Inside the SOC: How Junior Analysts Actually Get Hired with NEVERHACK Estonia Head of SOC

Louis Zezeran 3. sept 2026

Inside the SOC: what it really takes to get hired, and what happens once you’re in 

There is a strange contradiction at the heart of the cybersecurity job market. Every report and every keynote says the same thing: we need more security professionals, urgently. Yet talk to anyone who has just finished a cybersecurity degree, or spend ten minutes on the cybersecurity subreddit, and you will find people who have sent out dozens of applications and heard nothing back. 

In this episode of the NEVERHACK Cybercast, host Louis Zezeran sits down with the person best placed to explain that gap: Fothul Karim Forhan — Forhan to everyone who works with him — Head of SOC at NEVERHACK Estonia. Forhan runs a 24/7 security operations centre, sits on the hiring panel, and is not far removed from being a junior himself. He moved from Bangladesh to Estonia in 2019 to study cybersecurity engineering at TalTech, took a job in his second year with the company then known as Cybers, and was one of its first SOC analysts when the team was only two people. 

That trajectory is why this conversation is worth an hour of any aspiring analyst’s time. Forhan is not describing a career path he took twenty years ago in a different industry. He is describing the one that exists right now. 

Academic knowledge is not operational knowledge 

Forhan’s central idea — and he acknowledges up front that not everyone will agree with him — is that there are two kinds of knowledge, and confusing them is what leaves graduates stuck. 

Academic knowledge is what a university gives you: the concepts, the vocabulary, the foundations. Operational knowledge is something else entirely. It is what an enterprise actually needs, what a client actually wants, and what a live environment actually looks like. A degree prepares you for the first and barely touches the second, and recognising that early was one of the most useful things he did. 

His answer was a home lab, and he is specific about what that meant. Not one virtual machine and a tutorial, but an attempt to build a miniature SOC: multiple instances and machines, open-source AV and detection tooling, an Elastic stack, network logs pulled off a small home router. From there the real learning began — writing detection rules, working out where the log sources live in Windows and Linux, understanding what the data means and how it is captured. 

Then comes the point that matters most. There are thousands of YouTube videos showing you exactly this build, and watching them is fine — but watching is not doing. The moment you hit an error the video did not cover, you have to work out what to do next. That, he argues, is what actually prepares you for an enterprise environment, which is the same thing at a vastly larger scale. 

Certifications: worth it, but not for the reason you think 

Forhan is candid about his own bias: at NEVERHACK, candidates are not judged on certifications. But plenty of other employers do care, and he thinks a junior should get one or two anyway. 

His reasoning is about evidence, not prestige. You do not need the highest-level certification available. What one or two certifications give you is something a course completion cannot: an exam somebody else set and marked. When Forhan sees a certification, he knows roughly what that exam covered — which means he knows something concrete about the candidate, rather than taking them at their word. 

For getting started he points to TryHackMe and Hack The Box, less as certifications than as genuinely good course material, and mentions Security+ alongside vendor-specific paths like Microsoft’s SC-200. 

Then the piece almost everybody skips: document your projects and put them on GitHub or GitLab. His argument is simple and slightly uncomfortable. He believes in data and facts, and if you have never met someone, visible work is all there is to go on. A brilliant home lab that exists only in your bedroom is invisible to every hiring manager on earth. 

Why NEVERHACK stopped setting technical tasks — and what replaced them 

The most immediately useful part of this episode concerns the interview itself. 

NEVERHACK Estonia’s SOC used to set candidates a technical task. They no longer do, for two reasons. At any real volume of applicants the task has to be identical for everyone, and the results clustered — it consumed everyone’s time to tell you something a conversation revealed faster. And decisively: in the era of AI, Forhan is confident any task he sets can be solved by a model. The signal is gone. 

What replaced it is a conversation, and knowing how that conversation is designed is a real advantage for a candidate. 

Forhan does not ask for textbook definitions. He asks people to explain things in their own words, and he will offer hints along the way. He wants to know whether you understand what a SOC is, what a given tool does, and — the question most candidates never prepare for — why that tool exists at all. “It protects against malware” is not an answer. The real one sits a level deeper. 

His view on tooling follows from this and should be liberating for anyone whose CV feels thin. Tools are just tools. With the underlying concepts, an unfamiliar platform takes a couple of weeks to a month to learn, because most tools share the same core ideas behind a different interface. What cannot be picked up in a month is conceptual understanding, and that is what he is hiring for. 

Which brings him to the human side. Skills can be taught, and nobody is thrown into a production environment without training first. What matters alongside them is whether the person fits the team, and whether there is visible passion and drive. Confidence matters — but Forhan draws a sharp line between confidence and overconfidence. If you do not know something, say so. Nobody is counting the percentage of questions you answered correctly. Inventing an answer out of thin air is the thing that actually costs you the job. 

Louis adds a companion tactic from his own hiring experience in a very different industry: if you do not know something, turn it around and ask an inquisitive question. That is what a real conversation looks like, and it demonstrates exactly the behaviour a SOC needs. 

The tierless SOC: why “above my pay grade” is a design flaw 

The second half of the episode moves from getting hired to what the job is actually like, and turns into something closer to a leadership masterclass. 

Most people picture a SOC as a pyramid. Level 1 analysts watch alerts and escalate what they cannot handle. Level 2 takes the harder cases. Level 3 does detection engineering, playbooks and big-picture threat work. The levels are distinct teams, and a Level 1 analyst essentially never touches detection engineering. 

NEVERHACK Estonia does not work that way. The SOC runs a tierless model with distributed leadership and what Forhan calls dynamic streams — no walls between teams, and an “analyst” who is also an engineer. Automation, detection engineering, process engineering and platform engineering all live inside the SOC, and analysts rotate through them. 

The organising principle is what he calls an authority position: whoever picks up an incident owns it. They decide what to do with it, they follow it through, and they ask for help when they need it — but “this is above my scope” is not an available exit. 

His case against the tiered model is a resource argument as much as a moral one. Silos overwhelm seniors with constant escalations while leaving juniors repeating the same narrow task, learning nothing and heading toward fatigue. Louis points out the flip side: seniors who never touch the front line lose contact with the reality their teams live in — the general in the air-conditioned office while the soldiers are in the mud. 

There is a scale point that is easy to miss, too. Because the SOC runs 24/7, its cumulative working time is roughly three times that of a nine-to-five team, so ideas get built, tested and shipped faster. 

Leadership, transparency and the 75% rule 

The episode closes on how decisions get made. Forhan’s rule is transparency: any decision he takes comes with documented pros, cons and reasoning, so nobody can reasonably conclude it came down to personal bias. He is equally honest that not every idea gets approved, and that the usual reason is a difference in point of view — leadership sees KPIs and constraints an individual contributor cannot. The failure is not the rejection. It is failing to explain it. 

Louis offers the coaching version of the same idea: if your team brings you a plan that is about 75% of what you would have done and it meets the requirements, approve it. People are more invested in their own plan, and when they hit an obstacle they pivot on their own instead of coming back for permission. 

And when Louis asks how an established, heavily tiered SOC could ever make this transition, Forhan’s answer is short. Treat it as a project. Analyse the risk. Accept that operational capacity will take a hit and that it might not work. Then find the people who will lead it, trust them, guide them, and try — because you cannot get a good outcome without trying. 

Listen now 

Whether you are trying to break into cybersecurity, hiring analysts, or rethinking how your own SOC is structured, this conversation is full of things you can act on this week: build the lab, document the work, learn the concepts rather than the buttons, and stop hiding behind escalation. 

Listen to the full episode now, subscribe to the NEVERHACK Cybercast, and visit neverhack.com to find out more about our SOC and our open roles. Forhan has also offered to come back for a deeper technical episode on how a modern SOC runs — so if you have questions, send them in. 

Jaga

Märksõnad

Märksõnad

Jaga

Viimased postitused

23. juuli 2026

Nutikad kodumasinad võivad avada ukse küberkurjategijatele

Veel kümmekond aastat tagasi tähendas turvaline kodu eelkõige korralikku lukku ja võib-olla ka valvesüsteemi. Tänapäeval tähendab kodu kaitsmine aga palju enamat. Üha suurem osa meie elust toimub digitaalses keskkonnas ning koos sellega on muutunud ka turvariskid. Kurjategijad ei pea enam füüsiliselt kellegi koju sisse murdma,  piisab vaid ligipääsust ühele internetti ühendatud seadmele. Robotmuruniidukid, robottolmuimejad, turvakaamerad, […]

Loe edasi
2. juuli 2026

Kuidas tagada turvaline AI ja pilveteenuste kasutamine

Netskope aitab muuta nähtamatud riskid nähtavaks Pilveteenused, SaaS-rakendused ja tehisintellekt on saanud meie igapäevase töö oluliseks osaks. Küsimus ei ole enam isegi selles, kas töötajad neid kasutavad, vaid selles, kas organisatsioon suudab seda kasutust turvaliselt omaltpoolt juhtida. Täna on võimalik töötada kõikjal- kontoris, kodus, kliendi juures ja liikvel olles. Andmed liiguvad Microsoft 365, Google Workspace’i, […]

Loe edasi
2. juuli 2026

Üks turvanõrkus võib peatada kogu tootmisliini

Eesti tööstusettevõtted on viimastel aastatel teinud suure arenguhüppe. Automatiseeritud tootmisliinid, ühendatud seadmed, pilveteenused ja digitaliseeritud tarneahelad aitavad tõsta efektiivsust ning konkurentsivõimet. Kuid mida rohkem sõltub tootmine digitaalsest taristust, seda suuremaks muutub ka küberturvalisuse roll. Neverhack Estonia juhatuse liikme Rita Käit’i sõnul ei ole Eesti tööstusettevõtete suurim väljakutse enam tehnoloogia puudumine, vaid tervikpildi puudumine. „Paljud ettevõtted […]

Loe edasi