Free Plan

SOC Analyst Onboarding Plan

Onboarding built for how the role works now, not for 2022.

The historic path put a new analyst on the queue for a year before anything resembling investigation. That path is obsolete: AI now absorbs the repetitive enrichment that used to fill it, so the judgment calls that once surfaced only at senior level arrive in month one. This plan front-loads them.

What changed, and why the old plan fails

Ramp curves have compressed. Analysts entering the role now reach senior capability materially faster than the historic two-to-four-year curve, when their time goes on investigative reasoning rather than repetitive enrichment. The first six months should look different from three years ago: less queue, more investigation, earlier.

That is not a productivity claim, it is a design constraint on onboarding. If AI clears the enrichment, the new analyst stops accumulating the incidental pattern exposure that used to come free with queue time. The exposure has to be deliberately scheduled instead, or they arrive at their first ambiguous escalation with no reference points.

WorkWho does it nowWhat onboarding must therefore teach
Enrichment, lookups, correlation of known entitiesIncreasingly automatedHow to audit the machine's output, not how to reproduce it
Deciding whether an alert matters hereThe analystOrganizational context: what is normal in this estate
Escalation under ambiguityThe analystDeciding with incomplete evidence, and saying what is missing
Talking to the business about impactThe analystWriting for a reader who is not in the SOC
The trap: onboarding that still teaches manual enrichment as a core skill trains for the part of the job that is being automated, and skips the parts that are not. Teach enrichment as something to verify, in an afternoon, and spend the recovered weeks on judgment.

The 90-day plan

Twelve weeks, four gates, one artifact per week. Copy the table. The artifact column is the point: it is the only evidence the week happened, and it doubles as competence evidence later.

WkFocusArtifact producedReady when
1Raw records, no console. Sign-in events, process creation, mail headers.One page per record type: field meanings, and the three fields that decide the outcome.Names the deciding fields unaided.
2This estate. What logs where, retention, known blind spots.Data map: source, table, retention, what it cannot tell you.Answers "which source would prove this" for three questions.
3Query language against live data.Five queries they wrote, each answering a stated question.Queries run unedited and return the intended rows.
4Gate 1. Consolidate, no new material.Walks their week 1 to 3 artifacts.Reads an unfamiliar raw record and states what it proves.
5Audit the automation. Take enriched alerts and check the enrichment.Three cases where the automated context was incomplete or wrong.Finds one without prompting.
6Triage historical closed alerts against a scorecard.Ten scored alerts with written rationale.Agrees with the original outcome on 8 of 10, and defends both disagreements.
7Live low-severity queue. Mentor reviews the write-up, not the decision.Their closed queue with rationale.No write-up reworked for missing evidence.
8Gate 2. Consolidate.Triage log with the two hardest calls annotated.Closes low-severity unsupervised for one shift.
9One incident, alert to scoped picture.Timeline, every entry sourced.No unsourced entries.
10Same incident: containment options, written finding, and a business-readable summary.The finding, plus five sentences a non-SOC reader can act on.States at least one thing the evidence does not support.
11Review an AI-drafted detection rule. Find the evasion gap.Peer review comments on a generated rule.Identifies a logic or scope weakness, and explains why.
12Gate 3. Tune and deploy that rule. Hand over.Tuning note: what changed and why.Explains why it fires, not that it does.
Why week 11 reviews a rule instead of writing one

Current practice is explicit about where the durable skill sits: the detection engineers most exposed to automation are the ones whose value was writing rules from scratch. The ones who remain valuable can take a generated rule, spot the evasion gap or the performance problem, and explain it in a peer review.

So week 11 hands the new analyst a plausible AI-drafted rule with a real weakness in it: a condition that a trivial command-line variation evades, or a threshold copied from a template that does not match your volume. Their artifact is the review, not the rule. Authoring comes next, and it comes easier once they have read a bad one closely.

Gate criteria, and the one that is not in week 12

Each gate has a single pass criterion above. Use the same four questions at every one, in this order, because the second exposes the answer to the first.

AskA weak answer sounds like
Walk me through how you reached that.Describes what the tool showed rather than what they concluded.
What would have changed your mind?Cannot name anything. They pattern-matched, or the automation did.
What could you not establish?Nothing offered. Everything is presented as settled.
Who needs to know, and in what words?Technical detail with no consequence stated.
Gate 4 is at week 20

Unannounced. Hand them an alert type they have never seen and read the write-up cold. Onboarding assessed only while a mentor watches measures supervised performance, and supervised performance is not what a 3am shift tests.

What to measure

Time in seat has become a poor proxy for capability now that ramp curves vary this widely. Demonstrated judgment is the better one, and it is observable inside a shift.

Track thisNot this
Time to a defensible classification on an unfamiliar alertAlerts closed per hour
Proportion of write-ups needing reworkCourses completed
Tickets a senior reopened after closureHours logged
Whether they state what they could not establishQuiz scores
Cases where they caught bad automated enrichmentMonths since start date

Defining the role before you onboard into it

If the role is not defined, the plan has nothing to aim at. The NICE Workforce Framework for Cybersecurity is the usual reference: it publishes Work Roles with Task, Knowledge and Skill statements, and Competency Areas grouping them, available as data you can lift rather than reinvent.

Take the Work Role closest to the seat you are filling, pull its TKS statements, and mark each one as covered by a week in the plan above, covered by existing experience, or not covered. The not-covered list is your onboarding gap, and it is also the honest answer when someone asks what this person is trained for.

Why bother: the same mapping answers an audit question later. ISO 27001:2022 clause 7.2 requires you to determine the competence necessary and retain evidence of it, and a role-to-TKS mapping with per-week artifacts is that evidence without a separate exercise. See evidencing team competence.

The content behind weeks 1, 3, 6, 9 and 11

The SOC and Detection Engineer path runs this order across six courses: reading evidence, query fluency, triage, investigation end to end, then detection authoring and tuning. Hands-on against a realistic enterprise dataset, with a scenario-based exam and verifiable credential on each, so gate evidence accumulates on its own. Business seats are $324 per seat per year, any number of seats, one invoice.

See Business pricing

Weekly security engineering insights

Detection techniques, architecture patterns, and operational judgment, every Tuesday.

No spam. Unsubscribe anytime.