This is where the second pass actually plays out, the last gate before an interview hits your
inbox. The recruiter slows down right here, and even then your current role still drives
around 95% of the decision.
Makes sense: nothing tells a hiring team what you can run in production right now the way your
current job does. To clear that "yes", this section has to walk the full
SOC Analyst role profile, one bullet per slot you listed in Domain
Expertise above. Every bullet has to come off something you actually held in production,
not a Jira card that wandered past your queue.
1
Alert Triage & Tier-1/2 Response
You triage the flood of alerts and stop the real threats fast. Most alerts are noise and a few are real,
so hiring managers want proof you tell them apart quickly, not just close tickets. Talk about how you
used a tight triage workflow and containment actions, in Splunk ES and Sentinel, to hold MTTA and your
SLA hit rate.
Techniques
Triage workflow
Disposition discipline
Containment actions
Tier-3 escalation criteria
Tools
Splunk ES, Microsoft Sentinel
Elastic SIEM, Panther
ServiceNow SecOps, Jira
Metrics
Alerts closed per quarter
MTTA / MTTR
SLA hit rate
2
SIEM & Log Analysis
You turn raw logs into the signal that catches an intrusion. A missing log source is a blind spot, so
hiring managers want the coverage you built, in numbers. Show them how you used cross-source correlation
and statistical baselining, with SPL and KQL, to onboard data sources and cut query latency.
Techniques
Cross-source correlation
Dashboards & saved searches
Statistical baselining
Time-window analysis
Tools
Splunk SPL, Microsoft Sentinel KQL
Elastic Lucene / EQL
Sumo Logic, Panther
Metrics
Data sources onboarded
Dashboards maintained
Query latency cut
3
EDR & Endpoint Investigation
You chase a threat down to the exact process on the exact host. Hiring managers look here to see whether
you can isolate a compromised host in minutes, or let it spread while you dig. Point out how you used
process-tree analysis and host containment, in Crowdstrike Falcon with osquery, to cut time-to-isolate
and root out persistence.
Techniques
Process-tree analysis
Persistence triage
Host containment
Memory & disk artifact pull
Tools
Crowdstrike Falcon
SentinelOne, Defender for Endpoint
Sysmon, osquery, Velociraptor
Metrics
Hosts contained
Persistence found / removed
Time-to-isolate
4
Threat Hunting & Intelligence
You go looking for the intrusions no alert fired on. The attacker already inside is the one that hurts,
so hiring managers want hunts that surface what detection missed. Mention how you used hypothesis-driven
hunting and ATT&CK walks, with MISP and Yara, to surface latent intrusions and operationalize IOCs.
Techniques
Hypothesis-driven hunting
ATT&CK technique walks
IOC operationalization
Anomaly baselining
Tools
MITRE ATT&CK Navigator
MISP, OpenCTI, ThreatConnect
Yara, Sigma, KQL hunts
Metrics
Hunts run per quarter
Latent intrusions surfaced
IOCs operationalized
5
Incident Response & Escalation
You take a confirmed incident from first alert to clean closure. How a SOC handles a live incident sets
the whole outcome, so running one to closure tells a hiring manager they can rely on you. Walk them
through how you used IR playbooks and impact scoping, with PagerDuty and CloudTrail, to drive incidents
to closure and cut dwell time.
Techniques
IR playbook execution
Scoping & impact analysis
Bridge facilitation
Postmortem authoring
Tools
PagerDuty, FireHydrant
CloudTrail, GuardDuty
Volatility, KAPE, Velociraptor
Metrics
Incidents led to closure
MTTR
Dwell time cut
6
Phishing & Email Defense
You shut down phishing before someone clicks. Two things ride on it for a hiring manager: campaigns
neutralized fast, and users who stop clicking over time. Lay out how you used user-report triage and
attachment detonation, with Proofpoint and Any.Run, to neutralize campaigns and drive click-rate down.
Techniques
User-report triage
URL & attachment detonation
Credential-replay detection
Phishing simulation
Tools
Proofpoint, Abnormal, Mimecast
KnowBe4, Hoxhunt
URLscan, Any.Run, Joe Sandbox
Metrics
Reported messages triaged
Campaigns neutralized
User click-rate down
7
Detection Tuning & SOAR Automation
You cut the false positives that bury the real alerts. An alert queue full of noise is worse than none,
so hiring managers read tuning as a SOC that can actually respond. Spell out how you used Sigma rules
and SOAR auto-enrichment, with Tines and Splunk SOAR, to cut the false-positive rate and auto-triage
inbound.
Techniques
Sigma rule authoring
FP root-cause analysis
SOAR auto-enrichment
Alert backlog burn-down
Tools
Sigma, Splunk SPL, KQL
Tines, Torq, Splunk SOAR
Python, GitHub Actions
Metrics
False-positive rate cut
Auto-triaged % of inbound
Tier-1 toil reclaimed
8
Tooling & Workflow
You capture repeat investigations as runbooks the whole team reuses. SOCs keep the analysts who scale
the team's knowledge, not the ones who hoard it in their heads, so this stands out. Tell them how
you built shared runbooks and detection-as-code, in Git with Python, to speed tier-1 ramp and reclaim
analyst toil.
Techniques
Secure-by-default templates
Internal CLI / runbooks
Inner sourcing
Self-serve docs
Tools
Git, GitHub
Bash, Python, Go
Backstage TechDocs
Metrics
Templates maintained
PR cycle time
Secure-onboarding ramp cut