IT Operations

Security Operations

Security operations professionals master the art of defensive thinking—anticipating threats others miss. This paranoid precision creates CIOs who build resilient systems and never get caught unprepared when everything breaks.

L1 – L9 · 9 tours Leads to: CIO → What's a Reference DRS?

The Career Arc

Rotational · L1–L3

Build the Security Operations craft. Prove you can wield the tools of IT Operations.

  • L1 : Learn security monitoring fundamentals and develop alert triage skills
  • L2 : Own first-tier alert triage and escalate confirmed incidents
  • L3 : Investigate complex alerts independently and contribute to detection rule development

Transformational · L4–L7

Deliver Security Operations outcomes — each IT Operations tour at this altitude has a defined mission and success criteria.

  • L4 : Lead incident investigations and mentor junior analysts
  • L5 : Drive detection engineering initiatives and optimize SOC processes
  • L6 : Set security operations direction and define detection strategy
  • L7 : Set security operations strategy across multiple teams

Manage a Team?

Great Security Operations managers are practitioners first. The IT Operations IC responsibilities in L4–L7 are your foundation — your management responsibilities are additive:

  • Hire for problem-solving under pressure—outages don't wait
  • Coach your team to think business-first—IT serves the mission
  • Run 1:1s that develop breadth—not just depth in one system
  • Give feedback that builds calm under fire—direct, supportive, timely
  • Remove blockers—fight for budget, tooling, and executive buy-in

Foundational · L8–L9

Shape the IT Operations organization from the Security Operations chair — build institutions, not just products.

  • L8 : Own enterprise security monitoring and incident response
  • L9 : Shape organizational security posture through operational excellence
→ C-Suite: L10 is the CIO path — a distinct page, not duplicated here.

L1 — Associate Security Operations Analyst Rotational

Mission

Learn security monitoring fundamentals and develop alert triage skills

This tour of duty

Complete SOC onboarding and successfully triage your first 100 alerts

Own the outcomes

  • Learn security operations fundamentals including SIEM, alerts, and response
  • Triage security alerts following runbooks with guidance
  • Write incident documentation and case notes
  • Document alert patterns and investigation findings
  • Support senior analysts on complex investigations
  • Participate in SOC shifts to learn security monitoring

Security Operations at L1 — the competency bar

Software Engineering
2
IT Operations
2
Information Security
1

AI in this role

  • Using AI to summarize alert context from multiple log sources
  • Drafting initial incident notes from investigation findings
  • Learning detection logic by asking AI to explain complex queries

L2 — Junior Security Operations Analyst Rotational

Mission

Own first-tier alert triage and escalate confirmed incidents

This tour of duty

Own a shift and maintain SLA compliance for alert response times

Own the outcomes

  • Triage and investigate security alerts independently
  • Perform incident response following playbooks
  • Write comprehensive incident reports
  • Design simple detection rules for known threats
  • Contribute to runbook and playbook improvements
  • Operate security infrastructure with guidance

Security Operations at L2 — the competency bar

IT Operations
2
Information Security
2
Software Engineering
1
Quality Engineering
1
Operational Excellence
1

AI in this role

  • Correlating alerts across systems using pattern recognition tools
  • Generating investigation timelines from scattered log entries
  • Drafting escalation summaries for senior analysts

L3 — Senior Security Operations Analyst Rotational

Mission

Investigate complex alerts independently and contribute to detection rule development

This tour of duty

Lead your first major incident investigation from detection to resolution

Own the outcomes

  • Own security operations domains end-to-end
  • Design detection rules and response playbooks
  • Lead incident response for security events
  • Lead SOC shift operations and coordination
  • Mentor junior analysts on security operations
  • Drive SOC process and detection improvements

Security Operations at L3 — the competency bar

IT Operations
3
Information Security
2
Software Engineering
1
Quality Engineering
1
Operational Excellence
1

AI in this role

  • Building detection queries from natural language threat descriptions
  • Analyzing malware behavior reports to extract IOCs
  • Automating repetitive triage tasks with scripting assistance

L4 — Staff Security Operations Analyst / Manager, IT Operations Transformational

Mission

Lead incident investigations and mentor junior analysts

This tour of duty

Build a detection rule that catches a previously undetected threat category

Own the outcomes

  • Lead security operations initiatives across domains
  • Design SOC processes and detection strategies
  • Mentor analysts on threat investigation and response
  • Define security operations standards and metrics
  • Drive cross-team incident coordination
  • Own incident response quality for the organization

Security Operations at L4 — the competency bar

IT Operations
3
Software Engineering
2
Information Security
2
Quality Engineering
1
Operational Excellence
1

AI in this role

  • Developing threat hunting hypotheses from threat intelligence feeds
  • Creating comprehensive incident reports from investigation notes
  • Mentoring juniors using AI to generate training scenarios

L5 — Senior Staff Security Operations Analyst / Senior Manager, IT Operations Transformational

Mission

Drive detection engineering initiatives and optimize SOC processes

This tour of duty

Design and implement a SOC process improvement that measurably reduces MTTR

Own the outcomes

  • Drive security operations strategy organization-wide
  • Design SOC programs that scale with threat landscape
  • Define security operations standards and best practices
  • Lead evaluation of security operations tools
  • Mentor senior analysts and shape operations culture
  • Solve the most complex security operations challenges

Security Operations at L5 — the competency bar

IT Operations
4
Information Security
3
Software Engineering
2
Quality Engineering
1
Operational Excellence
1

AI in this role

  • Optimizing detection coverage by analyzing alert patterns at scale
  • Building automated response playbooks from incident learnings
  • Evaluating new security tools using AI for POC analysis

L6 — Director, Security Operations Transformational

Mission

Set security operations direction and define detection strategy

This tour of duty

Build a SOC team that maintains 24/7 coverage with consistent quality

Own the outcomes

  • Set direction for security operations company-wide
  • Define SOC strategy and multi-year roadmap
  • Establish standards ensuring effective threat detection
  • Drive alignment on security operations investments
  • Represent security operations in executive discussions
  • Shape the vision for SOC evolution

Security Operations at L6 — the competency bar

IT Operations
4
Software Engineering
3
Information Security
3
Strategy
2
Quality Engineering
1
Operational Excellence
1

AI in this role

  • Forecasting SOC capacity needs from historical incident data
  • Generating board-ready security metrics dashboards
  • Designing SOC workflows that incorporate intelligent triage

L7 — Senior Director, Security Operations Transformational

Mission

Set security operations strategy across multiple teams

This tour of duty

Establish SOC capabilities across multiple business units or geographies

Own the outcomes

  • Shape the company's security operations vision and strategy
  • Define innovative approaches to threat detection and response
  • Establish principles guiding security operations decisions
  • Influence industry security operations practices
  • Mentor directors and senior operations leaders
  • Drive security operations innovation

Security Operations at L7 — the competency bar

IT Operations
2
Information Security
2
Strategy
2
Software Engineering
1
Quality Engineering
1
Operational Excellence
1

AI in this role

  • Benchmarking SOC performance against industry standards
  • Building business cases for security investments from operational data
  • Coordinating multi-team incident response

L8 — VP, Security Operations Foundational

Mission

Own enterprise security monitoring and incident response

This tour of duty

Transform security operations maturity from reactive to proactive threat hunting

Own the outcomes

  • Build and lead security operations teams
  • Define organizational structure for security operations
  • Establish hiring standards for security analysts
  • Create the operating model for SOC excellence
  • Partner with security leadership on SOC investments
  • Develop security operations managers and leaders

Security Operations at L8 — the competency bar

Software Engineering
2
IT Operations
2
Information Security
1
Strategy
1

AI in this role

  • Modeling security risk scenarios using simulations
  • Transforming raw security data into executive narratives
  • Designing scalable SOC architectures

L9 — SVP, Security Operations Foundational

Mission

Shape organizational security posture through operational excellence

This tour of duty

Lead security operations through a major incident that shapes industry practices

Own the outcomes

  • Own security operations strategy organization-wide
  • Define multi-year roadmap for threat detection
  • Build culture that attracts top security operations talent
  • Partner with executives on security posture strategy
  • Establish security operations as organizational strength
  • Shape the future of security operations at the company

Security Operations at L9 — the competency bar

Software Engineering
2
IT Operations
1
Information Security
1
Strategy
1

AI in this role

  • Shaping industry security operations standards through data-driven insights
  • Building security operations centers of excellence
  • Advising boards on security posture

What Hiring Managers Look For

L1-L3: Demonstrates hands-on experience with SIEM tools, incident response procedures, and can articulate specific security events they've investigated from detection through resolution.

L4-L6: Shows measurable impact on security posture through automation, threat hunting programs, or cross-functional security initiatives that reduced mean time to detection or response.

L7+: Presents board-level security strategy that balances business enablement with risk management, backed by quantified outcomes from security transformations at enterprise scale.

Common Career Transitions

Security Operations → Risk Management at L4-L5 for strategic security governance

Security Operations → Platform Engineering at L5-L6 for security-by-design architecture

Security Operations → Product Security at L4-L6 for application security leadership

Measure yourself against this ladder — pin it to your Career Record.

Build Your Career Record