🛡️ SOC Analyst / Blue Team
Cybersecurity career path
Detect, triage and respond to threats in a security operations centre.
Typical roles
- SOC Analyst (L1–L3)
- Detection Engineer
- Threat Hunter
Suggested certifications, by phase
Foundation
- Net+ CompTIA Network+
- Security+ CompTIA Security+
- SC-900 Microsoft Certified: Security, Compliance, and Identity Fundamentals
Core
- CySA+ CompTIA Cybersecurity Analyst+
- BTL1 Centri Blue Team Level 1
- SC-200 Microsoft Certified: Security Operations Analyst Associate
- GSOC GIAC Security Operations Certified
Advanced
- GCIH GIAC Certified Incident Handler
- GCIA GIAC Certified Intrusion Analyst
- GCDA GIAC Certified Detection Analyst
- BTL2 Centri Blue Team Level 2
Mastery
- CCDL2 Threat Hunting & DFIR Certification (CCDL2, formerly Certified CyberDefender / CCD)
- GCTI GIAC Cyber Threat Intelligence
- GREM GIAC Reverse Engineering Malware
A suggestion, not a set of prerequisites — one or two certifications per phase is plenty.