Skip to main content

Executive Summary

Junior SOC pathwayWazuh SIEM foundationSelf-paced learningRegular one-on-one feedback

Source-based starting point

Nkateko's submitted career assessment identifies strong interest in SIEM platforms, a preference for self-paced learning, willingness to invest substantial weekly time in learning, interest in Cisco, GitHub, Google and professional skills, and a desire to move into employment, increase earning potential and ultimately reach a leadership position.

The supplied professional profile describes an aspiring Junior SOC Analyst already building a Wazuh SIEM home lab, with practical focus on threat detection, log analysis and incident response. Existing profile strengths include cloud security, security monitoring, Windows fundamentals, networking and several foundation cybersecurity/networking credentials.

Primary pathway: Junior SOC Analyst → SOC Analyst / Security Operations Analyst
Secondary growth pathway: Detection Engineering / Cloud Security Analyst
Long-term direction: Security operations leadership, subject-matter expertise and mentoring

The secondary and long-term pathways are recommendations derived from the submitted interests, portfolio direction and stated leadership ambition; they are not claims of current role seniority.

Development priorities

  1. Windows security telemetry and event-log investigation.
  2. Wazuh administration, alert triage, rule tuning and detection logic.
  3. Networking and packet-analysis fundamentals for SOC investigations.
  4. Incident response, evidence handling and escalation discipline.
  5. MITRE ATT&CK mapping, threat intelligence and detection engineering basics.
  6. Git/GitHub workflow and evidence-quality portfolio development.
  7. Cloud-security fundamentals with a vendor-neutral control mindset.
  8. Professional communication, concise incident writing and regular mentor feedback.
  9. Time-management habits that balance work and sustained learning.
  10. Interview readiness and visible evidence for junior SOC opportunities.

12-month North Star

By the end of the roadmap, Nkateko should be able to investigate common Windows and network security events, operate and tune a SIEM, document incident decisions, create and test basic detection logic, explain common attacker techniques, demonstrate cloud-security fundamentals, collaborate through GitHub and present a credible evidence portfolio for junior SOC and security-operations roles.

Evidence standard

A course or certificate records learning; it does not independently prove operational capability. Progress is demonstrated through investigations, lab notes, detection rules, runbooks, GitHub repositories, mentor review and the ability to explain decisions under questioning.

Privacy boundary: the public IDR intentionally excludes private contact details and the raw assessment response. Portfolio evidence must use synthetic or expressly authorised information.