Every week someone asks what the job is really like once the training ends. So we asked two graduates working in security operations to describe a shift, hour by hour, with nothing tidied up.
The first hour is triage, not hacking
A shift opens with the queue that built up overnight. Most alerts are noise: a failed login from a director who is travelling, a scanner someone forgot to whitelist, a certificate that expired at midnight. The skill is deciding quickly which of the hundred can be closed and which two deserve an hour.
- Failed logins, clustered by user and location
- Endpoint alerts where the file hash is already known
- Anything touching a system that holds customer data
The middle of the day is writing
Nobody warns you how much of the job is writing. A good ticket explains what happened, what you checked, what you ruled out and what you recommend, in language a manager can act on. The analysts who get promoted are the ones whose tickets need no follow-up questions.
If I cannot explain the alert in three sentences, I do not understand it yet.
What the first six months feel like
Slow, then suddenly not. For the first month you check everything twice. By month three you recognise patterns and start noticing what is missing rather than what is there. That is the point the job becomes interesting.