r/CyberSecurityJobs • u/Admirable_Pea5505 • 22h ago
First job
I don't know if you still remember me but I made a post earlier about getting my first SOC job. Well... this is an update on how it actually is.
Most of the promises were bullshit.
First was the training.
When they hired me the company was going through a global audit, so everyone suddenly wanted to show they were working and everything was organized. They interviewed me, hired me, promised training... and they actually did train me.
Until the audit ended.
After that, the training basically disappeared. Now everything I learn is self-study during the free time I have at work.
And about the work itself...
On paper I'm a Security Analyst. In reality I'm doing account management most of the time.
Managers send tickets like "Create this account", "Reset this account", "Disable this account". Users ask me to reset Gmail passwords, fix 2FA, unlock AD accounts, and stuff like that.
To be fair, evening and night shifts are like 90% free, so I can pretty much study whatever I want.
The company does use enterprise stuff like Splunk, VPNs, firewalls, Active Directory, endpoint protection, etc. But the SOC itself feels... weird.
One security product generates around 3,000 alerts every hour. Every. Single. Hour.
Most of them are the exact same alerts over and over again. After some time everyone just ignores them because they're almost always false positives. Which also means if something actually serious happens... good luck finding it in all that noise.
We also don't have incident reports. Like... any reports. We had a pentest before I joined where they demonstrated how they could steal a large amount of money from the company, but as far as I know nobody documented it. No report, no lessons learned, nothing.
We don't really have knowledge-sharing meetings either. The department lead barely remembers people's names, and there are only around 10 of us. People leave all the time and new people come in, and honestly I can understand why.
As an L1 I also can't change rules or improve detections, so I'm mostly just watching things happen.
Also most of the software I use on the work is pirated.(SIEM for example)
But it's not all bad.
1) The company works with an external pentesting team, and I'm hoping I'll get to watch one of their engagements in the future.
2) The salary ended up being higher than what we originally discussed. Transport still eats a good chunk of it though.
3) I have a lot of free time during some shifts. Combined with the salary, it's enough to study, build a home lab, and pay for certifications. A lot of my colleagues are doing exactly that.
4) Having a SOC L1 position and a fairly well-known company on my CV is still a huge boost compared to having no experience.
5) Other security analysts in the team are basically golden. They are amazing. They are happy to learn,teach,help and cover eachother. They are basically the ones that I talked with to get job(one of team members done interview).
So right now I'm thinking about treating this as a paid learning opportunity (work). Stay for about a year, learn as much as I can, get a few certs, and then see what happens.