Beyond the alerts: How I built a career in detection engineering
Moving from SOC analyst to detection engineer is not about waiting for the right opportunity. It’s about building the right skills, asking better questions and understanding what sits behind every alert.
In this blog, I share the key lessons I learnt along the way.
How my career in cyber security took off
Every alert arrives with a question: is this noise, or is this the moment something real begins to unfold? In the SOC, that question sits behind every dashboard, every investigation and every decision made under pressure.
This is where I started my career in cyber security, focused on monitoring alerts, investigating suspicious activity and responding to incidents. Over time, I realised I did not just want to respond to threats. I wanted to understand how detection systems worked and help build the rules that identify those threats in the first place. That curiosity eventually helped me move from SOC analysis to detection engineering at Resillion.
The transition didn’t happen overnight. It came through consistent effort, hands-on learning and the support of an environment where internal growth is encouraged. Looking back, the most important shift wasn’t just moving into a new role but changing my approach to work itself. I always felt like I wanted to go deeper.
Key advice for building a cyber security career
Building up my foundational skills in the SOC
Before joining Resillion, I worked as an SOC Analyst. My role focused on monitoring security alerts, investigating suspicious activity and responding to incidents. It gave me a strong foundation and taught me an important lesson. For anyone looking to grow in cyber security: the best way to move forward is to understand what’s really happening behind the alerts.
That experience helped me understand how attacks happen in real environments. The hands-on exposure gave me more than operational experience. It shaped how I thought about security from the ground up. Rather than staying only within incident response, I became increasingly interested in how detection systems were designed.
So, when the opportunity to join Resillion came up, my SOC experience gave me a clear starting point, even if the environment I was stepping into was very different.
Making the move towards detection engineering
At Resillion, I continued my journey as an SOC Analyst. My day-to-day responsibilities included monitoring security dashboards, triaging alerts, investigating suspicious activity and escalating incidents when required.
While the work was familiar, this phase proved critical for the simple reason: you can’t build good detections if you don’t understand how alerts behave in the real world first.
For anyone hoping to make a similar move, gaining this kind of experience matters. Working with tools like Microsoft Sentinel, writing investigation notes and following playbooks for common attack scenarios helped me build a deeper understanding of security operations. More importantly, it gave me a clearer view of how detection systems function end-to-end. From there, my transition into detection engineering became more deliberate.
I began going beyond my immediate responsibilities, starting by analysing why certain detections were triggered, tuning alert rules and gradually writing better ones. My advice to others is to do the same: get curious about why an alert fires, learn the tools deeply and look for small ways to contribute beyond your day-to-day role.
I was very intentional about it. Slowly, I built my way into that role. Alongside this, I invested in developing my expertise through certifications such as SC-100, Certified Junior Detection Engineer and Torq Expert. The turning point came when my consistent contributions were recognised, giving me the opportunity to focus more fully on detection engineering.
At Resillion, my transition was supported through both opportunity and expectation. That mattered because much of my work involves moving across functions and projects in a matrix-style setup. It also means working directly with clients and applying my expertise in real-world environments.
What detection engineering looks like in practice
Today, my role sits firmly on the engineering side of cyber security, where the focus shifts from responding to threats to proactively identifying them. At its core, detection engineering is about defining what the system should look for and making sure it captures meaningful signals without being overwhelmed by noise. So, while no two days look the same, the underlying objective remains consistent.
For example, a typical day might begin with analysing a detection rule that is generating too many false positives. This usually involves diving into raw data using KQL queries in Microsoft Sentinel, identifying patterns and refining the logic so that alerts are triggered only when genuinely required.
On other occasions, the work is more proactive and involves building entirely new detections from scratch to address emerging threats. For example, I built a rule to catch phishing emails that used fake voicemail links to trick users, turning a recurring attack pattern into something the system could catch earlier.
Beyond detection logic, automation also plays a critical role. I develop response workflows using tools like Torq, making sure that when an alert is triggered, the right actions are executed immediately and reliance on manual intervention is reduced.
Increasingly, my work also intersects with AI-driven security. From building detection rules to enabling intelligent analysis, the role has evolved to include advanced capabilities that improve both speed and accuracy. That evolution is part of what keeps the work interesting every day.
What has tied all this together is continuous learning. Whether I am refining existing rules, experimenting with new detection strategies or exploring AI applications, the role demands both technical depth and adaptability. That combination is what makes the work rewarding and this transition truly worthwhile.
Advice for aspiring cyber security professionals
For anyone looking to break into cyber security, or move from SOC analysis into detection engineering, my advice is simple: start where you are and go deeper. Rather than focusing purely on titles or roles, focus on understanding what sits beneath them. If you are an SOC Analyst, look beyond the alerts and explore how detection rules are created and why they behave the way they do.
The same principle applies across disciplines whether you are in IT, development or operations. The key is curiosity: taking the time to understand systems more deeply rather than treating them as black boxes. Alongside this, practical experience is critical. Certifications can help establish a foundation, but real progress comes from applying knowledge in tangible ways. Even a small personal project shows that you are serious. Certifications help, but doing the work teaches you far more than theory alone.
Above all, consistency matters. Progress in cyber security is rarely immediate, but with sustained effort, it becomes inevitable.
A journey shaped by trust
My journey from monitoring alerts to building detection systems and working on AI-driven security has been shaped by both personal effort and the opportunities available within the right environment. Resillion gave me the foundation, the challenges and the trust I needed to grow into the engineer I always wanted to become. And for me, that is what real career growth looks like, not just moving into a new role, but becoming ready for the work you once hoped to do.
If you are looking for progress in cyber security as a career, the question is simple: are you willing to stay curious, go deeper and build your way towards it?
Take a look at the latest careers in cyber security at Resillion here.