SOC Analyst Onboarding Plan
Onboarding built for how the role works now, not for 2022.
The historic path put a new analyst on the queue for a year before anything resembling investigation. That path is obsolete: AI now absorbs the repetitive enrichment that used to fill it, so the judgment calls that once surfaced only at senior level arrive in month one. This plan front-loads them.
What changed, and why the old plan fails
Ramp curves have compressed. Analysts entering the role now reach senior capability materially faster than the historic two-to-four-year curve, when their time goes on investigative reasoning rather than repetitive enrichment. The first six months should look different from three years ago: less queue, more investigation, earlier.
That is not a productivity claim, it is a design constraint on onboarding. If AI clears the enrichment, the new analyst stops accumulating the incidental pattern exposure that used to come free with queue time. The exposure has to be deliberately scheduled instead, or they arrive at their first ambiguous escalation with no reference points.
| Work | Who does it now | What onboarding must therefore teach |
|---|---|---|
| Enrichment, lookups, correlation of known entities | Increasingly automated | How to audit the machine's output, not how to reproduce it |
| Deciding whether an alert matters here | The analyst | Organizational context: what is normal in this estate |
| Escalation under ambiguity | The analyst | Deciding with incomplete evidence, and saying what is missing |
| Talking to the business about impact | The analyst | Writing for a reader who is not in the SOC |
The 90-day plan
Twelve weeks, four gates, one artifact per week. Copy the table. The artifact column is the point: it is the only evidence the week happened, and it doubles as competence evidence later.
| Wk | Focus | Artifact produced | Ready when |
|---|---|---|---|
| 1 | Raw records, no console. Sign-in events, process creation, mail headers. | One page per record type: field meanings, and the three fields that decide the outcome. | Names the deciding fields unaided. |
| 2 | This estate. What logs where, retention, known blind spots. | Data map: source, table, retention, what it cannot tell you. | Answers "which source would prove this" for three questions. |
| 3 | Query language against live data. | Five queries they wrote, each answering a stated question. | Queries run unedited and return the intended rows. |
| 4 | Gate 1. Consolidate, no new material. | Walks their week 1 to 3 artifacts. | Reads an unfamiliar raw record and states what it proves. |
| 5 | Audit the automation. Take enriched alerts and check the enrichment. | Three cases where the automated context was incomplete or wrong. | Finds one without prompting. |
| 6 | Triage historical closed alerts against a scorecard. | Ten scored alerts with written rationale. | Agrees with the original outcome on 8 of 10, and defends both disagreements. |
| 7 | Live low-severity queue. Mentor reviews the write-up, not the decision. | Their closed queue with rationale. | No write-up reworked for missing evidence. |
| 8 | Gate 2. Consolidate. | Triage log with the two hardest calls annotated. | Closes low-severity unsupervised for one shift. |
| 9 | One incident, alert to scoped picture. | Timeline, every entry sourced. | No unsourced entries. |
| 10 | Same incident: containment options, written finding, and a business-readable summary. | The finding, plus five sentences a non-SOC reader can act on. | States at least one thing the evidence does not support. |
| 11 | Review an AI-drafted detection rule. Find the evasion gap. | Peer review comments on a generated rule. | Identifies a logic or scope weakness, and explains why. |
| 12 | Gate 3. Tune and deploy that rule. Hand over. | Tuning note: what changed and why. | Explains why it fires, not that it does. |
Current practice is explicit about where the durable skill sits: the detection engineers most exposed to automation are the ones whose value was writing rules from scratch. The ones who remain valuable can take a generated rule, spot the evasion gap or the performance problem, and explain it in a peer review.
So week 11 hands the new analyst a plausible AI-drafted rule with a real weakness in it: a condition that a trivial command-line variation evades, or a threshold copied from a template that does not match your volume. Their artifact is the review, not the rule. Authoring comes next, and it comes easier once they have read a bad one closely.
Gate criteria, and the one that is not in week 12
Each gate has a single pass criterion above. Use the same four questions at every one, in this order, because the second exposes the answer to the first.
| Ask | A weak answer sounds like |
|---|---|
| Walk me through how you reached that. | Describes what the tool showed rather than what they concluded. |
| What would have changed your mind? | Cannot name anything. They pattern-matched, or the automation did. |
| What could you not establish? | Nothing offered. Everything is presented as settled. |
| Who needs to know, and in what words? | Technical detail with no consequence stated. |
Unannounced. Hand them an alert type they have never seen and read the write-up cold. Onboarding assessed only while a mentor watches measures supervised performance, and supervised performance is not what a 3am shift tests.
What to measure
Time in seat has become a poor proxy for capability now that ramp curves vary this widely. Demonstrated judgment is the better one, and it is observable inside a shift.
| Track this | Not this |
|---|---|
| Time to a defensible classification on an unfamiliar alert | Alerts closed per hour |
| Proportion of write-ups needing rework | Courses completed |
| Tickets a senior reopened after closure | Hours logged |
| Whether they state what they could not establish | Quiz scores |
| Cases where they caught bad automated enrichment | Months since start date |
Defining the role before you onboard into it
If the role is not defined, the plan has nothing to aim at. The NICE Workforce Framework for Cybersecurity is the usual reference: it publishes Work Roles with Task, Knowledge and Skill statements, and Competency Areas grouping them, available as data you can lift rather than reinvent.
Take the Work Role closest to the seat you are filling, pull its TKS statements, and mark each one as covered by a week in the plan above, covered by existing experience, or not covered. The not-covered list is your onboarding gap, and it is also the honest answer when someone asks what this person is trained for.
The content behind weeks 1, 3, 6, 9 and 11
The SOC and Detection Engineer path runs this order across six courses: reading evidence, query fluency, triage, investigation end to end, then detection authoring and tuning. Hands-on against a realistic enterprise dataset, with a scenario-based exam and verifiable credential on each, so gate evidence accumulates on its own. Business seats are $324 per seat per year, any number of seats, one invoice.
See Business pricingWeekly security engineering insights
Detection techniques, architecture patterns, and operational judgment, every Tuesday.
No spam. Unsubscribe anytime.