Skip to main content
Image coming soon

The Data-Driven SOC Analyst Playbook for Infosec Leads

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Data-Driven SOC Analyst Playbook for Infosec Leads

Turn SIEM noise, vulnerability scans and IAM logs into a defensible monthly security analytics pack the CISO can take to the board.

The CISO asks why mean time to detect went up this quarter and the honest answer is buried inside three tools nobody has joined.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Information security leads with a data analytics background sit at the only seat in the company that can answer two questions at once. The first is operational, what is happening on the network and how fast are we catching it. The second is governance, which controls are degrading, which exceptions are still open, and what does the audit committee need to sign this quarter. The problem is that the answers live in different tools with different schemas and different owners. The SIEM holds alerts and case timestamps. The vulnerability scanner holds CVEs, exploit prediction scores and asset criticality. The IAM platform holds joiner mover leaver events and privileged access timestamps. The GRC tool holds the control register and the exception log. Nothing joins. When the CISO needs a board pack each month, the lead manually pastes screenshots into slides and the audit trail breaks. This course teaches the data model rebuild, the joins, the clause mappings to ISO 27001 and NIST CSF, and the published monthly analytics pack so the conversation upstream stops being defensive and starts being numerical.

What you walk away with

  • Rebuild a SIEM event taxonomy that survives an EDR or platform change without losing six months of trend data.
  • Join SIEM, vulnerability scanner, IAM and GRC data into a small star schema you can rebuild from scratch in a week.
  • Produce a defensible monthly security analytics pack with mean time to detect, mean time to respond, exception register status and control degradation flags.
  • Map every metric on the pack back to one ISO 27001 Annex A clause and one NIST CSF subcategory so auditors stop asking for evidence walks.
  • Walk the CISO and the audit committee through the pack in twenty minutes without reverting to screenshots.

The 12 modules

Module 1. The Monday Morning Triage Reality and the Numbers Behind It
Open with the actual seat. A senior infosec analyst with a data background opens the console on a Monday and sees thousands of weekend events. This module covers the four questions the role must answer each week, the upstream stakeholders who care about each, and the data sources that hold each answer. By the end you can list which question is currently unanswerable in your environment, which becomes the start of the rebuild plan.
Module 2. Auditing the Current Stack: SIEM, Scanner, IAM, GRC, Ticketing
A practical audit of the five tools that already hold the data you need. For each tool list the schema you have access to, the export rate limits, the retention period, the timestamp source, and the owner of record. The output is a single page table that becomes the input for every module after this. You also identify tools you do not control where a data sharing agreement is needed before the rebuild can start.
Module 3. The SIEM Event Taxonomy Rebuild
The SIEM is the centre of gravity. Almost every taxonomy you inherit will have a mix of vendor categories, custom rules and ad hoc tags that nobody can defend. This module walks through a clean rebuild aligned to MITRE ATT and CK tactics and techniques, the rules for promoting a custom detection to a permanent category, and how to migrate without losing the historical trend. Worked examples use a Microsoft Sentinel and a Splunk taxonomy.
Module 4. Vulnerability Scanner Joins: CVE, EPSS, Asset Criticality
The vulnerability backlog is meaningless without exploit prediction and asset criticality. This module shows how to pull the CVE list, the EPSS or Kenna score, the asset criticality rating from the CMDB and the patch status from the endpoint platform into one table that can answer in one query which findings are both exploitable and on a tier one asset. The same join feeds the patch backlog metric on the board pack.
Module 5. IAM and Privileged Access Logs: Joiners, Movers, Leavers, Standing Privilege
Identity events are the most under-used data set in most infosec analytics functions. This module covers the join between HR joiner mover leaver events, IAM provisioning events, privileged access activations and the actual SIEM authentication events. The output is a metric that shows standing privilege days per account, time to deprovision a leaver, and the count of privileged sessions per quarter that bypassed PAM.
Module 6. The Small Star Schema That Survives a Tool Change
Most security data warehouses fail because they mirror the tool of the moment. This module designs a small star schema with five fact tables and a handful of dimensions that holds events, findings, identities, controls and exceptions. The point is that when the SIEM or the scanner is replaced, the schema does not change and the trend line does not break. Includes a worked Snowflake and a worked Postgres example with a sample loader pattern.
Module 7. Mapping Every Metric to ISO 27001 Annex A and NIST CSF
Numbers without clause anchors are debated. Numbers with clause anchors are signed off. This module walks through the mapping of each metric on the monthly pack back to one ISO 27001 Annex A control and one NIST CSF subcategory, with notes for SOC 2 Trust Services Criteria where they overlap. The result is that the auditor asks one question per metric instead of one question per evidence walk.
Module 8. The Exception Register: From Stale Spreadsheet to Live Join
Most exception registers are a stale spreadsheet that the GRC analyst updates once a quarter. This module replaces it with a live join between the GRC register, the vulnerability backlog and the IAM standing privilege view, so the exception register is always current and every entry has a named owner, a due date and a control clause. The output is the exception status column on the board pack.
Module 9. Control Degradation Flags and the Trend Lines That Matter
A board pack that only shows green and red without trend is theatre. This module covers the four trend lines that earn the meeting: detection coverage by ATT and CK technique over six months, mean time to respond per severity, exception count by clause and patch backlog by exploitability tier. The module also covers the wording of the flag column, when an amber should become a red, and when a red is a control degradation that triggers a formal exception.
Module 10. The Monthly Analytics Pack Template and the Twenty Minute Walk
A finished template. One page of metrics. One page of trend lines. One page of exception register status. One page of the three changes recommended for sign off this month. The module includes the narrative skeleton, the chart sizing rules, the colour conventions and a worked twenty minute walk for an audit committee. The pack is built so that the CISO presents the first page and the lead presents the next three on request.
Module 11. Defending the Numbers: Auditor Questions, Internal Audit, External SOC
The pack only works if it survives a challenge. This module covers the seven questions internal audit, external SOC 2 audit and the lead supervisor in a regulated sector typically ask about security metrics, the artefact each question maps to in the star schema, and the canonical answer. The module also covers the wording for the limitations section so the lead never has to retract a number under pressure.
Module 12. The First Ninety Days: Roll Out, Stakeholder Briefings, Handover
A week by week plan for the first ninety days after the course finishes. Week one rebuilds the SIEM taxonomy. Weeks two and three stand up the star schema and load SIEM and scanner data. Week four loads IAM and GRC. Weeks five to eight publish the first monthly pack with the CISO. Weeks nine to twelve refine and brief the audit committee. A handover pack lets a peer analyst step in without losing continuity.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Stakeholder asks why mean time to detect went up this quarter and you can answer in one chart with one clause anchor.
External SOC 2 or ISO 27001 audit asks for control monitoring evidence and you hand them the monthly pack with the clause mapping already done.
CISO needs to defend the security budget at the audit committee and the trend lines on the pack do most of the work.
A peer analyst leaves and the next person can rebuild the star schema in a week without losing six months of trend data.

What you get with this course

  • Twelve written modules in the Art of Service learning environment.
  • Downloadable star schema diagram, loader patterns for Snowflake and Postgres, and a SIEM taxonomy mapping template.
  • Worked monthly analytics pack template with the twenty minute walk script.
  • ISO 27001 Annex A and NIST CSF clause mapping spreadsheet pre-populated for the metrics in the pack.
  • The hand-built implementation playbook tailored to your specific SIEM, scanner, IAM and GRC stack.

What you will have in hand by Day 1, Week 1, Month 1

Day one, course access provisioned in the Art of Service learning environment.

Day one, the hand-built implementation playbook is delivered alongside course access.

Weeks one to four, work through modules one to six and stand up the star schema on a sample data set.

Weeks five to eight, work through modules seven to ten and publish the first monthly pack.

Weeks nine to twelve, work through modules eleven and twelve, brief the audit committee and hand over.

Before and after

Before

You can answer any one security question on demand, but you cannot publish a defensible monthly pack the CISO can take upstream without manual screenshots and a defensive narrative.

After

You publish a monthly analytics pack with clause-anchored metrics, live exception register and degradation flags, and the audit committee meeting is twenty minutes of numbers instead of two hours of debate.

What happens if you do not address this

The role stays operational. The CISO keeps escalating without numbers and the audit committee keeps signing off on narrative. When the next external audit asks for control monitoring evidence the analyst pastes screenshots into slides and the audit trail breaks. The seat that combines cybersecurity, information security and data analytics is rare. Without the published pack the rarity stays invisible.

Who it is for

Cybersecurity and information security specialists with a working knowledge of SQL, Python or KQL and at least one SIEM, vulnerability scanner and IAM platform in production. Typically a senior analyst, team lead, or hands-on manager who is the only person in the room who can read both a query plan and an incident timeline. Often the person the CISO turns to for the numbers behind the narrative.

Who this is NOT for. This is not a beginner SOC analyst course and not a pure GRC course. If you have never queried a SIEM or never mapped a control to a clause, the level will move too fast. If you only want a written incident response runbook with no data work, the Audit Evidence Mastery course is closer to what you need.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly four to six hours per module across twelve weeks, with the heavier weeks two through four for the star schema build and weeks seven and eight for the first published pack.

Why $199 is the right number

A generic SIEM administration certification teaches the tool, not the analytics pack. A pure GRC course teaches the clause mappings, not the joins. A data analytics bootcamp teaches the queries, not the security context. This course assumes the rare combination of cybersecurity, information security and data analytics that this role already has, and builds the one missing artefact which is the published monthly pack.

FAQ

Does this require a specific SIEM, scanner or IAM platform?
No. The worked examples use Sentinel and Splunk for SIEM, Tenable and Qualys for scanning, and Microsoft Entra and Okta for IAM, but the schema and the clause mappings are platform-neutral. The implementation playbook is hand-built for your specific stack.
Can the metrics work for SOC 2 as well as ISO 27001 and NIST CSF?
Yes. Module seven includes the SOC 2 Trust Services Criteria overlap notes and the same metrics serve all three frameworks with the right clause anchors.
I am the only senior analyst in the team. Can I publish the pack alone?
Yes. The pack is designed to be built by one senior analyst with read access to the SIEM, scanner, IAM and GRC tools. Module twelve includes the handover pack so a peer can take over without losing continuity.
How does the implementation playbook differ from the course modules?
The modules teach the method on worked examples. The implementation playbook applies the method to your specific stack, your specific clause set and your specific stakeholder list, written for you by hand after enrolment.
Is there a refund if the course is not the right level?
Yes. Thirty day refund if the level is wrong or if the modules do not match what was described.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.