July 28, 2026
Day 3: Inside the SOC — Where Security Actually Happens
The shift

By Temple
1 min read
The shift
Day 3 was about the Security Operations Center, the SOC. I'd heard the name before without really knowing what it meant. Now I do: it's the team that watches everything, catches the threats, and responds. The nerve center.
I'm keeping the course material to myself (it belongs to TechCrush), so this is the shape of the day, not the details.
What landed
Two things stuck.
First, the SOC isn't one job. It's layered. Different tiers, different responsibilities, from triaging the first alert to handling a full incident. There's a real structure to how a team defends an organization, and today I finally saw the shape of it.
Second, the part that actually got me: the analyst work felt familiar.
Before cybersecurity, I spent years doing data annotation. Labeling text, images, and audio. Reviewing datasets for quality and consistency. Catching the thing that didn't fit. I'd always filed that under "separate from real security work."
Turns out it's not so separate. A SOC analyst staring down a stream of alerts, deciding what's signal and what's noise, is doing a version of the same thing. Sit with the information. Spot the anomaly. Decide if it matters.
What I'm taking from it
I didn't expect an old skill to map onto a new field like that. It made Day 3 feel less like starting from scratch and more like rearranging what I already know.
Which is a relief, honestly. The field is huge, and any sign that I'm not starting at absolute zero helps.
Onward.
— Temple