Skip to content

Ultimate Guide to Building a SOC and SIEM Career in 2026

An ultimate roadmap to launching a successful Security Operations Center (SOC) and SIEM career, covering essential skills, home labs, certifications, and salaries.

/ ARTICLE
[ FIG. 1 ]
SIEM and SOC tools and roadmap visualization for cybersecurity analysts

A Tier 1 analyst on a night shift will close somewhere between forty and two hundred alerts. Most of them are a backup agent that looks like data exfiltration, a developer running a port scan nobody told the SOC about, or the same misconfigured service account failing to authenticate every ninety seconds since March. The job is not catching attackers. The job is being right about which of those two hundred things is not noise, at 04:00, on hour seven, without slowing down — because the queue does not stop while you think.

That is worth saying up front, because most guides to this career sell the exciting version and candidates arrive expecting it. The compensating fact is that no other entry point in security puts you in front of that much real production telemetry that fast. It is the best available seat for learning what an environment actually looks like, and it is why incident response, threat hunting and detection engineering are all much easier to reach from a SOC than from outside one. This guide covers what the work involves, how to build a lab that proves you can do it, which certifications get you through a filter and which are a waste of a year’s budget, and what the market pays in 2026. For a real-world architecture case study, read Building a 24/7 Tier-1 SOC in Malaysia.

SOC architecture diagram showing Tier 1, 2, 3 analysts, SIEM platform, and alert sources

What is a SOC (Security Operations Center)?

A Security Operations Center (SOC) is the team that owns detection and response — monitoring, triage, investigation and containment, on a rota that covers hours when nobody else is awake. The centralisation is the point. Detection spread across an infrastructure team, a cloud team and whoever happens to notice something is not a SOC; it is four people each assuming one of the others is watching.

Two constraints shape everything about how these teams work, and both are worth understanding before you apply. The first is that coverage is expensive: genuine 24/7 needs roughly five to six analysts per seat once you account for leave, illness, training and turnover, which is why plenty of organisations run 8×5 in-house and hand the nights to an MSSP. The second is that alert volume is not a fixed property of the environment — it is a decision someone made about thresholds. A SOC drowning in alerts usually has a tuning problem being described as a staffing problem, and knowing the difference in an interview marks you out immediately.

SOC command center monitoring threat alerts

What is SIEM (Security Information and Event Management)?

If the SOC is the defensive team, Security Information and Event Management (SIEM) is where they do the work. A SIEM pulls telemetry from every corner of an environment — firewalls, endpoints, servers, identity providers, cloud control planes — normalises it into a common schema, and makes the whole lot searchable from one console.

The normalisation is the underrated half. Getting logs into one place is easy; getting a Windows security event, a Palo Alto traffic log and an Okta sign-in to agree on what “the user” and “the source address” mean is the work, and it is where most deployments quietly fail. A field that did not parse does not throw an error. It returns nothing, which on screen is indistinguishable from a clean environment.

What a working SIEM gives you:

  • Log ingestion and aggregation: Centralising telemetry into a single searchable store. The cost model is almost always per gigabyte ingested or indexed, which means every log source is a budget decision — and why the source somebody dropped to save money is so often the one you needed during an investigation.

  • Correlation rules: Joining events that mean nothing alone — a sign-in from an unfamiliar country, then a mailbox rule creation, then a bulk download — into one alert. Correlation across sources is what you are paying for; single-source alerting a firewall can already do itself.

  • Alerting: Putting the result in front of an analyst while the trail is fresh. Every rule you add has a false-positive rate, and that rate is paid by a human on shift. A rule that fires ten times a night and is wrong nine of them does not improve detection; it trains the team to click through.

  • Forensic auditing: Retaining history so an investigation can reconstruct what happened and when. Retention is the hard ceiling on every investigation you will ever run — if you keep thirty days and the intrusion started in February, the answer to “when did they get in” is permanently unavailable, and no amount of analyst skill recovers it.

  • Compliance reporting: Producing the audit trails that PCI-DSS, ISO 27001 and the local regulator expect. Useful, and worth being honest about: compliance reporting is frequently what funds the platform, which is why SIEMs end up tuned for evidence production rather than detection quality.

    Still deciding what platform fits? See SIEM vs. SOAR - Which One Do You Need?.

Whether you end up on Splunk, Microsoft Sentinel, Cortex XSIAM, or open-source tooling like Wazuh and the Elastic Stack, SIEM proficiency is the single most transferable technical skill for landing a SOC role. Not the product — the habit of thinking in queries, and the instinct to ask what a given log source would and would not have recorded.

Diagram of SIEM data flow from multiple sources to alerts and dashboards

Advertisement

SOC Analyst Roles and Career Path (Tier 1, 2, 3 and Beyond)

Most SOCs organise around a tiered model: juniors absorb the volume, seniors take the depth. It is worth knowing that the model is contested. A visible minority of mature teams have flattened it, on the argument that tiering optimises for throughput at the cost of analyst development — an L1 who only ever escalates never learns to finish an investigation, and turnover follows. Tiered or not, the work below still exists; the question is only whether one person or three do it.

Tier 1 — Triage Analyst (L1): The usual entry point. L1 lives in the alert queue: confirming or dismissing detections, running the standard enrichment — IP and domain reputation, email header analysis, checking whether the process that fired is normal for that host — and escalating what survives. Consistency matters more than brilliance here, because the value of a triage decision comes from it being reproducible by the next person on shift. The thing nobody mentions in the job advert: the rota. Rotating nights degrade sleep, health and judgement in ways a shift allowance does not fully compensate, and it is the most common reason people leave the tier rather than progress out of it. Ask about the shift pattern in the interview. A team that answers precisely has thought about it.

Tier 2 — Incident Responder (L2): Picks up what L1 escalates and establishes scope: what else did this account touch, is this host the first or the fifth, did anything leave the estate. That means endpoint telemetry, network traffic, malware behaviour, and then a containment call — isolate the host, disable the account, block the destination. Containment is a genuine trade-off rather than a formality: isolating early stops the bleeding and simultaneously tells the intruder they have been seen, which sometimes converts a patient operator into one who burns access aggressively on the way out. Two to five years’ hands-on experience is typical.

Tier 3 — Threat Hunter and Forensic Specialist (L3): Works from hypotheses rather than alerts, looking for what detection missed — living-off-the-land execution, credential misuse that looks like ordinary authentication, lateral movement over protocols that are supposed to be there. Also deep forensics, malware analysis, and writing the detections (Sigma, KQL, SPL) that turn a finding into something Tier 1 catches automatically next time. The honest constraint: hunting hours compete directly with triage hours. In an under-staffed team, hunting is the first thing cancelled, and it is cancelled quietly.

SOC Lead / Manager: Owns coverage, the detection strategy, the tooling budget and the metrics. Be sceptical of the metrics. Mean Time to Detect and Mean Time to Respond are the standard reporting pair and both are trivially gameable — closing alerts faster improves MTTR whether or not anything was investigated. The teams that use them well pair them with a measure that cannot be gamed the same way, such as detections written per quarter, or how many incidents were found by hunting rather than by an alert.

Beyond the tiers, the specialisations worth knowing about: Detection Engineering (building and tuning the analytics, increasingly treated as a software discipline with rules in version control and tested in CI), Threat Intelligence (tracking adversary behaviour and converting it into detections that actually run), and DFIR. Detection engineering is currently the strongest pay jump available from a SOC seat, and the one with the shortest path — it is largely a matter of writing rules well, in public, until someone notices.

Below is a summary of the SOC analyst tiers and their focus areas:

SOC RoleTypical ExperienceKey Focus & Responsibilities
Tier 1 SOC Analyst (L1)0-2 years (entry level)Monitor alerts (SIEM, IDS); initial triage of events; identify false positives vs. real threats; follow playbooks for common incidents; escalate serious issues to Tier 2.
Tier 2 SOC Analyst (L2)~2-5 years (mid-level)Deep investigation of incidents; malware analysis and network forensics; containment and remediation actions; coordinate with IT/engineering teams; adjust security tool rules to improve detection.
Tier 3 SOC Analyst / Threat Hunter (L3)5+ years (senior)Proactive threat hunting in logs and systems; analyse advanced/stealth threats; lead incident response for major breaches; root cause analysis; develop new detection techniques; mentor junior analysts.
SOC Lead / Manager5-10+ yearsTeam leadership & mentoring; ensure 24/7 coverage; incident response planning; KPI reporting (e.g. response times, number of incidents); strategy and improving SOC processes; liaise with upper management.

SOC career path ladder from Tier 1 Analyst to SOC Manager

Essential Skills and Certifications for SOC Analysts

Underneath all of it sits one skill: knowing what normal looks like in the environment you are watching, well enough that abnormal is visible without a rule telling you. Everything below is in service of that.

  • Networking and OS internals: You cannot judge a log you do not understand. TCP/IP, DNS, routing, the common ports and what legitimately uses them. On the host side, Windows Event Logs and Linux syslog — and specifically the gap between them and reality. The default Windows audit policy does not log process command lines; without Sysmon, or Event ID 4688 with command-line auditing explicitly enabled, you get the process name and nothing about what it was told to do, which is where the entire signal usually lives. Knowing that a control is off by default is more useful than knowing the control exists.
  • Security fundamentals: The attack vectors — phishing, ransomware, credential stuffing, injection, API abuse — and, more usefully, where each one leaves evidence. MITRE ATT&CK should be second nature, with one caveat worth carrying: ATT&CK is a catalogue of observed behaviour, not a coverage scorecard, and a heat map showing 70% technique coverage usually means someone counted rules rather than testing whether they fire. The Cyber Kill Chain remains a decent mental model for where in a sequence you still have a chance to intervene.
  • SIEM and log querying: Get properly fluent in one query language. SPL and KQL are the most marketable; the transferable part is not syntax but the discipline of narrowing a search from “everything on that host” to the twelve events that answer the question. A caution that costs beginners real time: in Elasticsearch and Sentinel alike, a query against a field that was never mapped, or was mapped as the wrong type, returns zero results rather than an error. Zero results and “no malicious activity” look identical on screen. Validate that a field is populated before you trust an empty answer.
  • Incident response process: Preparation, Detection and Analysis, Containment, Eradication, Recovery, Post-Incident Review. Knowing what happens next is what turns an alert into an outcome. The step people skip is the last one, and it is the only step that stops the same incident recurring.
  • Scripting (Python / Bash / PowerShell): Not software engineering — automation of the tedium. Parsing a log file, querying a threat intelligence API, deduplicating a list of indicators, pulling the same five enrichments you currently do by hand forty times a shift. It compounds: the analyst who scripts their triage gets time back to actually investigate, and that time is where their career progression comes from.
  • Documentation and technical writing: More of the job than anyone expects, and the differentiator at promotion time. An investigation nobody can follow did not happen. If you can turn a chain of cryptic events into a narrative a manager can act on and an engineer can verify, you are already ahead of most of your queue.

For wider career planning tips, read Cybersecurity Career Accelerator.

Recommended Certifications:

Certifications do one job well: they get a CV past a filter that a human never reads. They do not demonstrate competence, and hiring managers who have interviewed enough candidates know it — which is why the interview questions get specific fast. Treat them as a gate fee, buy the cheapest one that opens the gate you are standing at, and spend the remaining money and time on the lab.

Two failure patterns are worth avoiding. The first is buying above your level: a CISSP with no operational experience reads as someone who studied management theory instead of doing the work, and it does not help for a Tier 1 application. The second is the renewal treadmill — most of these carry annual maintenance fees and CPE requirements, so a shelf of five certifications is a recurring cost you will be paying while wondering which ones to let lapse. Match the credential to the stage, and stop.

Career StageCertifications to Consider
Entry-Level (0-1 years)- CompTIA Security+: The industry standard for foundational cybersecurity knowledge.
- ISC2 Certified in Cybersecurity (CC): An accessible entry-level certificate covering security basics.
- CompTIA Network+ (or Cisco CCNA): Critical for establishing network routing and switching fundamentals.
Intermediate (1-3 years)- CompTIA CySA+ (Cybersecurity Analyst): Highly practical, focusing on threat detection, SIEM log analysis, and incident response.
- Cisco/Splunk Core Certified Power User: Demonstrates practical hands-on proficiency in using Splunk.
- Microsoft SC-200: Shows capabilities in managing Microsoft Sentinel and Defender operations.
Advanced (3+ years)- ISC2 CISSP: The premier, management-level security certification (requires 5 years of experience).
- GIAC GCIA / GCIH: Premier technical certifications from SANS focusing on intrusion analysis and incident handling.
- ISACA CISM: Ideal for those transitioning into security management.

Note: in Malaysia and Singapore, most HR departments screen through an Applicant Tracking System before a human sees anything, and the screen is frequently run by a recruiter matching strings rather than assessing suitability. Security+, CySA+ and SC-200 carry real weight at that stage. Get them — then pair every credential with something you can demonstrate live, because the moment you reach a technical interviewer the certification stops counting and the question becomes what you have actually built.

This roadmap organizes certifications into domains, skill levels (Expert, Intermediate, Beginner), and relevant sub-domains.

481 certifications listed | July 2024

✨ Communication and Network Security

The communication and network security domain covers the ability to secure communication channels and networks. Topics include secure and converged protocols, wireless networks, cellular networks, hardware operation (warranty and redundant power) and third-party connectivity. IP networking (IPSec, IPv4 and IPv6) are also included in this domain.

Expert

  • CCIE Sec (Cisco Certified Implementation Expert - Security - $2,050 Hands-on Lab, $12,000 est Travel cost)
  • CCIE Ent (Cisco Certified Internetwork Expert - Enterprise Infrastructure - ~$2,050 hands-on lab, ~$12,000 in travel costs)
  • JNCIE Sec (Juniper Networks Certified Internet Expert, Security - $1,400 Hands-on Lab)
  • CCDE (Cisco Certified Design Expert - ~$1,600 written exam with hands-on lab)
  • FCX (Fortinet Certified Expert - $400 written exam, $1600 in-person lab)

Intermediate

  • CCNP Sec (Cisco Certified Network Professional - Security - ~$1,200 exam)
  • JNCIP Sec (Juniper Networks Certified Internet Professional, Security - $400 exam)
  • PCNSE (Palo Alto Networks Certified Network Security Engineer - $175 exam)
  • FCSS ZTA (Fortinet Certified Solution Specialist - Zero Trust Access - $800 two exams)
  • F5 CSE Sec (F5 Big-IP Certified Solution Expert - Security - $135 exam)
  • CCNP Ent (Cisco Certified Network Professional - Enterprise - ~$600 exam)
  • CCSM (Checkpoint Certified Security Master - $350 exam)
  • PCSAE (Palo Alto Certified Cloud Security Automation Engineer - $350 exam)
  • PCCSE (Prisma Certified Cloud Security Engineer - $350 exam)
  • FCSS NS (Fortinet Certificed Solution Specialist - Network Security - $800 two exams)
  • CCSE (Checkpoint Certified Security Expert - $250 exam)
  • JNCIS Sec (Juniper Networks Certified Internet Specialist, Security - $300 exam)
  • F5 CTS APM (F5 Big-IP Certified Technical Specialist - Access Policy Manager - $135 exam)
  • FCP NS (Fortinet Certified Professional - Network Security - $400 for 2 exams)
  • CCNA (Cisco Certified Network Associate - ~$330 exam)
  • F5 CTS DNS (F5 Big-IP Certified Technical Specialist - Domain Name Services - $135 exam)
  • PCDRA (Palo Alto Networks Certified Detection and Remediation Analyst - $155 exam)
  • CWSP (CWNP Certified Wireless Security Professional - $325 exam)
  • CREST CCNIA (CREST Certified Network Intrusion Analyst - $2,481 exam & essay, Hands on exam in UK)

Beginner

  • F5 CA (F5 Big-IP Certified Administrator - $135 exam)
  • eNDP (eLearnSecurity Network Defense Professional - $400 exam)
  • MNSE (Mosse Institute Network Security Essentials - $450 certification programme, 100% practical. No expiry.)
  • PCNSA (Palo Alto Networks Certified Network Security Administrator - $155 exam)
  • OWSE (ISECOM OSSTMM Wireless Security Expert - $100 annual sub, Unknown exam cost)
  • JNCIA Sec (Juniper Networks Certified Internet Associate, Security - $200 exam)
  • FCA (Fortinet Certificed Associate - Free course and exam required)
  • WCNA (Protocol Analysis Institute Wireshark Certified Network Analyst - $299 exam)
  • CCSA (Checkpoint Certified Security Administrator - $250 exam)
  • ITS-NS (Certiport IT Specialist - Network Security - $127 exam)
  • CCT (Cisco Certified Technician - $165 exam)
  • SOG NSP (SecOps Group Certified Network Security Practitioner - $249 exam)
  • Net+ (CompTIA Network+ - $369 exam)
  • FCF (Fortinet Certified Fundamentals Cybersecurity - Free 3 courses with exams req)
  • PCCET (Palo Alto Networks Certified Cybersecurity Entry-level Technician - $110 exam)

✨ IAM (Identity and Access Management) (The identity and access management domain covers the attacks that target the human gateway to gain access to data. Other topics include ways to identify users with rights to access the information and servers. Identify and access management covers the topics of applications, Single sign-on authentication, privilege escalation, Kerberos, rule-based or risk-based access control, proofing and establishment of identity.)

Intermediate

  • CIMP (Identify Management Institute Certified Identity Management Professional - $295 + Membership)
  • FCSS SASE (Fortinet Certified Solution Specialist - Secure Access Service Edge - $800 two exams)
  • CIAM (Identify Management Institute Certified Identify and Access Manager - $390 Exam)
  • CIDPRO (IDPro Certified Identity Professional - $700 exam)
  • SF CIAMD (SalesForce Certified Identity and Access Management Designer - $400 exam)
  • CIGE (IMI Certified Identity Governance Expert - $395 exam)

Beginner

  • CIST (IMI Certfied Identity and Security Technologist - $295 exam)
  • SC-300 (Microsoft Certfied: Identity and Access Administrator Associate - $165 exam)
  • CAMS (IMI Certfied Access Management Specialist - $195 exam)
  • SC-900 (Microsoft Certified: Security, Compliance, and Identity Fundamentals - $99 exam)

✨ Security Architecture and Engineering (The security architecture and engineering domain covers important topics concering security engineering plans, designs, and principles. Topics include assessing and mitigating information system vulnerabilities, fundamental concepts of security models and security architectures in critical areas like access control. Cloud systems, cryptography, system infiltrations (ransomware, fault-injection and more) and virtualized systems are also covered in this domain.)

Expert

Cloud/SysOps
  • VCDX DCV (VMware Certified Design Expert in Datacenter Virtualization- $3,995 exams, Application also req.)
  • VCIX DCV (VMware Certified Implementation Expert in DatacenterVirtualization - $900 two exams)
  • AWS SAP (Amazon Web Services CertifiedSolutions Architect - Professional - $300 exam)
  • AZ-305 (Microsoft Azure Solutions Architect Expert - $330 exam)
  • VCIX NV (VMware Certified Implementation Expert in NetworkVirtualization - $900 two exams)
  • Google PCSA (Google Professional Cloud Architect - $200 exam)
*nix
  • RHCA (Red HatCertified Architect - ~$3,745 exam, plus travel)
  • RHCE (Red HatCertified Engineer - $400 exam)
  • LPIC-3 (Linux Professional Institute Certified: 303 Security - $200 exam)
  • SCE (SUSE CertifiedEngineer - $195 practical exam)
ICS/IoT
  • ISA CE (ISACybersecurity Expert - $2,700 course + exam, Course required)
  • CACE (Excida IEC 62443 CertifiedAutomation Cybersecurity Expert - $700 exam)
General Engineering
  • CREST CRTSA (CREST Registered TechnicalSecurity Architect - $2,300 two exams, In person in the UK)
  • SABSA SCM (SABSA Chartered SecurityArchitect - Master Certificate - $3,750 exam & thesis, Branded courserequired)
  • GDAT (GIAC Defending Advanced Threats - $979 exam, SANS course recommended)
  • SC-100 (Microsoft Cybersecurity Architect - $165 exam)
  • SABSA SCP (SABSA Chartered SecurityArchitect - Practitioner Certificate - $3,750 written exam, Branded courserequired)
  • GDSA (GIAC Defensible SecurityArchitecture - $979 exam, SANS course recommended)

Intermediate

Cloud/SysOps
  • FCSS PCS (Fortinet Certified Solution Specialist -Public Cloud Security - $400 exam)
  • GCTD (GIAC Cloud Threat Detection - $979 exam, SANS course recommended)
  • MS-100 (Microsoft 365 Certified EnterpriseAdministrator Expert - $165 exam)
  • GPCS (GIAC Public Cloud Security - $979 exam, SANS course recommended)
  • GCSA (GIAC Cloud Security Automation - $979 exam, SANS course recommended)
  • FCSS SO (Fortinet Certified Solution Specialist -Security Operations - $400 exam)
  • PDSO CDE (PDSO Certified DevSecOps Expert - $1199, Exam and training bundled)
  • VCP DCV (VMware Certified Professional in Datacenter Virtualization - $375exam, Branded course required)
  • CCSP ((ISC)2 Certified CloudSecurity Professional - $599 exam)
  • FCP PCS (Fortinet Certified Professional - PublicCloud Security - $400 for 2 exams)
  • AWS CSS (Amazon Web Services Certified Security - Specialty - $150 exam)
  • SFCCCC (SalesForce Certified Community Cloud Consultant - $200 exam, Must beSalesForce Admin Certified)
  • EXIN PCSA (EXIN Professional CloudSolution Architect - $315 exam)
  • VCP NV (VMware Certified Professional in Network Virtualization- $375 exam, Branded course required)
  • AZ-500 (MicrosoftAzure Security Engineer Associate - $165 exam)
  • CSA CGC (Cloud Security Alliance CloudGovernance & Compliance - $315 exam)
  • GCLD (GIAC Cloud Security Essentials - $979exam SANS course recommended)
  • AWS SAA (Amazon Web Services CertifiedSolutions Architect - Associate - $150 exam)
  • EXIN PCSerM (EXIN Professional CloudService Manager - $315 exam)
*nix
  • GCWN (GIAC Certified WindowsSecurity Administrator - $979 exam, SANS course recommended)
  • CKS (Cloud Native ComputingFoundation Certified Kubernetes Security Specialist - $375 lab, Brandedcourse required)
  • LFCS (Linux Foundation CertifiedSystem Administrator - $300 exam)
  • FCP SO (Fortinet Certified Professional - SecurityOperations - $400 for 2 exams)
  • RHCSA (Red HatCertified System Administrator - $400 exam)
  • CKA (Cloud Native ComputingFoundation Certified Kubernetes Administrator - $375 lab, Branded courserequired)
  • LPIC-2 (LinuxProfessional Institute Certified: Linux Engineer - $400 2 exams)
ICS/IoT
  • GRID (GIAC Response and Industrial Defense -$979 exam, SANS course encouraged)
  • CSSA (Infosec Institute Certified SCADA Security Architect - $4,599 exam, Courserequired)
  • ISA CDS (ISA Certified DesignSpecialist - $2,700 course + exam)
  • TUV COTCP (TUV Rheinland Certified Operational Technology Cybersecurity Professional(GERMAN) - $415 exam)
  • GCIP (GIAC Critical InfrastructureProtection - $979 exam, SANS course encouraged)
  • ISA CRAS (ISA Certified RiskAssesment Specialist - $2,700 course + exam, Course required)
General Engineering
  • CIS LI (IBITGQ CertifiedISO 27001 Information Security Management Specialist Lead Implementer - $2008 course exam, Branded course required)
  • SFCTA (SalesforceCertified Technical Architect - $6000, Must be SF SA Certified)
  • SABSA SCF (SABSA Chartered Security Architect- Foundation Certificate - $3,750 exam, Branded course required)
  • SPLK-3001 (Splunk Enterprise Security CertifiedAdministrator - $130 exam, Branded course recommended)
  • SFSA (SalesForceSystem Architect - $400 hands-on lab)
  • CCSE (ECCouncil Certified Cloud Security Engineer - $100 exam, EC Council CourseRecommended)
  • MCSE (Mosse Institute Cloud SecurityEngineer - $600 exam)

Beginner

Cloud/SysOps
  • Google PCSE (Google Professional Cloud Security Engineer -$200 exam)
  • EXIN PCSM (EXIN Professional CloudSecurity Manager - $315 exam)
  • MDSO (Mosse Institute Certified DevSecOpsEngineer - $450 exam)
  • CSA CCSK (Cloud SecurityAlliance Certificate of Cloud Security Knowledge - $395 exam)
  • C)CSO (Mile2 Certified Cloud SecurityOfficer - $550 exam)
  • Server+ (CompTIA Server+- $319 exam)
  • PDSO CDP (PDSO Certified DevSecOps Professional -$799, Exam and training bundled)
  • EXIN PCD (EXIN Professional Cloud Developer -$315 exam)
  • Cloud+ (CompTIA Cloud+ -$369 exam)
  • Google ACE (Google Associate Cloud Engineer - $125 exam)
  • SOG CCSP-AWS (SecOps Group CertifiedCloud Security Practitioner - AWS - $249 exam)
  • AWS CP (Amazon Web Services Certified Cloud Practitioner - $100 exam)
  • EXIN PCA (EXIN Professional CloudAdministrator - $315 exam)
  • Cloud Essnt (CompTIA Cloud Essentials - $138 exam)
*nix
  • SCA (SUSE CertifiedAdministrator - $149 exam)
  • DCA (Docker CertifiedAssociate - $195 exam)
  • LPIC-1 (LinuxProfessional Institute Certified: Linux Administrator - $400 2 exams)
  • KCNA (Cloud Native ComputingFoundation Kubernetes and Cloud Native Associate - $250 exam, Brandedcourse required)
  • Linux+ (CompTIA Linux+ -$369 exam)
  • LFCA (Linux Foundation Certified IT Associate - $200 exam)
  • Apple ACSP (Apple CertifiedSupport Professional - $250 exam, Limited test locations)
  • A+ (CompTIA A+ - $253 exam)
ICS/IoT
  • ISA CAP (ISA CertifiedAutomation Specialist - $467 exam)
  • TUV COSM (TUV Certified OTSecurity Manager - $3,070 Course)
  • GICSP (GIAC Global IndustrialSecurity Professional - $979 exam, SANS course encouraged)
  • AZ-220 (Azure IoT Developer Specialty - $165 exam)
  • ISA CFS (ISA CertifiedFundamentals Specialist - $2,700 course + exam, Course required)
  • EITCA/IS (EITCA/ISInformation Security Certificate - $120 exam)
  • CACS (Excida IEC 62443 CertifiedAutomation Cybersecurity Specialist - $700 exam)
  • TUV COSP (TUV Certified OTSecurity Practitioner - $2725 course)
  • CIOTSP (CertNexus CertifiedInternet of Things Security Practitioner - $250 exam)
General Engineering
  • AZ-900 (Microsoft Azure Fundamentals - $165 exam)
  • MCSF (Mosse Institute Cloud ServicesFundamentals - $450 exam)
  • MSAF (Mosse Institute SystemAdministration Fundamentals - $450 exam)

✨ Asset Security (The Asset Security domain deals with the issues related to the collection, storage, maintenance, retention and destruction of data. It also covers knowledge of different roles regarding data handling (owner, controller and custodian) as well as data protection methods and data states. Other topics include resource provision, asset classification and data lifecycle management.)

Expert

  • ASIS CPP (ASIS Certified Protection Professional - $485 exam)

Intermediate

  • CIPT (IAPP Certified Information Privacy Technologist - $550 exam)
  • CDPSE (ISACA Certified Data Privacy Solutions Engineer - $880 Application)
  • EPDPP (EXIN Privacy and Data Protection Practitioner - $243 Exam, Course req'd)
  • CIPA (IMI Certified Identity Protection - $295 Exam)
  • DCPP (DSCI Certified Privacy Professional - $205 Exam)
  • CIMP (IMI Certified Identity Management Professional - $295 Exam)
  • CDP (IMI Certified in Data Protection - $395 Exam)

Beginner

  • ASIS APP (ASIS Associate Protection Professional - $350 exam)
  • CRFS (IMI Certified Red Flag Specialist - $295 exam)
  • CIPP (IAPP Certified Information Privacy Professional - $550 exam)
  • EPDPF (EXIN Privacy and Data Protection Foundation - $207 exam)
  • EPDPE (EXIN Privacy and Data Protection Essentials - $145 exam)

✨ Security and Risk Management (The security and risk management domain covers general on skills related to the implementation of user awareness programs as well as security procedures. Emphasis is also placed on risk management concerning the acquisition of new services, hardware and software (supply chain). Other skills include social engineering defense mechanisms.)

Expert

  • ITIL Master (ITIL Master - $4,000 Interview)
  • GSE (GIAC Security Expert - ~$7475 for 10 exams)
  • PgMP (PMI Program Management Professional - $1,000 exam)
  • CISSP Concentrations ((ISC)2 Certified Information Systems Security Professional Concentrations - $599 exam)
  • NCSC CCPLP (NCSC Certified Cybersecurity Professional - Lead Practitioner - $1388 interview)
  • Zach EAPro (Zachman Enterprise Architect Professional (Level 3) - $2,999 exam & case study, Level 1 & 2 cert not req'd)
  • PMP (PMI Project Management Professional - $555 exam)
  • CISM (ISACA Certified Information Security Manager - $760 exam)
  • S-ISME (SECO Information Security Management Expert - $850 exam)
  • NCSC CCPSP (NCSC Certified Cybersecurity Professional - Senior Practitioner - $907 interview)
  • CISSP ((ISC)2 Certified Information Systems Security Professional - $749 exam)
  • TOGAF (OpenGroup TOGAF Certified - $360 exam)
  • CCISO (EC Council Certified Information Security Officer - $3,150 course exam, Branded course required)
  • EEXIN ISM (EXIN Information Security Management Expert - EST $799 oral exam)
  • GSTRT (GIAC Strategic Planning, Policy and Leadership - $979 exam, SANS course recommended)
  • NCSC CCPP (NCSC Certified Cybersecurity Professional - Practitioner - $225 interview)
  • PSM III (Scrum.org Professional Scrum Master III - $500 exam, Branded course required)
  • GSP (GIAC Security Professional - ~$3735 for 5 exams)
  • GISP (GIAC Information Security Professional - $979 exam, SANS course recommended)

Intermediate

GRC (Governance, Risk, and Compliance) & General Management
  • ITIL SL (ITIL Strategic Leader - $4,800 two courseexams, 2 branded courses required)
  • Zach EAP (Zachman Enterprise Architect Practitioner (Level 2) -$2,999 exam & case study, Level 1 cert not req'd)
  • GSLC (GIAC Security LeadershipCertification - $979 exam, SANS course recommended)
  • S-CISO (SECO Certified InformationSecurity Officer - Resume review)
  • CASP+ (CompTIA Advanced SecurityPractitioner+ - $509 exam)
  • ITIL MP (ITIL Managing Professional - $9,600 4course exams, 4 branded courses requires)
  • Scrum SPS (Scrum Scaled Professional Scrum - $250 exam)
  • GLEG (GIAC Law of Data Security &Investigations - $979 exam, SANS course recommended)
  • CISSM (GAQMCertified Information Systems Security Manager - $170 exam)
  • CGRC ((ISC)2 Certified inGovernance, Risk and Compliance - $599 exam)
  • CRISC (ISACA Certified inRisk and Information Systems Control - $760 exam)
  • CSM (GAQM Certified ScrumMaster - $128 exam)
  • CASM (GAQM Certified AgileScrum Master - $128 exam)
  • CM)ISSO (Mile2 Certified MasterInformation Systems Security Officer - Complete C)SP, C)ISSO, C)ISSM andIS20 ($2200))
  • S-ISP (SECO Information SecurityPractitioner - $550)
  • Scrum PSD (Scrum Professional ScrumDeveloper - $200 exam)
  • GCPM (GIAC Certified ProjectManager - $979 exam, SANS course recommended)
  • BCS PCIRM (BCSPractitioner Certificate in Information Risk Management - $287 exam)
  • PEXIN ISM (EXINInformation Security Management Professional - $268 exam)
  • MGRC (Mosse Institute Certified GRC ExpertCertification - $450 certification programme, 100% practical. No expiry.)
  • M_o_R P (Axelos M_o_R Practitioner Risk Management - $560 exam)
  • CPD (GAQM CertifiedProject Director - $210 exam)
  • PMI ACP (PMI Agile CertifiedPractitioner - $495 exam)
  • EISM (EC CouncilInformation Security Manager - $3,499, Branded course required)
  • CGEIT (ISACA Certified in theGovernance of Enterprise IT - $760 exam)
  • EXIN 27001E (EXIN ISO/IEC 27001 Expert - ~$379 OralPresentation)
  • PECB 27005LM (PECB ISO/IEC 27005 Lead RiskManager - ~$1,595 exam, Course required)
  • DCCRP (DRI Certified Cyber ResilienceProfessional - $400 Exam)
  • Scrum PAL (Scrum Professional AgileLeadership - $200 exam)
  • CAPM (PMICertified Associate in Project Management - $300 exam)
  • PSM II (Scrum.org Professional ScrumMaster II - $250 exam)
  • APMG 20000P (APMG ISO/IEC20000 Practitioner - $308 Exam, Foundation or ITIL req'd)
  • C)ISRM (Mile2Certified Information Systems Risk Manager - $550 exam)
  • APMG 27001P (APMG ISO/IEC27001 Practitioner - $400 exam, Application essay)
  • PECB 27001LI (PECB ISO/IEC 27001 LeadImplementer - $930 exam, Course required)
  • Programming Language (Learning a programminglanguage is valuable to any IT professionals career. Recommendations:Python, Ruby, C++)
  • CCP (EC First Certified CCMC Professional - $2,995 exam, Courserequired)
  • C)ISSO (Mile2 Certified InformationSystems Security Officer - $550 exam)
  • CIS RM (IBITGQ Certified ISO 27005Information Security Management Specialist Risk Management - $2,783 courseexam, Branded course required)
  • EXIN 27001P (EXINISO/IEC 27001 Professional - $279 exam)
  • PECB 27032CM (PECB ISO/IEC 27032Lead Cybersecurity Manager - $899-$2,999 course exam, Course required)
  • C)HISSP (Mile2 Certified HealthcareInformation Systems Security Practitioner - $550 exam)
  • BCS PCIAA (BCSPractitioner Certificate in Information Assurance Architecture - $290 exam)
  • CCSA (EC First Certified Cyber Security Architect - $695 exam)
  • PPM (GAQM Professionalin Project Management - $210 exam)
  • C)ISSM (Mile2 Certified InformationSystems Security Manager - $550 exam)
  • TUV ITSM (TUV ITSecurity Manager (GERMAN) - $415 exam, Course required)
  • CCRMP (IBITGQ Certified in ManagingCyber Security Risk - $2,629 course exam, Branded course required)
  • PECB 27005RM (PECB ISO/IEC 27005 Risk Manager -~$995 exam, Course required)
  • CSBA (QAI CertifiedSoftware Business Analyst - $350 exam + written essay)

Beginner

  • CNDA (EC Council Certified NetworkDefense Architect - $200 application, Requires CEH cert)
  • DACRP (DRI Associate Cyber ResilienceProfessional - $200 exam, Course req)
  • CISRM (IBITGQ Certified ISO 27005Information Security Management Specialist Risk Management - $2,783 courseexam, Branded course required)
  • DCRMP (DRI Certified Risk ManagementProfessional - $400 exam, Application essay)
  • SSAP (SANS Security Awareness Professional - $1219 Exam, SANS MGT433 courserecommended)
  • GRCP (OCEG Governance, Risk, and Compliance Professional - $399 12 monthlicense)
  • SACP (The H Layer Security Awareness and CultureProfessional - $369 Exam)
  • CISP (GAQMCertified Information Security Professional - $170 exam)
  • Zach EAA (Zachman Enterprise Architect Associate (Level 1) -$2,999 course exam, Branded course required)
  • CAD (GAQM Certified AgileDeveloper - $128 exam)
  • CAC (GAQM Certified Agile Coach- $170)
  • ISMI CSMP (ISMI CertifiedSecurity Management Professional - $1159)
  • CSCS (EC First Certified Security Compliance Specialist - $695exam)
  • APMG 27001F (APMG ISO/IEC27001 Foundation - $400 exam, Application essay)
  • PECB 27001F (PECB ISO/IEC 27001 Foundation -$500-749 exam, Course required)
  • C)SLO (Mile2 Certified Security LeadershipOfficer - $550 exam)
  • GSEC (GIAC Security Essentials Certification - $979 exam, SANS courserecommended)
  • SSCP ((ISC)2 SystemsSecurity Certified Practitioner - $249 exam)
  • Security+ (CompTIASecurity+ - $404 exam)
  • M_o_R Fdn (Axelos M_o_R Framework Foundation - $495 exam)
  • Fair Fdn (Fair Institute Analysis Fundamentals- $1499 exam, Course required)
  • PSM I (Scrum.org Professional ScrumMaster I - $150 exam)
  • APMG 20000F (APMG ISO/IEC20000 Foundation - $308 exam)
  • ISMI CSM (ISMICertified Security Manager - $TBD)
  • BCS FISMP (BCS Foundation Certifiate in Information Security Management Principles -$249 exam)
  • CC (ISC2 Certified inCybersecurity - Free exam)
  • S-ISF (SECO Information SecurityFoundation - $460 exam)
  • GISF (GIAC Information SecurityFundamentals - $979 exam, SANS course recommended)
  • ITIL Fdn (ITIL Foundation - $383 exam)
  • Project+ (CompTIA Projec+ - $369 exam)
  • CIISec ICSF (CIISec Information andCybersecurity Fundamentals - $450 exam)
  • FEXIN (EXIN Information Security Foundation - $232exam)
  • EXIN 27001F (EXIN ISO/IEC27001 Foundation - $232 exam)
  • PECB 27005F (PECB ISO/IEC 27005 Foundation -$500-749 exam, Course required)
  • C CS F (IBITGQ Certified CyberSecurity Foundation - $725 course exam, Branded course required)
  • CIS F (IBITGQ Certified ISO27001 Information Security Management Specialist Foundation - $853 courseexam, Brandeed course required)
  • CSP (GAQM Certified SAFePractitioner - $170 exam)
  • IIBA CCA (IIBA Certification in CybersecurityAnalysis - $475 exam)
  • CITGP (IBITGQCertified in Implementing IT Governance - Foundation & Principles - ~$2,499course exam, Branded course required)
  • C)ISCAP (Mile2 Information SystemsCertification and Accredidation Professional - $550 exam)
  • CSAP (Infosec Institute Certified Security Awareness Practitioner - $2,599 exam,Course required)
  • PECB 27032F (PECB ISO/IEC 27032 Foundation -$500-749 exam, Course required)
  • MCL (Mosse Institute Cybersecurity Leadership- $450 exam)
  • ITS-C (Certiport ITSpecialist - Cybersecurity - $127 exam)

✨ Security Assessment and Testing (The security assessment and testing domain deals with all the techniques and tools used to find system vulnerabilities, weaknesses and potential areas of concern not addressed by security procedures and policies. Attack simulations, vulnerability assessment, compliance checks, and ethical disclosure also fall under this domain.)

Intermediate

  • GSNA (GIAC Systems and Network Auditor - $979 exam, SANS course recommended)
  • GCCC (GIAC Critical Controls Certification - $979 exam, SANS course recommended)
  • PCI QSA (PCI Qualified Security Assessor - $3000 req'd course)
  • CISA (ISACA Certified Information Systems Auditor - $760 exam)
  • GMON (GIAC Continuous Monitoring - $979 exam, SANS course recommended)
  • CIS LA (IBITGQ Certified ISO 27001 Information Security Management Specialist Lead Auditor - $2,008 course exam, Branded course required)
  • GCIA (GIAC Certified Intrusion Analyst - $979 exam, SANS course recommended)
  • CTPRA (Shared Assessment Certified Third-Party Risk Assessor - $1295 course)
  • PECB 27001LA (PECB ISO/IEC 27001 Lead Auditor - $930 exam, Course required)
  • IS20 (Mile2 IS20 Controls - $550 exam)
  • C)ISSA (Mile2 Certified Information Systems Security Auditor - $550 exam)
  • APMG 27001A (APMG ISO/IEC 27001 Auditor - $400 exam, Application essay)
  • APMG 20000A (APMG ISO/IEC 20000 Auditor - $308 Exam, Possible Course Req)
  • C)ISMS-LA (Mile2 Certified Information security Management Systems Lead Auditor - $550 exam)
  • CIS IA (IBITGQ Certified ISO 27001 Information Security Management Specialist Internal Auditor - $1543 course exam, Branded course required)
  • TUV MSA (TUV Rheinland Mobile Security Analyst (GERMAN) - $415 exam, Course required)
  • CTPRP (Shared Assessment Certified Third-Party Risk Professional - $1295 course)
  • IIA CIA (The Institute of Internal Auditors Certified Internal Auditor - $1315 3 exams)

Beginner

  • DCBCLA (DRI Certified Business Continuity Lead Auditor - $400 exam, Application req)
  • TUV Auditor (TUV Rheinland IT Security Auditor (GERMAN) - $415 exam, Course required)
  • DCBCA (DRI Certified Business Continuity Auditor - $400 exam, Application req)
  • GRCA (OCEG Governance, Risk, and Compliance Auditor - $399 12 month license)
  • CISST (GAQM Certified Information systems Security Tester - $170 exam)
  • EXIN CIT (EXIN Cyber & IT Security - $225 exam)
  • TUV CySec (TUV Rheinland Cybersecurity Specialist (GERMAN) - $415 exam, Course required)
  • TUV CyAware (TUV Rheinland Cybersecurity Awareness (GERMAN) - $415 exam, Course required)

✨ Software Security (The software development security domain deals with implementing software-based security protocols within environments for which the IT professional is responsible. Risk analysis, vulnerability identification and auditing of source codes are all covered in this subset. Additional topics include software-designed security, maturity models, development methodologies, open-source and third-party development security.)

Intermediate

  • GWEB (GIAC Certified Web Application Defender - $979 exam, SANS course recommended)
  • S-CSPL (SECO Secure Programming Certified Leader - $460 exam)
  • CSSLP ((ISC)2 Certified Secure Software Lifecycle Professional - $599 exam)
  • CASE (EC Council Certified Application Security Engineer (.NET or Java) - $550 exam)
  • DevNet Pro (Cisco DevNet Professional - $1200 two exams, DevNet Associate req'd)
  • GMLE (GIAC Machine Learning Engineer - $979 exam)

Beginner

  • CASST (GAQM Certified Advanced Software Security Tester - $210 exam)
  • CCSC (CertNexus Cyber Secure Coder - $300 exam)
  • DevNet A (Cisco DevNet Associate - $300 Exam)
  • SOG CAP (SecOps Group Certified AppSec Practitioner - $249 exam)
  • CSST (GAQM Certified Software Security Tester - $170 exam)
  • C)SWAE (Mile2 Secure Web Application Engineer - $550 exam)
  • MASE (Mosse Institute Certified Application Security Engineer - $450 exam)
  • S-SPF (SECO Secure Programming Foundation - $460 exam)

✨ Security Operations (The security operations domain covers topics ranging from investigations and digital forensic to detection and intrusion prevention tools, sandboxing and firewalls. Topics include user and entity behavior analytics, threat intelligence (threat hunting and threat feeds) log management, artifacts (mobile, computer and network), machine learning and AI-based tools, penetration testing, and exploitation development.)

Expert

Forensics
  • GREM (GIAC Reverse Engineering Malware - $979exam, SANS course recommended)
  • CFCE (IACIS Certified Forensic ComputerExaminer - $750 4 peer reviewed exams)
  • CSFA (CSIAC CyberSecurityForensic Analyst - $750 exam & lab)
  • GIME (GIACiOS and MacOS Examiner - $979 exam, SANS course recommended)
Incident Handling & Threat Intelligence
  • CCD (Certified CyberDefender - $800course, 2 exam attempt included)
  • CAWFE (IACIS Certified AdvancedWindows Forensic Examiner - $750 written exam & lab)
  • GCFA (GIAC Certified ForensicAnalyst - $979 exam, SANS course recommended)
  • GCTI (GIAC Cyber ThreatIntelligence - $979 exam, SANS course recommended)
  • CFSR (OpenText Certified ForensicSecurity Responder - $250 written exam & lab)
  • GNFA (GIAC Network Forensic Analyst - $979 exam, SANS course recommended)
  • MTIA (Mosse Institute CertifiedThreat Intelligence Analyst Certification - $450 certification programme,100% practical. No expiry.)
  • GCFR (GIAC Cloud Forensics Responder - $979exam, SANS course recommended)
  • BTL2 (Security Blue Team Level 2 - $2,190course, 1 exam attempt included)
Penetration Testing
  • CREST CSAM (CRESTCertified Simulated Attack Manager - $2,499 2 exams)
  • MRT (Mosse Institute Certified Red TeamerCertification - $450 certification programme, 100% practical. No expiry.)
  • CREST CCTINF (CREST CertifiedInfrastructure Tester - $2,520 exam & lab)
  • HTB CWEE (Hack the Box Certified WebExploitation Expert - $1260 Subscription available)
Exploitation
  • OSEE (Offensive SecurityExploitation Expert - $5,000 lab, Plus travel)
  • OSCE3 (Offensive Security Certified Expert 3 - $4649 3 labs)
  • OSWE (Offensive SecurityWeb Expert - ~$1649 lab)
  • OSEP (OffensiveSecurity Experienced Penetration Tester - $1,499 lab)
  • OSED (OffensiveSecurity Exploit Developer - $1,499 lab)
  • GXPN (GIAC Exploit Researcherand Advanced Penetration Tester - $979 exam, SANS course recommended)
  • GAWN (GIAC Assessing WirelessNetworks - $979 exam, SANS course recommended)

Intermediate

Forensics
  • GCFE (GIAC Cerified ForensicsExaminer - $979 exam, SANS course recommended)
  • GASF (GIAC Advanced Smartphone Forensics -$979 exam, SANS course recommended)
  • Cisco COP (Cisco CertifiedCyberOps Professional - $700 two exams)
  • CCFE (Infosec Institute Certified Computer Forensics Examiner - $4,599 exam,Course required)
  • MCPE (Mosse Institute CertifiedCyber Protection Expert - $800 exam)
  • CMFE (Infosec Institute Certified Mobile Forensics Examiner - $1,699 exam,Course required)
  • GX-FA (GIAC Experienced Forensics Analyst -$1299 exam, SANS course recommended)
  • CDRP (Infosec Institute Certified Data Recovery Professional - $4,599 exam,Course required)
  • eCDFP (eLearnSecurity Certified Digital Forensics Professional - $400 exam)
  • GPYC (GIAC PythonCoder - $979 exam, SANS course recommended)
  • MDFIR (Mosse Institute Certified DFIRSpecialist - $450 certification programme, 100% practical. No expiry.)
  • SC-400 (Microsoft Certified InformationProtection Administrator Associate - $165 exam)
  • CCE (ISFCE Certified Computer Examiner- $485 written exam)
  • CM)DFI (Mile2 Certified MasterDigital Forensic Investigator - Complete C)SP, C)DFE, C)NFE and C)CSA($2200))
  • EnCE (OpenText EnCase Certified Examiner - $200 two exams)
  • ACE (AccessData Certified Examiner - $100 + software)
Incident Handling & Threat Intelligence
  • GEIR (GIAC Enterprise Incident Response -$979 exam, SANS course recommended)
  • eCTHP (eLearnSecurity Certified Threat Hunting Professional - $400 lab)
  • GCED (GIAC Certified Enterprise Defender -$979 exam, SANS course recommended)
  • GCDA (GIAC Certified Detection Analyst - $979exam, SANS course recommended)
  • GCIH (GIAC Certified ForensicsAnalystr - $979 exam, SANS course recommended)
  • MTH (Mosse Institute Certified Threat HunterCertification - $450 certification programme, 100% practical. No expiry.)
  • CREST CRIA (CREST RegisteredIntrusion Analyst - $612 exam & lab)
  • CREST CRTIA (CRESTRegistered Threat Intelligence Analyst - $615 2 exams)
  • CREST CCHIA (CRESTCertified Host intrustion Analyst - $2,481 exam & essay, Hands on exam inUK)
  • eCIR (eLearnSecurity Certified Incident Responder - $400 lab)
  • C)IHE (Mile2 Certified Incident HandlingEngineer - $550 exam)
Penetration Testing
  • PACES (Pentester Academy CertifiedEnterprise Security Specialist - $339-749 Lab access, Exam included)
  • S-CEHL (SECO Certified Ethical Hacker Leader -Application)
  • CREST CRT (CREST RegisteredPenetration Tester - $612 exam)
  • CRTO II (ZeroPoint Security Red Team Operator II - $121 lab)
  • S-EHE (SECO Ethical Hacker Expert - TBD(still), Being redesigned)
  • CREST CCTIM (CRESTCertified Threat Intelligence Manager - $2,480 3 exams)
  • OSCP (Offensive SecurityCertified Professional - $1,499 labs)
  • GX-PT (GIAC Experienced Penetration Tester - $1299 exam, SANS course recommended)
  • GPEN (GIAC CertifiedPenetration Tester - $979 exam, SANS course recommended)
  • OSWP (Offensive SecurityWireless Professional - $450 labs)
  • CRTO (Zero PointSecurity Certified Red Team Operator - $121 lab)
  • LPT (EC Council Licensed Penetration Tester - $899 exam)
  • PNPT (TCM Security Practical NetworkPenetration Tester - $299 exam)
  • GCPN (GIAC Cloud PenetrationTester - $2,499 exam, SANS course recommended)
  • GRTP (GIAC Red Team Professional - $979 exam, SANS course recommended)
  • SOG CAPenX (The SecurityOps Group CertifiedAppSec Pentesting eXpert - $800 exam)
  • CSTL (CyberScheme Team Leader - $1945 exam)
  • eCPPT (eLearnSecurity Certified Professional Penetration Tester - $400 lab)
  • eWPT (eLearnSecurity Web Application Penetration Tester - $400 lab)
  • CM)IPS (Mile2 Certified MasterIntrusion Prevention Specialist - Complete C)VA, C)PEH, C)PTE and C)PTC($2200))
  • HTB CBBH (Hack the Box Certified Bug Bounty Hunter- $145 modules + $210 exam, $490 Subscription available)
Exploitation
  • eWPTX (eLearnSecurityWeb Application Penetration Tester eXtreme - $400 exam, $2000 training)
  • CREST CCSAS (CRESTCertified Simulated Attack Specialist - $2,520 2 exams & lab)
  • MCD (Mosse Institute CertifiedCode Deobfuscation Specialist Certification - $450 certification programme,100% practical. No expiry.)
  • GMOB (GIAC Mobile Device Security Analyst -$399 exam, SANS course recommended)
  • PJMR (Practical Junior MalwareResearcher - $399 lab)
  • CREA (Infosec Institute Certified Reverse Engineering Analyst - $4,599 exam,Course required)

Beginner

Forensics
  • OSIP (IntelTechniques OpenSource Intelligence Professional - $300 practical exam)
  • Cisco COA (Cisco Certified CyberOpsAssociate Cyber Operations - ~$325 exam)
  • C)CSA (Mile2 Certified CybersecurityAnalyst - $550 exam)
  • CHFI (EC Council Computer HackingForensics Investigator - $650 exam)
  • SC-200 (Microsoft Certified: Security OperationsAnalyst Associate - ~$165 exam)
  • MRCI (Mosse Institute RemoteCybersecurity Internship Programme - $49 certification programme, 100%practical. No expiry.)
  • EDRP (EC Council Disaster Recovery Professional - $450 exam)
  • HTB CDSA (Hack the Box Certified DefensiveSecurity Analyst - $145 modules + $210 exam, $490 Subscription available)
  • CySA+ (CompTIACybersecurity Analyst+ - $404 exam)
  • CSX-P (ISACA Cybersecurity Practitioner - $549lab)
  • C)NFE (Mile2Certified Network Forensics Examiner - $550 exam, Groups only)
  • GOSI (GIAC Open Source Intelligence - $979 exam, SANS course recommended)
  • OPSA (ISECOM OSSTMM ProfessionalSecurity Analyst - $100 annual sub, Unknown exam fee)
  • CSAE (Cyber Struggle AEGIS - $1700 course exam, Branded course required)
  • ASIS PCI (ASIS Professional CertifiedInvestigator - $485 exam)
  • MOIS (MOIS Certified OSINT Expert Certification- $450 certification programme, 100% practical. No expiry.)
  • CFA (GAQMCertified Forensic Analyst - $128 exam)
  • CSA (EC CouncilCertified SOC Analyst - $550 exam)
  • GFACT (GIAC FoundationalCybersecurity Technologies - $979 exam, SANS course recommended)
  • ECSS (ECCouncil Certified Security Specialist - $249 exam)
  • C)DFE (Mile2 Certified Digital ForensicsExaminer - $550 exam)
  • C)SP (Mile2 Certified Security Principles -$550 exam)
  • CSCU (ECCouncil Certified Secure Computer User - $125 exam)
  • MICS (Mosse Institute Introductions toCyber Security - Free exam)
Incident Handling & Threat Intelligence
  • S-TA (SECO Certified Threat Analyst - $550 exam)
  • ECIH (EC Council Certified IncidentHandler - $300 exam)
  • OSDA (OffensiveSecurity Defense Analyst - $2,499 exam, Learning subscription required)
  • CFR (CertNexusCyberSec First Responder - $250 exam)
  • CTIA (EC Council Certified Threatintelligence Analyst - $450 exam)
  • MAD SOCA (Mitre Att&ck Defender SecurityOperations Center Assessment - $299 annual subscription)
  • MAD CTI (Mitre Att&ck Defender Cyber Threatintelligence - $299 annual subscription)
  • CCOA (ISACA Certified CybersecurityOperations Analyst - $760 exam)
  • CREST CPIA (CRESTPractitioner Intrusion Analyst - $425 exam)
  • MESE (Mosse InstituteEnterprise Security Engineer - $450 exam)
  • CREST CPTIA (CRESTPractitioner Threat Intelligence Analyst - $425 exam)
  • S-SA (SECO Associate SOC Analyst - $480exam)
  • DV AOPH (Dark Vortex AdversaryOperations and Proactive Hunting - $2500 exam, Course required)
  • CND (ECCouncil Certified Network Defender - $550 exam)
  • CSX-F (IBITGQ CyberIncident Response Management Foundation - $768 course exam, Branded courserequired)
  • DV MILF (Dark Vortex Malware Incident and LogFoensics - $2000 exam)
  • CIRM Fdn (IBITGQ CyberIncident Response Management Foundation - $768 course exam, Branded courserequired)
Penetration Testing
  • C)PSH (Mile2 Certified Powershell Hacker -$550 exam)
  • CMWAPT (Infosec Institute Certified Mobile and Web App Penetration Tester - $4,599exam, Course required)
  • C)PTC (Mile2 Certified Penetration TestingConsultant - $550 exam)
  • CRTOP (Infosec Institute Certified Red Team Operations Professional - $4,599exam, Course required)
  • CSR (Cyber Struggle Ranger -Location Based Cost, Course Req)
  • CEH (ECCouncil Certified Ethical Hacker - $1,199 exam)
  • SOG CAPen (The SecOpsGroup Certified AppSec Pentester - $500 exam)
  • C)PTE (Mile2Certified Penetration Testing Engineer - $550 exam)
  • SOG CNPen (The SecOpsGroup Certified Network Pentester - $500 exam)
  • DV RTOS (Dark Vortex Red Team & OperationalSecurity - $2500 exam, Course required)
  • SOG CMPen And (The SecOps Group CertifiedMobile Pentester - Android - $400 exam)
  • SOG CMPen iOS (The SecOps Group Certified MobilePentester - iOS - $400 exam)
  • DV MoS (Dark Vortex Malware on Steroids - $2000 exam, Courserequired)
  • Pentest+ (CompTIA Pentes+ - $404 exam)
  • C)VA (Mile2 CertifiedVulnerability Assessor - $550 exam)
  • KLCP (Kali Linux Certified Professional - $299exam)
Exploitation
  • eMAPT (eLearnSecurity Mobile Application Penetration Tester - $400)
  • BSCP (Portswigger Burp SuiteCertified Practioner - $99 exam)
  • OPST (ISECOM OSSTMM ProfessionalSecurity Tester - Unknown)
  • OSWA (OffensiveSecurity Web Assessor - $2,499 Exam, Learning subscription required)
  • CSTM (CyberScheme Team Member - $610 exam)
  • eJPT (eLearnSecurity JuniorPenetration Tester - $249 lab)
  • S-EHP (SECO Ethical Hacking Practitioner -$550 exam)
  • CHAT (ISECOM Certified Hacker AnalystTrainer - $100 annual sub, Unknown exam price)
  • CREST CPSA (CRESTPractitioner Security Analyst - $425 exam)
  • OPSE (ISECOM OSSTMM ProfessionalSecurity Expert - $100 annual sub, Unknown exam cost)
  • MPT (Mosse Institute CertifiedPenetration Tester Certification - $450 certification programme, 100%practical. No expiry.)
  • CPENT (EC Council CertifiedPenetration Testing Professional - $999 exam)
  • CREST CCTAPP (CRESTCertified Web Application Tester - $2,520 exam & lab)
  • HTB CPTS (Hack the Box CertifiedPenetration Testing Specialist - $200 modules + $210 exam, $490Subscription available)
  • MRE (Mosse Institute Certified ReverseEngineer Certification - $450 certification programme, 100% practical. Noexpiry.)
  • ECES (EC Council CertifiedEncryption Specialist - $249 exam)
  • MCPT (Mosse Institute Cloud PenetrationTester - $450 exam)
  • C)PEH (Mile2 CertifiedProfessional Ethical Hacker - $550 exam)
  • GCPEH (GAQMCertified Professional Ethical Hacker - $170 exam)
  • EEHF (EXIN Ethical Hacking Foundation -$232 exam)
  • S-EHF (SECOEthical Hacking Foundation - $460 exam)
  • CHA (ISECOM Certified Hacker Analyst- $100 annual sub, Unknown exam cost)
  • DV OTD (Dark Vortex Offensive Tool Development - $2000 exam, Course required)
  • MVRE (Mosse Institute Vulnerability Researcher and Exploitation Specialist - $450 Exam)

Advertisement

Leading SIEM Platforms in 2026: Commercial vs. Open Source

You do not need to learn all of these. Ingestion, normalisation, correlation and search are the same four ideas everywhere, and once you can think in one platform the next is mostly new syntax and a different set of annoyances. Learn one properly rather than five superficially; “I know six SIEMs” reads, correctly, as “I have clicked around in six SIEMs”.

Knowing the landscape still helps, mostly so you can read a job advert accurately. Here is where the major platforms stand in 2026.

Commercial SIEM Platforms

Enterprise SIEMs buy you scale, vendor support, pre-built integrations and someone to escalate to at 3 a.m. The trade-off is not only that licensing is expensive — it is that licensing is usually priced on data volume, which puts a price on every log source and quietly turns detection coverage into a procurement negotiation. The most consequential security decision in many organisations is which sources did not make the budget, and it is rarely made by anyone in the SOC.

SIEM ToolVendor / OwnerKey Features & 2026 Market Context
Splunk Enterprise SecurityCisco (USA)The incumbent, and the reason SPL is the most portable query skill in the market. Enormous app ecosystem, will ingest essentially anything. Acquired by Cisco in 2024. The cost is genuinely the deciding factor at scale — volume-based licensing is why organisations end up filtering logs before ingestion, which moves the coverage gap somewhere nobody is looking at it.
Microsoft SentinelMicrosoft (USA)Cloud-native, queried with KQL, and effectively frictionless if your identity and productivity estate is already Microsoft — Entra ID, Microsoft 365 and Defender connectors are first-party and cheap to turn on. That is also the trade: it is at its weakest as a neutral aggregator of a heterogeneous estate, and pay-as-you-go pricing means a noisy new source can produce a bill nobody approved.
Cortex XSIAM / QRadarPalo Alto Networks (USA)IBM sold its QRadar SaaS assets to Palo Alto Networks in 2024, and customers are being migrated onto Cortex XSIAM. On-premise QRadar deployments are still running in plenty of places but are on a clock. Worth knowing if you are weighing a QRadar-specific certification — platform-specific credentials are the ones that expire when a vendor changes direction.
ArcSight ESMOpenText (Canada)A veteran platform, still entrenched in government and large legacy enterprises. Capable correlation engine; heavy to operate and heavier to modernise. Knowing it is a niche advantage in exactly the sectors that pay for stability.
RSA NetWitnessRSA Security (USA)Log analysis combined with full packet capture and network monitoring. The forensic detail is excellent — you can reconstruct a session rather than infer it — and the price of that is storage and infrastructure most organisations decide they cannot justify.

Want to understand how SIEM fits alongside automation tools? See SIEM vs. SOAR - Which One Do You Need?.

Open-Source and Community SIEM Tools

If you are building a lab or working somewhere with no licensing budget, this is where you start — and the configuration effort is a feature. Wiring up a forwarder by hand, discovering the agent is running but nothing is arriving, and tracing it to a firewall rule teaches you more about SIEM operations than any course. Free is also the wrong word: you pay in your own time, and in production you pay again in the engineering hours that a vendor support contract would otherwise cover.

SIEM ToolOverview & FeaturesPros & Cons
Elastic Security (ELK)Elasticsearch, Logstash and Kibana with a security layer on top: detection rules, a case management workflow and an ATT&CK-aligned rule set. Search is genuinely fast, and it will swallow log formats nothing else will parse.Pros: Very customisable, large community, excellent for unstructured logs.
Cons: Memory-hungry, and the operational burden is real — index lifecycle management, shard sizing and mapping conflicts become your problem. Machine learning and several detection features sit behind a paid tier.
WazuhSIEM and endpoint monitoring in one: agents on hosts handle file integrity monitoring, log collection, rootkit checks and active response, feeding a central manager with an OpenSearch-based interface.Pros: Free, with compliance rule sets (PCI-DSS, NIST 800-53) mapped out of the box, and the fastest route to seeing your own endpoint telemetry.
Cons: Custom decoders and rules use a bespoke XML syntax that transfers nowhere else, and active response is a loaded weapon — a rule that isolates a host will eventually isolate the wrong one.
GraylogA focused log management engine with straightforward search and alerting. Does the boring 80% cleanly.Pros: Far lighter than ELK and quicker to stand up; a good choice if the goal is centralised logs you will actually search.
Cons: Multi-source correlation needs scripting or the commercial tier, so it can become the thing you outgrow rather than the thing you build on.
Security OnionA purpose-built Linux distribution for network security monitoring: Zeek, Suricata, Wazuh, Elastic and a case tracker, pre-integrated.Pros: The single best way to learn network forensics without assembling the stack yourself. Zeek connection logs alone will teach you more about your network than any diagram.
Cons: Genuinely resource-hungry — plan on 16 GB of RAM as a floor for anything beyond a token deployment — and the number of moving parts is disorienting at first.
AlienVault OSSIMThe open-source ancestor of the commercial USM platform, now under LevelBlue following the AT&T Cybersecurity spin-out. Bundles asset discovery with Snort-based intrusion detection.Pros: Broad feature set in one console.
Cons: Effectively legacy — sparse updates and a shrinking community. Fine to have seen, a poor choice to build a career skill on.

For career preparation, start with Wazuh or the Elastic Stack — active communities, adequate documentation, and habits that transfer. If you have to pick one and you are targeting Microsoft-heavy employers, note that Sentinel offers a free tier for a limited data volume, and KQL is worth more on a CV in this region than any open-source query syntax. Whatever you choose, use it for months rather than weeks. Depth in one platform is what interviews test; breadth across five is what CVs claim.

SIEM dashboard showing a triggered security alert

Hands-On Practice: Setting Up Your SOC Home Lab

Reading about SIEM is a reasonable start. Catching your own simulated attack in your own logs is what makes you employable, because it is the one thing on a junior CV that cannot be bluffed — the follow-up question is always “what did the process tree look like”, and there is no answer to that from a course.

Two things before you start. Keep the lab isolated: a host-only or internal virtual network, no bridged adapter. A bridged VM running attack tooling is on your home network and, depending on your ISP and what you point it at, potentially somebody else’s — scanning infrastructure you do not own is a criminal matter in both Malaysia and Singapore, and “it was for my portfolio” is not a defence. And snapshot every VM once it is clean. You will break the SIEM. That is the point, but it is much less painful with a snapshot to fall back to.

Here is how to build a working mini-SOC:

  1. Set up the infrastructure: Nothing exotic. 16 GB of RAM runs two or three VMs comfortably under VirtualBox or VMware Workstation Player; 8 GB works if you are disciplined about running one guest at a time. If your machine cannot cope, cloud free tiers do the job — set a billing alert before you start, because an unattended lab instance is a bill, not a lesson.
  2. Deploy your VMs: A Windows 10/11 guest as the target workstation, and a Linux guest running Ubuntu Server or Debian.
  3. Install your SIEM: Wazuh or Elastic Security on a dedicated VM. Give it more disk than you think — index growth is what kills lab SIEMs, and Elasticsearch responds to a full disk by flipping indices to read-only, at which point ingestion stops silently and your dashboards simply stop moving rather than reporting an error.
  4. Start ingesting logs:
    • On the Windows guest, install Sysmon with a community configuration such as SwiftOnSecurity’s. This is the step that matters most: without it you get process names, with it you get command lines, parent-child relationships, network connections and hashes. Read the config rather than just applying it — it is a filter, and knowing what it deliberately excludes is knowing your own blind spots.
    • Install the matching forwarder (Wazuh agent, Splunk Universal Forwarder, Winlogbeat/Elastic Agent) and point it at the SIEM. Then confirm events are actually arriving by searching for something you just did. An agent showing “connected” while shipping nothing useful is the single most common lab failure, and the console will not tell you.
  5. Simulate attacks — actually do this: An empty SIEM teaches nothing. Generate the data.
    • Use Atomic Red Team to execute individual ATT&CK techniques and watch what surfaces. Run the cleanup commands afterwards; several atomics leave persistence behind by design.
    • Do some by hand too: an Nmap scan against the Windows guest, a failed-authentication burst, a PowerShell download cradle. Manual work is where you notice how little the default logging captured.
  6. Build detections:
    • After each simulation, find the exact events it produced. Which Event IDs fired? What was the parent process? What did not get logged?
    • Write a rule for it — alert when one source produces more than ten failed authentications inside sixty seconds — and then, more importantly, try to evade your own rule. Spread the attempts over five minutes and watch it stay silent. That gap between “my detection fired” and “my detection is hard to slip past” is the entire discipline of detection engineering, and finding it yourself is worth more than any course module.

Building a Portfolio That Gets You Interviews

A lab nobody can see is indistinguishable from no lab. Make the work legible:

  • GitHub: Push the detection rules, the queries, the scripts. Five well-documented detections beat fifty copied from a public repo — and write down what each one misses, because a rule with a stated limitation demonstrates judgement, while a rule presented as complete demonstrates that you have not tested it. Scrub the repo before it goes public: lab hostnames, internal IP ranges and anything resembling a real credential.
  • Incident write-ups: After each exercise, produce a short structured report — what fired, what you checked, what you concluded, what you would remediate, and what you could not determine from the available logs. That last section is the one experienced interviewers read.
  • Blog posts: Doubles as proof of the technical writing the job actually demands. One post explaining exactly why a detection failed is worth more than ten walkthroughs of an installation that went fine.

Network topology showing workstation VMs sending security telemetry to a central SIEM server

Landing the Job: Resume and LinkedIn Optimization

Skills and lab work get you this far. Now they have to survive a document filter and a thirty-second human skim, which are two different audiences with incompatible preferences — the filter wants terms, the human wants specifics. Write for the human and make sure the terms are present naturally, rather than the reverse.

Writing a Resume That Works

  • Lab work counts: No professional security experience is not a blocker — an empty CV is. Put the lab under “Technical Projects” and be specific: “Deployed Wazuh across a three-VM lab, ingested Sysmon telemetry from a Windows 11 endpoint, and wrote custom rules for credential dumping and lateral movement” says more than any list of tool names. Label it honestly as a lab. Interviewers work out the difference in one question, and a candidate who blurred it has failed a more important test than the technical one.
  • Use the right terms: SIEM, SOC, log analysis, incident response, KQL, SPL, Sysmon, MITRE ATT&CK — worked into the descriptions of what you did, not stacked in a keyword block at the bottom. Mirror the vocabulary of the specific advert; a filter tuned for “Microsoft Sentinel” does not necessarily match “Azure Sentinel”.
  • Put numbers in: “Investigated 12 simulated incident scenarios across a 3-VM lab”, “wrote 8 Wazuh rules covering Credential Access and Discovery techniques”. Concrete, checkable, and memorable — but only claim numbers you can talk through, because the interviewer will pick one of the eight rules and ask what it does.

Using LinkedIn Strategically

  • Your headline is a search field: Recruiters search it. “Student” and “Job Seeker” match nothing anyone is looking for; “Aspiring SOC Analyst | CompTIA Security+ | Home Lab: Wazuh, Sysmon, KQL” matches the queries they actually run.
  • Post about the lab: A screenshot of your SIEM catching a simulated attack, with two paragraphs explaining which events gave it away, is the highest-return content a junior can publish. Blur hostnames and addresses first — the lab is yours, but the habit needs to exist before you are posting about an employer’s environment.
  • Engage rather than collect: Find the SOC managers, senior analysts and recruiters hiring in your market, and comment on their work with something substantive. Hiring in this field runs heavily on recognition, and being the person who asked a good question three months ago beats a cold connection request every time. It is also slow — treat it as something you start now and benefit from later, not a tactic for the week you need a job.

LinkedIn profile mockup for an aspiring SOC analyst

Managed Security Providers (MSSPs) and Freelance Pathways

Most people picture an in-house corporate SOC. Numerically, that is not where the entry-level seats are.

  • Managed Security Service Providers (MSSPs): MSSPs monitor many client environments at once, and they hire juniors continuously — partly because they need volume, partly because attrition is high. Both facts are the same fact. You will see more variety in six months than a quiet in-house SOC produces in three years, and you will see it on a rota, under a contractual response time, across environments you were given a runbook for rather than an understanding of. Take it deliberately: it is an excellent two-year education and a poor five-year plan. The analysts who get the most out of MSSP work treat every unfamiliar client stack as free exposure and leave for an in-house role once the learning curve flattens.
  • SOC-as-a-Service (SOCaaS): Mid-sized organisations outsourcing monitoring wholesale. Similar work, usually a broader toolset and a faster tempo. The structural limitation is worth knowing before you join: an outsourced SOC can detect and recommend, but rarely has the authority to act on the client’s estate, so you will regularly identify something serious and then wait for someone else to decide. If sitting with that is going to frustrate you, it is better to know now.
  • Freelance consulting: Full-time freelance SOC monitoring barely exists — nobody hands continuous access to their security telemetry to a contractor, and data protection obligations make it awkward even when they want to. Project work does exist: standing up a cloud SIEM, producing a compliance report, auditing what an organisation is and is not logging. That last one is a genuinely good niche for someone competent, because most small companies have no idea, and the answer is nearly always “less than you think”.

Thinking about exploring the offensive side of security too? Read Launching a Penetration Testing Career in Malaysia & Singapore.

Below are the platforms worth searching for entry-level security roles, remote contracts and local listings. A caveat on all of them: a large share of security hiring never reaches a job board, and the roles that do are the ones that could not be filled through a referral first. Use these as a supplement to talking to people, not a substitute.

✨ Top 20 Job Boards in Singapore
#WebsiteFocus / Notes
1MyCareersFutureOfficial government portal; trusted source for local IT jobs
2JobStreet SGPopular across SEA; strong in tech, finance, and corporate hiring
3LinkedIn JobsTop choice for IT professionals and remote-friendly opportunities
4eFinancialCareers SGGreat for fintech, cyber risk, and IT roles in banking sector
5Tech in Asia JobsFocused on startups, regional tech jobs, and remote options
6NodeFlairSingapore-based tech career platform with salary transparency
7STJobsBacked by The Straits Times, mostly local listings
8JobTechAI-driven platform that curates real-time job market data
9Glints SGFast-growing platform for tech & creative roles, great for startups
10JobsCentral SGCovers both IT and non-IT sectors; good for fresh grads
11StartupJobs AsiaStartup-centric, often includes equity-based and flexible roles
12HackerTrailTech-specific hiring platform, includes coding challenges
13Wantedly SGCompany culture-focused job search for startups and tech firms
14Monster SGInternational platform, useful for IT and expat positions
15GrabJobsFeatures chatbot-based application process, includes tech support roles
16XcruitNew-age job platform with integrated video resumes
17InternSGBest for internships, junior roles in IT, marketing, and engineering
18TalentTribeVisual job descriptions, focuses on tech and youth jobs
19JobsDB SGStill active, though many jobs are mirrored with JobStreet
20DrJobs SGPopular in the expat and overseas Singaporean community
✨ Top 20 Job Boards in Malaysia
#WebsiteFocus / Notes
1JobStreetMost popular job portal in Malaysia, strong IT category
2LinkedInGreat for IT & cybersecurity, allows direct networking with employers
3JobsCentralIT, engineering, and graduate jobs
4Hiredly (WOBB)Young, startup-friendly; includes internships & entry-level IT roles
5myFutureJobsGovernment portal, good for local IT and GLC jobs
6Tech in Asia JobsStartup-focused, regional, many remote tech jobs
7GlintsIT jobs in startups & SMEs, also has freelance and contract listings
8FastJobsSimple UI; has tech support, IT admin, and basic dev jobs
9JobstoreBroad platform, decent number of tech job listings
10Indeed MalaysiaGlobal portal, wide range of local and expat-friendly IT roles
11Job MajesticSpecialises in high-paying or niche roles, strong tech presence
12FutureLabMentorship platform with growing job board for students and juniors
13Monster MalaysiaOlder platform but still lists IT jobs across Asia
14BossjobAI-based matching, supports messaging employers directly
15JobCartMalaysian job portal gaining traction in tech & digital job markets
16JobifyEmerging site, startup jobs, internships, tech openings
17RicebowlBilingual portal (English/Chinese), includes tech jobs
18TribeHiredFor tech and startup talent, includes high-level developer roles
19MaukerjaBlue-collar + tech support/IT admin roles
20InternSheepsInternships in IT, cybersecurity, and digital marketing
✨ Top 10 Remote IT Job Sites
#WebsiteFocus / Highlights
1We Work RemotelyOne of the oldest & largest platforms for remote software & DevOps jobs
2Remote OKRemote tech jobs with global employers; filter by timezone
3TuringU.S. companies hiring vetted remote developers from Asia
4RemotiveCurated list of remote dev, cloud, and cyber jobs globally
5JobspressoRemote-only jobs in tech, sysadmin, cybersecurity, product, and support
6Working NomadsDaily updated list of remote tech roles from global sources
7OutsourcelyRemote jobs from startups looking to hire directly - no commission cuts
8PangianRemote jobs with timezone matching; strong in tech, cyber, data
9Hubstaff TalentFree remote job marketplace for freelancers and long-term IT contracts
10CodementorXHigh-paying freelance/remote developer jobs, especially for experienced devs
Advertisement

2026 Salary Expectations & Job Market Insights

Treat every figure below as an indicative band rather than a quote. Published salary data in this region is thin, self-reported and lags the market, and the spread within a single band is driven more by sector than by skill — a bank or a regulated telco pays materially above a mid-market employer for the same job title. Verify against current listings before you anchor a negotiation on anything here.

  • Malaysia: Demand for qualified analysts continues to outstrip local supply, which has pushed entry-level pay up steadily. Most enterprise SOCs pay a shift allowance on top of base, which matters at Tier 1 — it can be a meaningful fraction of take-home, and it is also compensation for a rota that will cost you sleep, so count it honestly rather than treating it as a bonus.
    • Junior / Entry-Level: RM 3,500 – RM 5,500 per month
    • Mid-Level: RM 6,000 – RM 10,000 per month
    • Senior / Lead: RM 11,000+ per month
  • Singapore: The regional financial and technology hub, with the salaries to match. Compare on what remains after housing rather than on the headline, and check the work-pass position before you plan around it — for a junior role the employer must sponsor an Employment Pass against a qualifying salary threshold, and many will simply hire locally instead. Candidates with a few years of experience have a far easier time of it.
    • Junior / Entry-Level: SGD 4,000 – SGD 5,500 per month
    • Mid-Level: SGD 6,500 – SGD 9,500 per month
    • Senior / Lead: SGD 10,500 – SGD 15,000+ per month Security+ or CySA+ paired with demonstrable lab work carries real weight with Singapore hiring managers — the certification gets the CV read, the lab gets the interview.
  • Remote roles: With a few years of experience and genuinely good written English, remote work for US, UK and European employers is accessible from Southeast Asia, and earning in a stronger currency while living in Kuala Lumpur or Penang is a powerful arbitrage. The parts nobody mentions: many SOC roles cannot be remote at all, because the client contract or the regulator requires monitoring from a specific jurisdiction; the ones that can be will usually want you on their business hours, which from this region means nights; and contractor arrangements typically come without the employment protections, medical cover or provident fund contributions a local role includes. Price that in before comparing headline numbers.

The money is not the main argument for Tier 1 anyway. The argument is optionality. Incident Response, Threat Hunting, DFIR, Detection Engineering and Cloud Security all pay considerably more, and each of them is a plausible move from inside a SOC and a difficult one from outside. The seat is the point — and the people who use it well are the ones who volunteer for the tuning work, the automation nobody has time for, and the write-ups nobody wants to do, because those are the tasks that look like the next job rather than the current one.

A Six-Month Roadmap to Your First SOC Role

Most people do not need more advice; they need a sequence and a finish line. The plan below assumes roughly ten to fifteen hours a week alongside a job or a degree. At that pace six months makes you a credible junior candidate — not a competent analyst. That happens in your first year on a real queue, watching an environment you did not build, and no amount of preparation substitutes for it. Halve the pace and it takes a year; that is fine, and it is a much better outcome than abandoning it at week seven, which is what usually happens to people working from a plan built for forty hours a week.

MonthFocus AreaKey Milestones & Goals
Month 1FoundationsNetworking that you can reason about, not recite: IP addressing, DNS, DHCP, ports, and what a normal handshake looks like in a packet capture. Get fluent enough on the Linux command line to grep and pipe without looking things up, and learn to navigate Windows Event Viewer. Milestone: capture your own traffic in Wireshark and explain a DNS lookup end to end.
Month 2Security BasicsAttack vectors — ransomware, phishing, brute force, credential reuse — studied through what each leaves behind rather than how each works. Get familiar with the ATT&CK matrix as a reference you look things up in. Begin CompTIA Security+ preparation. Milestone: for three techniques, name the log source that would catch each.
Month 3SIEM MasteryPick one platform (Wazuh, Elastic or Sentinel’s free tier) and stand it up on your virtualisation host. Ingest from at least two hosts. Milestone: answer “which accounts authenticated to this machine in the last 24 hours” with a query you wrote, not a dashboard someone else built.
Month 4Active DefenceExpand the lab. Run Atomic Red Team techniques, find the resulting events, and write correlation rules that catch them. Then try to evade each rule. Milestone: one written rule, plus a paragraph on the conditions under which it stays silent.
Month 5Incident ResponseThe IR lifecycle applied to your own lab incidents, plus enough scripting in Python or PowerShell to parse logs and automate the enrichment you keep doing by hand. Sit CySA+ or an equivalent if the budget allows — it is optional, and the lab is not. Milestone: a full incident write-up including what the logs could not tell you.
Month 6Portfolio & PrepTidy the GitHub repository, rewrite the CV around what you built, update LinkedIn, and start applying — to MSSPs and SOCaaS providers as well as in-house roles. Expect rejections in volume; entry-level security postings routinely draw hundreds of applicants, and the ones that land are usually the ones with a referral behind them. Milestone: applications out, and at least one conversation with someone already doing the job.

Conclusion: Your SOC Career Awaits

Nobody arrives at this fully formed. The standard path is a lab that breaks weekly, a certification you were not sure was worth the money, and a detection rule that did not fire the first four times. That is not the rough version of the process. That is the process.

What separates the people who get in is rarely talent. It is that they kept going after the point where it stopped being interesting — the fortieth alert, the agent that connects and ships nothing, the rewrite of a rule that was almost right. Build the lab. Break it. Write the detections, then evade them. Document what you learned, including the parts where you were wrong, because that is the material that makes an interview go well.

Two honest caveats to end on. The demand is real, but it is not uniform: there is far more hiring at Tier 1 and in GRC than in the specialisations people actually want, so plan on the SOC seat being a route rather than a destination. And the shift work is a genuine cost, not a rite of passage — go in knowing that, choose the employer partly on how they run the rota, and you will last long enough to reach the roles this job opens up. That, not the entry salary, is the return.

Explore the rest of the blog for more cybersecurity career guidance. Get in touch if you are looking for mentorship, or if you would like to discuss strengthening your organisation’s security posture.


Share article

Subscribe to my newsletter

Receive my case study and the latest articles on my WhatsApp Channel.

Warning

Ask CyberROX AI