Before you work in a SOC, Watch This. w/SOC Expert Brandon Poole

Поделиться
HTML-код
  • Опубликовано: 3 окт 2024
  • In this video, we interview Security Operations Center (SOC) expert Brandon Poole on what life is like in a SOC, how SOCs can differ, and what questions you should be asking in SOC interviews to make sure you are making a great career decision.
    This is arguably one of the most important/informative SOC videos on this channel.
    TIME MARKS:
    0:20 Show Intro
    2:52 Interview Start
    3:20 What is the difference between a runbook and a playbook
    5:20 How are SOCs treated like the helpdesk of cybersecurity?
    6:17 Why are tiered SOCs the old way of running a SOC and what is bad about them?
    8:03 What questions should you ask during a SOC interview to identify red flags?
    14:50 What are different types of SOCs?
    20:18 What are the challenges of not having an IT background and working in cybersecurity?
    23:05 How to avoid not being taken seriously?
    24:00 Real life SOC horror story
    36:19 GRC v. SecOps people
    39:28 Why is it ok not to evict a malicious actor in your network environment?
    44:37 Why do SOC analysts need to think slow and smooth?
    50:05 What is the value of detection engineering?
    📱 Social Media
    LinkedIn: / geraldauger
    Twitter: / gerald_auger
    RUclips: / geraldauger
    Discord: / discord
    Twitch: / gerald_auger_simplycyber
    🔥 My Curated Website of Free Cyber Resources
    SimplyCyber.io
    📷 🎙 💡 MY STUDIO SETUP
    📷 Camera / Video
    Sony Alpha a6400 amzn.to/2TZliEb
    Sigma 30mm F1.4 amzn.to/3hEJFA2
    Gonine AC-PW20 AC Adapter (for a6400) amzn.to/3wDZBqc
    Fotga 52mm Slim Fader amzn.to/3khne5w
    Boom Scissor Arm Stand amzn.to/3efSv5b
    Logitech C922 Pro Stream Webcam 1080P amzn.to/3i8AI0B
    BlueAVS HDMI to USB Video Capture Card 1080P amzn.to/3i5JAEk
    Anker USB C to HDMI Adapter amzn.to/3kjjoJ4
    60-Inch Lightweight Tripod amzn.to/36B5j1u
    5X 6.5ft Portable Green Screen Chromakey Collapsible amzn.to/3efW9Mp
    Glide Gear TMP100 Adjustable Teleprompter amzn.to/3B36DrZ
    🎙 Audio
    Blue Yeti Nano Premium USB Mic amzn.to/3efWcb3
    BOYA BY-M1 3.5mm Electret Condenser Microphone amzn.to/3AZzJIN
    Boom Scissor Arm Stand amzn.to/3efSv5b
    Neewer Professional Microphone Pop Filter Shield amzn.to/3ekdZOi
    💡 Lighting
    UBeesize 10’’ LED Ring Light amzn.to/3i23qAm
    Neewer Ring Light Kit:18"/48cm Outer 55W 5500K Dimmable LED Ring Light amzn.to/2U0slwo
    Fovitec 2-Light High-Power Fluorescent Studio Lighting Kit amzn.to/36zDS8A
    Neewer 2-Pack Dimmable 5600K USB LED amzn.to/3B0crCQ
    Neewer 480 RGB Led Light amzn.to/2Vzwmbf
    60-Inch Lightweight Tripod amzn.to/36B5j1u
    🧑🏻‍💻 Workstation
    2020 Apple Mac Mini with Apple M1 Chip amzn.to/3wybMVL
    Logitech MX Master 3 Advanced Wireless Mouse amzn.to/3xFCkWp
    Apple Magic Keyboard amzn.to/3ehMRiP
    Huanuo Dual Monitor Stand Mount amzn.to/3keFZqc
    Dell U2717D IPS 27" UltraSharp InfinityEdge Slim Widescreen amzn.to/36znqoG
    USB C to SD Card Reader amzn.to/2VG1RRd
    StarTech 2 Port USB C KVM Switchamzn.to/3efWoa7
    Toshiba Canvio Basics 1TB Portable External Hard Drive USB 3.0 amzn.to/3hZOK4A
    External Hard Drive Portable Carrying Case amzn.to/3r62XRM
    Mountable Surge Protector Power Strip with USB 5 Outlets 3 USB Ports amzn.to/3wDmlqv
    🥼 Raspberry Pi Lab
    Raspberry SC15184 Pi 4 Model B 2019 Quad Core 64 Bit WiFi Bluetooth (2GB) amzn.to/3i61EhI
    Miuzei Case for Raspberry Pi amzn.to/2Vzyrnz
    Micro Center 32GB Class 10 Micro SDHC Flash Memory Card with Adapter amzn.to/3B0Qm6X
    Micro HDMI to HDMI Cable 6FT amzn.to/3ekpiG3
    👉 Some product links are affiliate links which means if you buy something SimplyCyber receives a small commission (but it all costs the same to you, so consider it supporting the channel 😉 )
    🙌🏼 Donate
    Like the channel and got value? Please consider supporting the channel
    www.buymeacoff...
    😎 Merch 😎
    👉🏼 SimplyCyber Branded Gear: teespring.com/...
    🎥 Livestreams are produced through StreamYard.
    $10 credit using my referral link below if you ever upgrade to pro plan.
    streamyard.com?pal=6534222448689152
    Disclaimer: All content reflects the thoughts and opinions of Gerald Auger and the speakers themselves, and are not affiliated with the employer of those individuals unless explicitly stated.
    #cybersecurity#Cyber #InformationSecurity #Risk #Privacy #getAjob #cybersecurity #infosec #career #selfdevelopment #continuedEducation #entrylevel #careergrowth #security #tech #technology #security #simplycyber
  • НаукаНаука

Комментарии • 174

  • @gilbertsabina4944
    @gilbertsabina4944 3 года назад +69

    Possibly one of the greatest interviews ever that give the audience a raw insight into the SOC world from a true real life perspective. Gold!

    • @SimplyCyber
      @SimplyCyber  3 года назад +12

      Brandon brings the heat. I'm actually carving up another video from that interview for a part 2.0. He I had talked for over 3.5 hours during this session. It was epic.

  • @LawStudent2014
    @LawStudent2014 3 года назад +10

    Gerald, I have been watching, stopping, and researching based upon this video...it is The Blueprint for not only preparing for the field but also preparing a potential SOC Analyst to research companies to target and interview. Breath of fresh air, solid!

  • @Hemoglakbin
    @Hemoglakbin 4 месяца назад

    I don't think I ever left a comment, but this is one of the videos that introduced me to Simply Cyber. I appreciate it even more after so many months getting to learn about the field.

  • @jamealjordon1376
    @jamealjordon1376 Год назад +2

    After a few minutes, I put on popcorn for this one. A sobering, candid, rose-colored glasses off, entertaining eye opening interview in SOC work environments.

  • @TechTualChatter
    @TechTualChatter 3 года назад +13

    He hit the nail on the head when he said sometime they have SOC structured like helpdesk. Playbooks should not be step by step because they end up hindering an analyst more than it helps them. They should be very basic in nature to provide a guideline on how to handle certain alerts. I’ve been seeing your content on LinkedIn and didn’t know I wasn’t subscribed yet

    • @SimplyCyber
      @SimplyCyber  3 года назад +2

      Thanks for the sub. Not sure if you saw but last week I had brandon on again w two other experts for a panel on soc skills. May be of interest. ruclips.net/video/le0hXgZmn1U/видео.html

  • @ceooftorment927
    @ceooftorment927 Год назад +5

    SOC analyst is where I want to get a starting point. It seems easy getting to know a lot because of the amount of videos there are on it, but because of the plethora of videos, it's hard to know a true starting point. This video seems like the best starting point for me. Love it.
    I have pretty basic IT experience between work/school. I actually work where I went to school lol. I'm pretty much the grunt, but it's great because I'm tagging along with the hardware support, network support, and the dude maintaining the wifi, firewalls,etc. I even got word from my boss that he'll be getting me more involved with security tasks!

    • @SimplyCyber
      @SimplyCyber  Год назад +2

      nice. lean into that and try to leverage every opportunity to 'do' security stuff. great for the resume and finding out what you like and dont'

  • @shaunherrera7492
    @shaunherrera7492 2 года назад +2

    This was locker room talk! I didn't know stuff this raw and real was on youtube. Thanks a mil Mr. Auger and Mr. Poole!

  • @JimmyBeans84
    @JimmyBeans84 Год назад +4

    I would love to see you interview an architect and talk about what it takes to get into that field. Awesome video, as always!

  • @JohnReedMan88
    @JohnReedMan88 Месяц назад

    Dude reminds me of John Strand. I found some other videos with him on your channel and elsewhere but I cannot get enough. You really need to have him on again.

  • @getoutmore
    @getoutmore 2 года назад +4

    As someone wanting to move into SOC from SysAdmin I really really enjoyed this. I just freaking love your content so much Gerald, thank you honestly :)

    • @ctjmaughs
      @ctjmaughs 2 года назад

      I would jumping from sysadmin is leap. It will definitely help you but keep in mind what motivates you, if you are someone that needs to fix things then the SOC is not going to work out. Hired a few sysadmins that didn't realized the Soc would never configure the customer's equipment and left after giving it a try for about 6 months. Answer that question about what you are looking for and maybe the SOC life might line be for you.

  • @Jotin8664
    @Jotin8664 3 года назад +7

    Just need to say that the content in this video is absolutely amazing. This is something I have saved for future reference as I progress in my career

    • @SimplyCyber
      @SimplyCyber  3 года назад +2

      Thank you! Brandon is an exceptional ambassador for the soc

  • @kristel3191
    @kristel3191 3 года назад +7

    Wow this hit so many good points especially the struggles of working in MSSP and working in tiered SOCs.

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      Yeah, the reality is different from the text book (or at least has more dimensions than a text book). Thanks for watching.

    • @ctjmaughs
      @ctjmaughs 2 года назад

      Some good questions an analyst should asks on these job interviews

  • @thefrub
    @thefrub Год назад +1

    Thank you for this great insight! I'm new and I'm trying to avoid the common mistakes. At the end of the day we have to remember that IT/Security/Compliance is a cost center, and our job is to help the business function and balance risks... without the business, we don't get a paycheck

  • @billymat883
    @billymat883 3 года назад +4

    One of the best videos that's give you a full understanding as SOC analyst 👍🏾

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Billy! That’s a heartwarming comment. Thanks for letting me and community know. Awesome!

  • @glum_hippo
    @glum_hippo 8 месяцев назад

    This is gold. Thanks for putting together this interview and the whole playlist really.

  • @wendy_113
    @wendy_113 Год назад +1

    I really enjoyed this so much I'm looking into cybersecurity where I would belong in my first year. I learned so much thank you!

  • @ctjmaughs
    @ctjmaughs 2 года назад +9

    Pretty good video. I am a Soc manager at a MSSP and can definitely relate to what was talked about

  • @marcschweiz
    @marcschweiz 3 года назад +6

    This was honestly so amazing. I learnt so much in such a short span of time

  • @zachzabel148
    @zachzabel148 2 года назад +2

    Dudes thanks for this interview definitely helps with routing a career into SOC. Was already thinking about doing help desk for 2 years after school, now I know that is probably the best way forward in order to understand things, hands on, and be able to develop into a SOC analyst.

  • @LOSisBEAST2
    @LOSisBEAST2 3 года назад +16

    That was a good ass video. Like damn the info he dropped in that was priceless

    • @SimplyCyber
      @SimplyCyber  3 года назад +4

      I'm glad you agreed. He dropped a lot. This whole conversation happened because we were filming for something else (Lima Charlie EDR), and the app hung and we were just kind of chatting killing time and I was like 'WOW this is great stuff', Carved it out and made it its own video.
      What was the most interesting thing you got from the video?

    • @LOSisBEAST2
      @LOSisBEAST2 3 года назад +1

      @@SimplyCyber That's super convenient. I would say the way he described the whole tiered vs free flow soc was great. The pro's and con's were well thought of and how there's different type of SOCKS. I feel like you could even say the same for NOC's.

  • @TryGoFurtherAndSucceed
    @TryGoFurtherAndSucceed Месяц назад

    Great interview! thank you for the upload!!

  • @phoenix14830
    @phoenix14830 2 года назад +2

    This was awesome. Thank you so much for the content you provide to the community. After each video, I always have a bunch of good notes and tools.

  • @deveau145
    @deveau145 6 месяцев назад

    My new headline, "I want to get into a SOC." Good information, I can relate to the different types of SOC's and great questions for an interview.

  • @bobanmilisavljevic7857
    @bobanmilisavljevic7857 Год назад +1

    Thank you for planting the SOC seed Gerry. I appreciate your guidance and take it to heart
    💪🧙‍♂️⌨️

  • @jamelappsolute457
    @jamelappsolute457 Год назад +1

    Great interview, a ton of insight. Branden was giving me Seth Rogen vibes. Great stuff!

  • @stefanforest7582
    @stefanforest7582 3 года назад +3

    This is a really really good video about a SOC. It is long, but worth to watch multiple times.

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      I agree its longer format than most of my vids, but it was so much content I cut it down as best i could. The SOC life piece was about 1.5 hours before I started cutting it back. Maybe I should release a directors cut version with no edits. LOL.

    • @kristel3191
      @kristel3191 3 года назад +1

      Gerald Auger - Simply Cyber would definitely be inferested on watching the whole thing!

  • @WILBER117100
    @WILBER117100 3 года назад +2

    Exactly what I was waiting!

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Thanks Wilber! Hope you find it worth your time and meets your expectations. Let me know what you found most surprising from Brandon.

  • @jcz4035
    @jcz4035 Год назад

    Completely agree with Brandon at 18 min…treat the interview as two way. Don’t be hesitant to treat it as a conversation.

  • @ug1502ez
    @ug1502ez 2 года назад

    I've always liked you and your channel Gerald, but now I like you even more. Thanks for this video

  • @cheftp404
    @cheftp404 3 года назад

    Ok, this was really really good! Sometimes the truth hurts, but you gotta hear it. Great insights!

  • @rayancrasta7460
    @rayancrasta7460 3 года назад +1

    Was Waiting for this exact video ❤️

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      Thans Rayan. I hope you enjoy it and find the same value that I did from Brandon. It was awesome.

  • @jimmyasbell261
    @jimmyasbell261 3 года назад +3

    This is solid gold. Well done! Subscribed & Liked!

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Welcome aboard! Thanks Jimmy. Brandon is awesome.

  • @hankmoody5241
    @hankmoody5241 3 года назад +1

    Great video and channel! You’ve helped me so much. Keep up the great work.

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Glad to help! I will! Thanks.

  • @crowbar9566
    @crowbar9566 2 года назад +4

    I'm a 44 year old career changer looking to get into InfoSec and who has an interview for a SOC Analyst role. This is seriously putting me off 😂😂😂

    • @SimplyCyber
      @SimplyCyber  2 года назад

      Better to find out now then put in the work to get there and find out

    • @crowbar9566
      @crowbar9566 2 года назад

      @@SimplyCyber I think your guy is being overly negative. A lot of other videos say its a good place to start.

    • @SimplyCyber
      @SimplyCyber  2 года назад +3

      @@crowbar9566 I think soc is an excellent place to start but there is alert fatigue and mental heath challenges soc analyst face. Check out the “all things soc analyst” video on the channel w Eric Capuano, another great explainer vid on what the soc analyst role is. 2nd most viewed video on the channel

    • @crowbar9566
      @crowbar9566 2 года назад

      @@SimplyCyber I'll take a look, thanks Gerald. Love the channel btw.

  • @stonesteppin
    @stonesteppin 3 года назад +2

    Great interview and content!!

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      Thank you so much Shanna! Brandon was awesome to have on the show.

  • @jacrispy219r5
    @jacrispy219r5 9 месяцев назад +1

    Not going to lie. I was hoping to finish my Google cyber perfesional certification and land a job. Now I’m worrying it’s not enough.

    • @celconicuzn
      @celconicuzn 9 месяцев назад

      Invest your time into building a good portfolio, continuing to do practical labs (document them into your portfolio), and reach out to companies/recruiters.
      If you follow this plan for long enough, you are going to get hired. Prove that you are passionate to the right people. Don't give up hope!

  • @SilentKoala
    @SilentKoala 3 года назад

    PREACH! Excellent interview

  • @ShadowF305
    @ShadowF305 Год назад

    Just got an offer for a SOC position so i needed to see this . Thank you!
    Also the guest speaking sounds like Seth Rogan 😂

    • @SimplyCyber
      @SimplyCyber  Год назад

      Congratulations! And Brandon is awesome

  • @vak21
    @vak21 3 года назад +2

    this was so good!
    I loved the frank conversation with Brandon.

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Thanks Jose. He tells it how it is. What was your favorite part?

    • @vak21
      @vak21 3 года назад +1

      @@SimplyCyber well asking during the interview for the retention rate after one year ^^
      also asking for career plans during the interview, for moving from soc1 to soc2 and soc3... or people looking down at soc analysts :(

    • @SimplyCyber
      @SimplyCyber  3 года назад

      @@vak21 Those were both great points. The retention rate one can't be sugarcoated either.

  • @metaparcel
    @metaparcel 3 года назад +3

    Mr. Poole likes to rip a bong or two from time to time.

  • @roncall6065
    @roncall6065 Год назад

    They don’t know how to think pure gold 💎

  • @DocFleg
    @DocFleg 2 года назад +1

    Super valuable. Thank you, guys. :)

  • @Guilhermeabcd
    @Guilhermeabcd 3 года назад

    That's pure gold. Thanks!

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      You bet! Brandon is awesome.

  • @lufothealien9387
    @lufothealien9387 3 года назад +2

    One major issue I found whilst working in a SOC environment is the fact that you never feel like you completed something. I you are a person that would like to have goals to complete, SOC unfortunately is not for you. I found myself getting quite depressed because there isn't really a reward based system like other jobs were you get a deadline to complete something and then having the satisfaction of completing it. It is kinda a continuous state of uncertainty. I do not know if this is the case with all SOCs but it was the case for me.

  • @ardithereqi8459
    @ardithereqi8459 2 года назад

    Such a great talk!

  • @Fitnessdealnews
    @Fitnessdealnews Год назад

    Awesome

  • @MadG0dSecurity
    @MadG0dSecurity 3 года назад

    This video helped a lot! Thanks for this!

  • @dannyfitz6115
    @dannyfitz6115 3 года назад +1

    Wow! This is amazing!

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Thanks Danny, Brandon is legit legit

  • @TheCloudsMySofa
    @TheCloudsMySofa 3 года назад +1

    awesome vid...learned a LOT.

  • @michelledmiller5120
    @michelledmiller5120 3 года назад +1

    Enjoy your channel, learning so much and a-lot of my questions are being answered 🙌🏼🙏🏼. I am new to cyber security, And 💯 interested in Digital Forensics, my classes start in November( National University) Do you have a book that you would recommend? And my favorite Burbon Knob Creek & Cooper lol

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Thanks and good bourbon choice. I have Real Digital Forensics by Beitjlich and Jones but its a bit dated (2007) it is good text though. I'd suggest engaging some DfiR folks on LinkedIn about what books they think could be good.
      its tricky, because DF gets very specific very quick. Like do you want to just know high level, or understand how to image boxes, how to dead disk imaging, how to do chain of custody, how to make your own DF tools, how to do live imaging, etc.
      I have a video on the channel from Erik Venema around digital forensics. Its more geared toward law enforcement officers transitioning into digital forensics as a 2nd career, but hes easily the most focused professional on DF ive had on the channel. May want to check out that video, and Erik provides his email address in it and asks anyone to contact him with questions. Could be another avenue to pursue. Best wishes Michelle.

  • @The_Corner_Of
    @The_Corner_Of 2 года назад

    What they said. The Boys Season 3,now. Great series

  • @shesaidwhatmonkey
    @shesaidwhatmonkey 2 года назад

    This was a great video.

  • @roncall6065
    @roncall6065 Год назад

    Help desk of security 🔥

  • @ninjatendo8199
    @ninjatendo8199 2 года назад

    awesome! thank you

  • @nithinrkan
    @nithinrkan Год назад

    Great insights

  • @debwigley4660
    @debwigley4660 3 года назад +1

    Look at that lovely background video you have there! ;)

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      Black Hills Infosec is always bringing the heat. Be sure to check them out --> ruclips.net/channel/UCJ2U9Dq9NckqHMbcUupgF0A

    • @bobbynewport3332
      @bobbynewport3332 3 года назад +1

      DEBBBBBB 💪🏾💪🏾💪🏾BHIS IS MY RELIGION

  • @sds123faf
    @sds123faf 2 года назад

    So much venting, I do not know if Brandon needs a holiday or if he is really passionate about his job 😄

  • @jendychijasper8743
    @jendychijasper8743 3 года назад

    Thanks for the upload....

    • @SimplyCyber
      @SimplyCyber  3 года назад

      You're welcome; Thanks for being part of the community.

  • @munud23
    @munud23 3 года назад

    Thank You for this

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      You're welcome! Brandon brought it this episode. It was actually part of a much larger Lima Charlie EDR video series that will be coming out.

  • @mitchevergreen
    @mitchevergreen 3 года назад +3

    You have Jason Blanchard and other WWHF folks on your screen at the end :D

    • @SimplyCyber
      @SimplyCyber  3 года назад +2

      Yup. They were running a solarwinds briefing I believe. I always have another Cybersecurity RUclips channel running in my videos. I try to reference them for socializing them, but sometimes forget. Theres so many great folks out there sharing cybersecurity education/knowledge I like to make sure they get shared. :)

  • @marbanrivera
    @marbanrivera 3 года назад

    I learned a lot on this vid..thanks!

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Glad it was helpful! What was the most surprising thing you took away Marvin?

  • @dawsonsschittcreek5395
    @dawsonsschittcreek5395 3 года назад +2

    I'm thinking of a career change from a more of a physical security role (law enforcement w/Bachelor's in Pre-Law) into cybersecurity. I was looking at Penn State's online cybersecurity program. The kicker is I am 41 years old, and would be graduating at roughly 43 years old. My question is, am I too old to attempt this career change & enter the world of cybersecurity? Thank you in advance for your response - it is greatly appreciated!

    • @SimplyCyber
      @SimplyCyber  3 года назад +2

      You are not too old. You may have to realign expectations as you may have a reduction in salary, but we are in need of cyber talent. If you can do the job great!,

    • @RJ-is9ko
      @RJ-is9ko 2 года назад

      I dont feel like age is shunned upon in the cyber field as it is in the soft dev field. I think you're fine.

    • @TheMocutMiester
      @TheMocutMiester 2 года назад +1

      Never too old. If you have the mind and willpower, it can be done

  • @danieldejager1847
    @danieldejager1847 2 года назад

    I really dislike it when SOC analysts asks the question - tell me what this attack does....and what that attack does.....should we start memorizing the MITRE ATT&CK framework techniques? I decided not to answer that question when it is asked, instead I reply why don't you ask me how I should approach a particular attack.

  • @toddboucher3302
    @toddboucher3302 2 года назад

    Question then I passed my CNA I think it was 2015 maybe 16 I was going to go take it again but with the new Cisco I didn’t think it was really necessary so I kind of went through studied a little bit of the information and moved on finishing up some Linux studies right now but I was going to jump into some stuff on him off SOC should I go back and actually get a cc NASA the latest one or an NP maybe or just keep plugging away and security right now I manage a real lot large telecommunication system

  • @pranavrastogi8549
    @pranavrastogi8549 3 года назад

    Informative 👍

  • @Victoria-cl5of
    @Victoria-cl5of 3 года назад

    Brandon mentioned different good and bad SOC positions with diff companies. What good companies does he recommend for entry level (or any entry level job)?

    • @SimplyCyber
      @SimplyCyber  3 года назад

      I'll have to ask him. He works in that space and may not want to call out a company by name as good/bad.

    • @Rob-iy2rt
      @Rob-iy2rt Год назад

      Just get a job, continue to practice and study and then move companies as you move up. You really shouldn't stay in one specific SOC longer than 5 years. If that's you, you haven't grown.

  • @FranklinHicks-qs4gs
    @FranklinHicks-qs4gs Год назад

    Mr Poole needs to learn the magic of shampoo !!!

  • @bullethead1953
    @bullethead1953 3 года назад

    So good.

  • @ItsNerradT
    @ItsNerradT 10 месяцев назад

    I could not help but think "Seth Rogan vibes" throughout this entire segment

  • @EbenezerYiadom
    @EbenezerYiadom 3 года назад

    Thank you❤️❤️❤️

    • @SimplyCyber
      @SimplyCyber  3 года назад

      You are so welcome. Hope you found value. What was the most surprising thing Brandon shared with you?

    • @EbenezerYiadom
      @EbenezerYiadom 3 года назад

      @@SimplyCyber Definitely found value, the most surprising one was when he mentions- SOC analysts are like Help Desks of Cyber security. I was like oops hehhehe, ...and a whole lots of good ones he shared as being limited and not doing much in roles like some Help Desks

  • @hankmoody5241
    @hankmoody5241 3 года назад +2

    I love the aspects of a SOC Analyst as a starting point for myself. My passion is for security infrastructure though. Do you think a SOC Analyst can effectively transfer to a Security Engineer and then to Security Architect? Or possibly SOC Analyst directly to Security Architect?

    • @SimplyCyber
      @SimplyCyber  3 года назад +4

      Absolutely. A SOC analyst will develop a realization of how data flows around network and where endpoints are with respect to segmentation, and all the challenges associated with storing, enriching, de-duplicating, and coorelating logs. Its a solid path into architect.

    • @hankmoody5241
      @hankmoody5241 3 года назад

      @@SimplyCyber I greatly appreciate your response and time. Especially knowing that you actually are a Security Architect.

  • @VicHobgoblin
    @VicHobgoblin Год назад

    Hi Gerald, they offered me a work as MSS Operator (managed security services operator). I think i did not understood what they really do, they were a bit cold in giving info (maybe for security reasons? ). What i know is that the company is well known in the cyber security enviromnent where i live. Do you have any idea about what a mss operator could do? Thank you so much for your help!

  • @user-xz4oc6mr6i
    @user-xz4oc6mr6i Год назад

    The issue with the IT is and because it's such a big and dynamic field, there is no proper path to master it and therefore it became a f..... Wild-Wild-West. See all the certifications existing today. So u then almost always end up with people coming from university with zero to none practical or even theoretical experience but a Master degree, because the company likes it as it elevates their reputation and therefore hires them. This people will then get some higher IT positions such as SOC Analyst, and start to make decisions. And as we all know, where is no knowledge, there is place for arrogance to grow. Therefore I think in today's world, IT suffers pretty much from wrong educated people being hired for the wrong positions, just because CEO's and HR people doesn't want to know it better.

  • @PetritK10
    @PetritK10 2 года назад

    Which cert gives you knowledge to start as SOC Analyst

    • @SimplyCyber
      @SimplyCyber  2 года назад

      I’ve heard Cysa+ is good for that, but doing labs like RangeForce and blueteamlabs.online are going to go a long way for practical skill development

  • @nitindubey5472
    @nitindubey5472 3 года назад +1

    great video amazing what do you think is it good idea to start career in GRC audit as fresher what i have heard from most of guys in cyber audit nobody hires fresher and what skills or certification must for get into cyber audit having ISO 27001 helps or CEH along with ISO 27001 is good idea.

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Im confused by your post, specifically what you mean by 'fresher', but i will say if you want to get into audit get familiar with standards like ISO 27001 or (and Id say start here) NIST CSF. Lot of orgs are adopting CSF so it will need auditting. Also CISA is the cert to go for if you want to go audit. Thanks for watching.

    • @nitindubey5472
      @nitindubey5472 3 года назад

      @@SimplyCyber fresher who is just starting career in cyber field CISA is for 5 years of experience guys.

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      @@nitindubey5472 ok gotcha. Sec+ is a solid start Cert to open doors. Really getting familiar with frameworks or learning regulations that would apply. I.E HIPAA for healthcare, NIST CSF, PCI (for credit card handling companies). etc. You basically need to understand the standards so when you audit you know the scope. Also a solid understanding of IT concepts is important so when you are checking if a control is in place or not, you dont get misled by a response from an engineer during interviews on control implementation.

    • @nitindubey5472
      @nitindubey5472 3 года назад

      @@SimplyCyber it would be great if you could recommend some good source for audit GRC because of youtube and google also most of things are related with VPAT side or SOC related .
      does interview expect having ISO 27001 certificate must like spending 500dollar for ISO is good option .

    • @SimplyCyber
      @SimplyCyber  3 года назад

      @@nitindubey5472 in the US iso 27001 isnt very prevalent. CHeck this out; this is guidance on how to build an assessment plan for a fisma audit; its basically a step-by-step guide on executing a cybersecurity audit (against NIST 800-53), but the steps transfer across any standard: csrc.nist.gov/publications/detail/sp/800-53a/rev-4/final

  • @NeoKurow
    @NeoKurow 8 месяцев назад

    That room is a mess and that is because this guy doesn't have the time to clean it and keep it in order. That is a HUGE red flag about the SOC analyst life!

  • @susansree7675
    @susansree7675 3 года назад

    What are the good positions in soc?

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      Depends on your interest. Detection engineer seems like a lot of fun. Forensics if you like to go heads down on intricate projects.

  • @jovictor3007
    @jovictor3007 Год назад

    Why do you expect a tier 1 soc analyst to be giving you recommendations as a system admin or network admin ? That is not his job , do your job ! , your are basically asking a tier 1 whose main job is triage to do your system and network admin job , then what are you being paid for ? And If for some reason they give you recommendations and you decide not to apply them because it is worth the risk, that is your problem, they did their job if an incident happens you will just have to explain alone to your bosses how it was a risk worth having.

    • @xk964264
      @xk964264 Год назад

      I was thinking the same, yeah he’s correct but what’s good I’m new trying to do my job and I’m here not saying I know everything, if this guy is looking down on me like that. Time to move on to a better working environment.

  • @ctjmaughs
    @ctjmaughs 2 года назад

    Those 6-9 month boot camps have lead to better hires than those cyber degrees of late

    • @SimplyCyber
      @SimplyCyber  2 года назад +1

      practical skills are gold right now. the trick is weeding out legit bootcamps vs. cash grab mills

    • @levalagana9276
      @levalagana9276 2 года назад

      @@SimplyCyber please can you recommend some legit boot camps?

  • @donteatthepaint8412
    @donteatthepaint8412 2 года назад

    #SOCLIFE

  • @omniinvestments7128
    @omniinvestments7128 3 года назад +1

    BRANDON:
    "We need a *Threat Intelligence Team* as well...!!!!"
    - some golfing CSO
    ME: LOLz

  • @Rob-iy2rt
    @Rob-iy2rt Год назад +2

    Unfortunately, I find this guy obnoxious. Most of what he said, especially about the penetration test experience, makes it seems like he thinks he's a know-it-all and probably even exaggerates a bit. The pen tester told him the vulnerability. He gave a suggestion, but ultimately, it is up to the company what they want to do with the report that was given. Also, his comments about where to start are completely biased. Like he even admitted, there weren't SOCs when many of the so-called security experts started. They started as something else, meaning they started as a know-nothing help desk. That's basically what he said tier 1 SOC analyst is. So basically it's the same start. The difference is, now there are SOCs, and many of them need tier 1 analyst. If they don't give you support with further education, you can do it yourself. That's exactly what you would have had to do on the help desk. Personally, I wouldn't want to work with him, because he sounds a bit toxic himself. There are plenty of teams out there where you can start with your certs and do well. But the key is continuous education. Stay the course. Don't let people discourage you.
    The video got better toward the end when they started talking about slowing down.

    • @CyDETECT
      @CyDETECT Год назад +1

      I completely agree with you

    • @xk964264
      @xk964264 Год назад

      Could have not said it better myself, But this is reality and we need to be prepared to be judged and made fun off by small minded people at a toxic working environment. This should make us stronger and better. It’s life survival of the fittest and those who are insecure will treat you like that. It’s reality he’s basically saying know your shit or someone like me could make your working environment a living hell. I would not want to work with him or any of he’s teammates because they are probably the same ,,,, >>unless he tells me that he has cleaned up after himself. 😂. Jokes aside it’s reality I’m glad the interview was done….

  • @unholy7324
    @unholy7324 2 года назад

    do you guys have any videos on imposter syndrome? ive looked around and didnt see anything. i have been working with a mentor for the last year with 3 hours a day 5 days a week and 6-8 hours on my off days (i take days off when i get brain dead) prepping for this xfer from store side to a SOC as an analyst. even after all that tailored training my mentor had to push me into a resume because i still don't think im ready. i slept 3 hours last night because im crash coursing hard for an interview next week. ive worked help desk, i have my own lab that i even remote into from work im pretty much always pentesting something and i still feel like an idiot that doesnt know anything. it sucks. anyone else like me?

    • @SimplyCyber
      @SimplyCyber  2 года назад +1

      You are putting in the hours and I bet you have lots of lessons learned, assumptions proven wrong (that you learned from), accomplishments to share, etc. you’re good.
      I’ve been in the industry 18 years, have a PhD in cyber operations and there’s a ton i don’t know about. The field is huge my friend, just work hard and try to deliver value to your business and you’ll be great. Dominate the next interview

    • @unholy7324
      @unholy7324 2 года назад

      @@SimplyCyber thank you. i woke up at 4 this morning prepping for market open and to brush up on some interview questions. i also had some lab time with my mentor sunday and he assured that they hire entry level for attitude and drive over skills. i was also told told it would be months before they got me up to speed on their system(s) anyway. so i feel a lot better about it.

    • @Rob-iy2rt
      @Rob-iy2rt Год назад

      Nobody knows everything. You got this! Continuous education is key. Many people who have "made it" stop studying. They don't "make it" very long after that. It's a life-long learning process. Again, nobody knows everything.

  • @StarWolfx64
    @StarWolfx64 4 месяца назад

    bros so mad at new incoming people into security. my bad im a new entry level tier 1 soc and not a 15yr sr network engineer. Also im not familiar but the pen tester out of college found the vulnerability. do pen testers also give solutions and solve for the vulnerability for the company as well? I would hope the more experienced people in the field would help and teach the newcomers than laugh at them and "Take away their credibility" for an entry level position mistake or lack of knowledge. It'd make sense if it was a high level position but its the entry field for cybersecurity

  • @rohanofelvenpower5566
    @rohanofelvenpower5566 2 года назад

    23:07 Geralds radar has detected a whale crying for help near the coast of Japan : ))

  • @RicondaRacing
    @RicondaRacing 2 года назад +1

    Lets go Brandon, I mean you gotta clean that room

  • @Alexithymiander
    @Alexithymiander 3 года назад

    Can I work with you guys?

  • @darkarmy5878
    @darkarmy5878 3 года назад +2

    Brandon is a chubby version of john strand

  • @RicondaRacing
    @RicondaRacing 2 года назад

    Lots of bad career crushing SOCs... not refreshing...lol

  • @TK-le8wd
    @TK-le8wd 3 года назад

    So, is taking a SOC job as your first Cyber job, a bad move for your future security career?

    • @SimplyCyber
      @SimplyCyber  3 года назад +2

      I think its a great move. You will see A LOT.

    • @garcand
      @garcand Год назад

      A network engineer role is better

    • @TK-le8wd
      @TK-le8wd Год назад

      @@garcand Having done both now, I’d have to disagree with this statement. The SOC paid quite a bit more and I make even more now that I’ve gained time. The pay scale for Network Engineers compared to what I make now is no where close.

    • @garcand
      @garcand Год назад

      @@TK-le8wd and i would have to disagree with you. There are a lot of elements for answering this question. In my experience Network Engineering and Programming backgrounds have landed me in Tier 3 SOC Roles . Which ultimately landed me in roles for Red Team Penetration Testing. It was the Networking background that got me the job over all of them. In addition, it always depends on the location for work, interview questions, the employer , who you know, what you prefer, and your overall tech experience. Having experience in both fields will increase salary but i have learned that Networking and Programming are the foundations for cyber security. I guess everyone's entitled to their opinons but thats how my 6 figure journey started JS. Hopefully, the reader can extract the context . Best of luck .

    • @TK-le8wd
      @TK-le8wd Год назад +1

      @@garcand@ ag Ok, I misunderstood what you were trying to say with the first statement. I apologize, as I thought you meant to stay as a Network Engineer vs. going into Cyber. So, yes, the Network Engineer role is essential, as we both know. Networking is a fundamental skill of Cyber. So I apologize for misunderstanding your first statement. I also have a background inin both of the things you mentioned and sys admin roles.

  • @RicondaRacing
    @RicondaRacing 2 года назад

    "Toxic work environment" laughs in FPL.

  • @deathofasellout
    @deathofasellout 9 месяцев назад

    Went from analysis to pure gatekeeping. The older generation sucks.

    • @JohnReeds-pn3nc
      @JohnReeds-pn3nc 9 месяцев назад

      Maybe I missed it when I watched, but what part was gatekeeping?

  • @raulcalleros6468
    @raulcalleros6468 Год назад

    This guy looking like Seth Rogen its just hard to me take him serious... lol

  • @jahjahtruth
    @jahjahtruth 2 года назад

    RGE lol lol 😂😂😂😂😂😂

  • @patrickslomian7423
    @patrickslomian7423 2 года назад

    This guu should realy clean up befor taking a video call WTF ?

  • @edwardjaycocks5497
    @edwardjaycocks5497 Год назад

    The statement being made is undeniably true, and I can vouch for its accuracy based on my extensive experience over the years. I think it's a systemic problem of the it industry overall.