Skip to content

Latest commit

 

History

History
239 lines (188 loc) · 19.7 KB

hr_training.md

File metadata and controls

239 lines (188 loc) · 19.7 KB

SOC HR and training

This page deals with SOC HR and training topics.

ToC

Must read

MITRE reference

HR roles and organization

As per what is explained on the management page, I would recommend to make sure the following roles are being assigned to people:

  • SOC analyst;
  • SOC analyst lead;
  • SOC detection engineer;
  • Threat intel analyst;
  • Threat intel lead (if several analysts)
  • SIEM expert and data scientist;
  • Pentester (offensive team);
  • Incident handler;
  • Incident manager;
  • SOC/CSIRT tools admin;
  • SecDevOps analyst;
  • SOC/CERT/CSIRT deputy manager.
  • SOC/CERT/CSIRT manager.

They can be FTE or outsourced, it will depend on your needs and constraints. My recommendations are explained in the RACI template that I propose.

Recommended SOC trainings

Regular trainings

Challenges

SIEM

Splunk

Microsoft (Defender XDR / Sentinel)

Certifications

Free certifications:

Paid certifications:

Not working anymore ATOW: EthicalHackersAcademy, SOC & SIEM Security program: L1, L2, L3.

Recommended CERT/CSIRT trainings

Regular trainings & challenges [Free]

Certifications

Paid certifications:

Free certifications:

Challenges

Recommended CTI trainings

Certifications

Recommended VOC (Vulnerability management) trainings

Certifications

Recommended offensive security trainings

NB: this is mainly for red/purpleteaming activities.

Regular trainings

Certifications

Recommended management trainings

Paid certifications

To go further

End

Go to main page.