| Field | Detail |
|---|---|
| Platform | TryHackMe |
| Room URL | tryhackme.com/room/socroleinblueteam |
| Category | SOC / Blue Team |
| Status | ✅ Completed |
| Points Earned | 64 |
| Tasks Completed | 6 |
| GitHub File | labs/tryhackme/rooms/soc-role-blue-team.md |
| Live Website | tryhackme.html |
Discover security roles and learn how to advance your SOC career, starting from the L1 analyst. The room deepens understanding of the SOC team structure, defines the responsibilities of each role across the defensive lifecycle, and maps out realistic career progression paths from junior analyst to senior positions.
Worked through each task sequentially, building on the foundational SOC knowledge from Junior Security Analyst Intro. Focused on understanding the full scope of what a SOC team does collectively, how each role contributes to the defence mission, and what a realistic analyst career journey looks like through the TryHackMe SOC Level 1 path.
SOC team roles — detailed breakdown:
| Role | Shift Work? | Core Function | When Involved |
|---|---|---|---|
| L1 Analyst (Junior) | Yes — 24/7 | Initial alert triage, monitoring, first-line investigation | Every shift |
| Senior Analyst (L2) | Yes | Complex case handling, mentoring L1 analysts, escalation decisions | When L1 escalates |
| SOC Engineer | No | Tool maintenance, alert configuration, detection rule building | Ongoing, not shift-based |
| SOC Manager | No | Reporting to top management, team coordination, process ownership | Ongoing |
| Incident Responder | On demand | Major incident response, forensics, containment | Only during significant incidents |
Career progression paths from SOC L1: