Executive Summary
Source-based starting point
Nkateko's submitted career assessment identifies strong interest in SIEM platforms, a preference for self-paced learning, willingness to invest substantial weekly time in learning, interest in Cisco, GitHub, Google and professional skills, and a desire to move into employment, increase earning potential and ultimately reach a leadership position.
The supplied professional profile describes an aspiring Junior SOC Analyst already building a Wazuh SIEM home lab, with practical focus on threat detection, log analysis and incident response. Existing profile strengths include cloud security, security monitoring, Windows fundamentals, networking and several foundation cybersecurity/networking credentials.
Recommended development placement
Primary pathway: Junior SOC Analyst → SOC Analyst / Security Operations Analyst
Secondary growth pathway: Detection Engineering / Cloud Security Analyst
Long-term direction: Security operations leadership, subject-matter expertise and mentoring
The secondary and long-term pathways are recommendations derived from the submitted interests, portfolio direction and stated leadership ambition; they are not claims of current role seniority.
Development priorities
- Windows security telemetry and event-log investigation.
- Wazuh administration, alert triage, rule tuning and detection logic.
- Networking and packet-analysis fundamentals for SOC investigations.
- Incident response, evidence handling and escalation discipline.
- MITRE ATT&CK mapping, threat intelligence and detection engineering basics.
- Git/GitHub workflow and evidence-quality portfolio development.
- Cloud-security fundamentals with a vendor-neutral control mindset.
- Professional communication, concise incident writing and regular mentor feedback.
- Time-management habits that balance work and sustained learning.
- Interview readiness and visible evidence for junior SOC opportunities.
12-month North Star
By the end of the roadmap, Nkateko should be able to investigate common Windows and network security events, operate and tune a SIEM, document incident decisions, create and test basic detection logic, explain common attacker techniques, demonstrate cloud-security fundamentals, collaborate through GitHub and present a credible evidence portfolio for junior SOC and security-operations roles.
Evidence standard
A course or certificate records learning; it does not independently prove operational capability. Progress is demonstrated through investigations, lab notes, detection rules, runbooks, GitHub repositories, mentor review and the ability to explain decisions under questioning.