Learn Computer Stuff
Home / Cybersecurity / Security Analyst
Cybersecurity

Security Analyst

You work out what an attacker did, or is doing, and write it up so someone can act.

No degree needed Medium. The tooling is learnable; the investigative habit takes practice.


Can I actually do this?

Reachable without a degree, usually via IT support or networking rather than directly. Closely related to the SOC analyst route — that one is the shift-based entry point, this is the broader analysis role.

Who it suits. People who chase loose ends and can write clearly under time pressure.

Runway. Realistic from help desk or networking plus deliberate lab practice.

Coming from another job?

Coming from help desk, networking or a SOC shift? All three are recognised routes into this work. SOC Analyst Help Desk / IT Support Network Administrator

Also advertised as

  • Information Security Analyst
  • Cyber Threat Analyst
  • Incident Analyst
  • Blue Team Analyst

The route

Four stations, in order. Each one is a thing you finish before the next matters.

  1. Station one

    Learn it free

    Only the best few, deliberately. Every one of these is free to use — the pill on each card says exactly what is and isn't free.

    MITRE ATT&CK

    Free to learn · no certificate

    The shared catalogue of attacker techniques, free and open. It is the vocabulary security teams and reports actually use, which makes it the highest-leverage thing to learn early.

    CISA — cyber threats and advisories

    Free to learn · no certificate

    Current advisories from the US cyber defence agency, free and public. Reading real advisories teaches the shape of an incident better than a course.

    Professor Messer Security+ SY0-701 full video course

    Free to learn · no certificate

    Free course covering the current Security+ objectives. The course is free; the exam is a separate paid purchase.

    See the full catalog in the explorer →

  2. Station two

    Attest strategically

    Security+ is the recognised entry credential here, same as for the SOC route. Buy it when you can also show investigation write-ups — the certificate alone competes with thousands of identical CVs.

    CompTIA Security+

    Free to learn · paid certificate Recognized

    The honest cost
    Cost$439
    Validity3 years.
    Renewal50 continuing-education units plus about $50/yr (~$150 per cycle), or renew automatically via a higher certificate such as CySA+, PenTest+ or SecurityX.
    AssessmentProctored exam — 90 questions, 90 minutes, pass mark 750/900
    ProctoredYes
    Verify viaCredly
    Cost per active year$196/yr(439 + 150) ÷ 3

    Named repeatedly as the foot-in-the-door credential for defensive security roles, and used as a DoD 8570 baseline.

    Read this before you buy

    This is a worked example of why we date everything: an apparent three-way price conflict was really one price change with stale copies downstream.

    · Official page

  3. Station three

    Prove it

    A certificate says you passed a test. These say you can do the job.

    An investigation mapped to ATT&CK

    Investigate a simulated incident and write it up using ATT&CK technique names. Speaking the shared vocabulary is what makes a write-up usable to a team.

    A detection you wrote and tested

    Write a detection rule, trigger it deliberately, and show it firing — plus what it misses.

    A threat brief from a real advisory

    Take a current CISA advisory and turn it into a one-page brief for a non-technical manager. That translation is most of the job.

  4. Station four

    Get hired

    Search these exact titles

    • security analyst
    • information security analyst
    • cyber threat analyst
    • incident analyst

    Who hires for this. Managed security providers, in-house security teams, government contractors, financial services and healthcare.

    Write-ups in shared vocabulary travel further than tool familiarity, because they land in language the hiring team's own reports already use. That is our reasoning, not a hiring statistic we have verified.

    On salary

    We don't publish salary estimates. Numbers copied between blogs drift from reality, and a wrong number costs you real negotiating power. When we have a verified public source, it goes here with its date.


Where this route continues

· How we verify