident response, vulnerability management, and common attack patterns.

A SOC analyst focuses on detection and response: monitoring networks, investigating alerts, running incident response plans, and updating protections. You’ll use systems like AWS EC2, Kafka, and Redshift to find and contain issues.

A cybersecurity engineer builds and hardens systems (Ansible playbooks, system hardening, designing security policies). A security architect plans the overall security strategy and compliance. Roles overlap, but SOC is operational and reactive.

Log reading and pattern recognition: you must quickly interpret logs from EC2, Kafka, Hadoop, Redshift, and application layers to find anomalies. That skill turns noisy alerts into real incidents.

Combine that with clear communication: you’ll explain findings to developers, vendors, and business teams and coordinate incident response and policy changes.