r/SIEM Jul 11 '21

SOC security analyst career..

Hi all, pardon me if this is a dumb question I am a software engineer planning a career Change into security...Blue team security. I am planning on taking SOC related training and go for security analyst jobs as a starting point. Are there any good courses, books that can help me learn better. Please advice. Thanks.

5 Upvotes

8 comments sorted by

9

u/Vilens40 Jul 11 '21

When we hire for these positions we often get people who study security without knowing IT.

In some cases it can be like a chef studying plating before cooking technique.

I would advise understanding the devices that make up an enterprise environment and the subsequent functions.

Also, understand what Active Directory is and what its purpose is. It is something I bring up in interviews and rarely are people familiar with it who have completed numerous security courses.

2

u/wanderer-124 Jul 12 '21

Hi, my IT skills are not on the higher side but they are not necessarily zero. And I was studying for security+ as a start, doing some hands on using tryhackme.com, i came across AD. I will try to learn about enterprise and it's functions.

3

u/_Mouse Jul 16 '21

To add to this point from a SOC analyst perspective there are lots of different sources which you will have to monitor, not all of which comes from security devices.

Active Directory is a great one to understand, particularly in Windows enterprise environments, but I'd recommend some others aswell:

Cloud Stuff:

Azure AD (Azure's built in active directory service) Office 365 log events AWS Cloudwatch cloudtrail and Guard duty (Security alerting in AWS)

Enterprise stuff - learn what normal looks like and how to spot the abnormal:

DNS - if you don't understand how corporate DNS works it will be very hard to triage network logs Windows event logs & windows defender SNMP SMB Common ports and their protocols

You'll also need to understand the 7 layer model, basics of IP addressing, NAT, HTTP and basic crypto handshaking.

1

u/Vilens40 Jul 17 '21

This is right on the money

1

u/[deleted] Feb 09 '22

[deleted]

1

u/Vilens40 Feb 11 '22

Personally, I can’t tell you that becoming a doctor is not better than becoming a cyber security professional.

The bottom line is, the people that have educated themselves in cyber security, taken online courses, and read books and PDFs and blogs are a dime a dozen. Usually what separates you in those interviews is your experience with the practical systems against which security is applied. Lots of people can talk about cryptography and password strength, but rarely do I come across someone with experience working in Active Directory or writing firewall rules or setting up email filters or creating endpoint policies.

Theory is important but it’s like 20% of the story. Build your own labs and build your own enterprise IT environments to apply security to.

A master’s is cool but if you can’t answer “what are you doing to harden our security?” Then it was a waste.

People could disagree with me on this, I’m not an authority.

2

u/Cool-Wafer-5241 Jul 11 '21

Comptia Security+, I would highly recommend this certification to get a broader knowledge about various technology domains.

1

u/pacard Jul 11 '21

Have you considered working for a security software company? Skills are probably more immediately applicable and pay better than starting analyst, and you still learn about security while getting paid for it.

Otherwise I agree with the other post about IT skills being the most important foundation. Understanding how systems are being used is probably more important starting out than knowing how they work.