Passer au contenu

FieldsCybersecuritySecurity Analyst

Security Analyst

Monitor, detect, and respond to threats before they become breaches.

Career

Structure
8 modules, each ending in a milestone
Proof
Verified against real tasks from module 2
Ends in
A defended capstone and a high-assurance credential

Get early access

The journey

  1. Practised under observation

    1. Systems, networks and the attacker's playbookThe ground an analyst reasons on: what normal looks like across systems and networks, and what attackers actually do, learned as recognisable patterns rather than trivia.Practised under observation
      MilestoneKnows normal, recognizes the playbook

      Normal is described concretely enough that a deviation stands out, and an attacker's likely moves are mapped to the specific records each would leave behind.

  2. From here, milestones are verified rather than practised.

    Verified against a real task

    1. Telemetry, log analysis and the monitoring platformReading the machine's account of itself, with log sources understood at the field level and the monitoring platform operated as an investigative instrument.Verified against a real task
      MilestoneFinds the answer in the data

      Questions get answered by query rather than by guessing, a timeline holds together across sources and time zones, and the benign reading of the evidence gets the same attention as the alarming one.

    2. Triage: deciding correctly under volumeThe seat's daily reality and its hardest skill: more alerts than hours, and the judgment to spend attention where it matters without missing the one that counts.Verified against a real task
      MilestoneRight call, consistently, under load

      The last alert of a shift gets the same method as the first, and the reason one was escalated while an identical-looking one was not is written down rather than felt.

    3. Investigation and digital forensics fundamentalsFollowing the trail to a defensible conclusion, with forensic fundamentals done properly and the scope question that decides whether a breach is actually contained.Verified against a real task
      MilestoneInvestigates to a defensible conclusion

      An investigation ends at the real scope rather than the convenient one, the record is protected before anything touches it, and the timeline names its own gaps.

    4. Threat hunting and intelligenceLooking for what no alert reported: hypothesis-driven hunting, intelligence used rather than collected, and the scripting analysts actually need, taught from zero.Verified against a real task
      MilestoneHunts with a hypothesis, automates the repetitive

      Every hunt states its hypothesis before it starts, and a hunt that finds nothing still leaves behind a detection, a coverage finding, or a documented negative.

    5. Incident response operationsWhen it is real: the response executed under pressure, containment weighed against evidence, and the communication that keeps an organisation coordinated while it happens.Verified against a real task
      MilestoneResponds under pressure, coordinates the room

      Containment is weighed against the evidence it would destroy, and the incident does not close until the way in has been found.

    6. Operating the detection functionMaking the operation work as a system, with metrics that mean something, a working loop with the engineers who build the detections, and automation that returns analyst hours.Verified against a real task
      MilestoneRuns the operation, closes the loop

      What this operation cannot see is said plainly, the detections that waste analyst time go back to their engineers as named cases rather than as complaint, and measurement improves the operation instead of ranking the people in it.

    7. The Security Analyst in the organizationSustaining accuracy and credibility: the human realities of a monitoring seat, the communication that gets action, and the career this path actually leads to.Verified against a real task
      MilestoneCredible, sustainable, and moving forward

      The people who must act do so because your escalations have been sound, and an action beyond your authority gets escalated rather than taken.

    1. Capstone

      An operation that catches the real thing

      A complete security operations engagement in an environment with real adversary activity, worked under observation on authorised systems throughout, from a baseline and a threat profile through a triage shift, a full investigation, a set of hunts and a live incident response to the operational and professional layers of the seat.

      Defence

      You walk an instructor through your own judgments: what normal was in this environment and how you knew, where your timeline has gaps, what you protected before you shut anything down and why in that order, and where your own judgment turned out wrong and whether the decision was still correct. The credential is not awarded if you cannot account for your own work.

    2. Credential

      High-assurance credential

      Evidence that you can decide correctly under volume and investigate to a conclusion an organisation can act on. It does not claim seniority, and it does not oblige any employer to accept it.

      See how proof works

What is not live yet

The desktop app, consent-based observation, scoring, and credentials are in development. Nothing here implies they are live yet.

Get early access