SOC HR and training

March 5, 2026 ยท View on GitHub

This page deals with SOC HR and training topics.

ToC

Must read

MITRE reference

HR roles and organization

As per what is explained on the management page, I would recommend to make sure the following roles are being assigned to people:

  • SOC analyst;
  • SOC analyst lead;
  • SOC detection engineer;
  • Threat intel analyst;
  • Threat intel lead (if several analysts)
  • SIEM expert and data scientist;
  • Pentester (offensive team);
  • Incident handler;
  • Incident manager;
  • SOC/CSIRT tools admin;
  • SecDevOps analyst;
  • SOC/CERT/CSIRT deputy manager.
  • SOC/CERT/CSIRT manager.

They can be FTE or outsourced, it will depend on your needs and constraints. My recommendations are explained in the RACI template that I propose.

NICE Framework

NIST 800-181 National Initiative for Cybersecurity Education Framework (NICE Framework) has done work to standardise job roles in the area. These roles have standardised descriptions with a list of Tasks that the role typically does, as well as Tasks, Knowledge and Abiltiy to undertake that role. It is mainly focused on US Government, and includes some roles which are typical for the defence or intelligence sector.

https://niccs.cisa.gov/workforce-development/nice-framework

These roles can be difficult to understand initially, but it is simple to map them through to your existing roles (for example, Cyber Defence Analyst = SOC Analyst, Cyber Defence Infrastructure Support = SOC Detection Engineer). Alternatively you can readily build custom job roles utilising the Tasks, Knowledge, Abilities, and Skills listed in the framework.

There is a reference spreadsheet that NIST released that can assist in building custom roles: https://www.nist.gov/document/supplementnicespecialtyareasandworkroleksasandtasksxlsx

Recommended SOC trainings

Regular trainings

Challenges

SIEM

Splunk

Microsoft (Defender XDR / Sentinel)

Certifications

Free certifications:

Not working anymore ATOW: EthicalHackersAcademy, SOC & SIEM Security program: L1, L2, L3.

Recommended CERT/CSIRT trainings

Must read/watch:

Regular trainings & challenges [Free]

Certifications

Free certifications:

Challenges

Recommended CTI trainings

Certifications

Recommended VOC (Vulnerability management) trainings

Certifications

Recommended offensive security trainings

NB: this is mainly for red/purpleteaming activities.

Must read/watch

Regular trainings [free]

Certifications

Free certifications

Recommended management trainings

To go further

End

Go to main page.