FieldsCybersecuritySecurity Analyst
Security Analyst
Monitor, detect, and respond to threats before they become breaches.
Career
- Structure
- 8 modules, each ending in a milestone
- Proof
- Verified against real tasks from module 2
- Ends in
- A defended capstone and a high-assurance credential
The journey
Practised under observation
Systems, networks and the attacker's playbookThe ground an analyst reasons on: what normal looks like across systems and networks, and what attackers actually do, learned as recognisable patterns rather than trivia.Practised under observation
MilestoneKnows normal, recognizes the playbookNormal is described concretely enough that a deviation stands out, and an attacker's likely moves are mapped to the specific records each would leave behind.
From here, milestones are verified rather than practised.
Verified against a real task
Telemetry, log analysis and the monitoring platformReading the machine's account of itself, with log sources understood at the field level and the monitoring platform operated as an investigative instrument.Verified against a real task
MilestoneFinds the answer in the dataQuestions get answered by query rather than by guessing, a timeline holds together across sources and time zones, and the benign reading of the evidence gets the same attention as the alarming one.
Triage: deciding correctly under volumeThe seat's daily reality and its hardest skill: more alerts than hours, and the judgment to spend attention where it matters without missing the one that counts.Verified against a real task
MilestoneRight call, consistently, under loadThe last alert of a shift gets the same method as the first, and the reason one was escalated while an identical-looking one was not is written down rather than felt.
Investigation and digital forensics fundamentalsFollowing the trail to a defensible conclusion, with forensic fundamentals done properly and the scope question that decides whether a breach is actually contained.Verified against a real task
MilestoneInvestigates to a defensible conclusionAn investigation ends at the real scope rather than the convenient one, the record is protected before anything touches it, and the timeline names its own gaps.
Threat hunting and intelligenceLooking for what no alert reported: hypothesis-driven hunting, intelligence used rather than collected, and the scripting analysts actually need, taught from zero.Verified against a real task
MilestoneHunts with a hypothesis, automates the repetitiveEvery hunt states its hypothesis before it starts, and a hunt that finds nothing still leaves behind a detection, a coverage finding, or a documented negative.
Incident response operationsWhen it is real: the response executed under pressure, containment weighed against evidence, and the communication that keeps an organisation coordinated while it happens.Verified against a real task
MilestoneResponds under pressure, coordinates the roomContainment is weighed against the evidence it would destroy, and the incident does not close until the way in has been found.
Operating the detection functionMaking the operation work as a system, with metrics that mean something, a working loop with the engineers who build the detections, and automation that returns analyst hours.Verified against a real task
MilestoneRuns the operation, closes the loopWhat this operation cannot see is said plainly, the detections that waste analyst time go back to their engineers as named cases rather than as complaint, and measurement improves the operation instead of ranking the people in it.
The Security Analyst in the organizationSustaining accuracy and credibility: the human realities of a monitoring seat, the communication that gets action, and the career this path actually leads to.Verified against a real task
MilestoneCredible, sustainable, and moving forwardThe people who must act do so because your escalations have been sound, and an action beyond your authority gets escalated rather than taken.
- Capstone
An operation that catches the real thing
A complete security operations engagement in an environment with real adversary activity, worked under observation on authorised systems throughout, from a baseline and a threat profile through a triage shift, a full investigation, a set of hunts and a live incident response to the operational and professional layers of the seat.
DefenceYou walk an instructor through your own judgments: what normal was in this environment and how you knew, where your timeline has gaps, what you protected before you shut anything down and why in that order, and where your own judgment turned out wrong and whether the decision was still correct. The credential is not awarded if you cannot account for your own work.
- Credential
High-assurance credential
Evidence that you can decide correctly under volume and investigate to a conclusion an organisation can act on. It does not claim seniority, and it does not oblige any employer to accept it.
What is not live yet
The desktop app, consent-based observation, scoring, and credentials are in development. Nothing here implies they are live yet.
Get early access