Mon–Fri, 9:00 AM – 6:00 PM EST

From SOC Analyst to Detection Engineer: A Contract Career Path

A step-by-step map from SOC analyst tickets to detection engineering work, with the skills, certs, and timelines that actually move contract consultants forward.

Security consultant reviewing SIEM dashboards at a multi-monitor desk at night

You have been staring at the same alert queue for eighteen months. Tier 1 triage, escalate, close, repeat. You know the SIEM cold, you can spot a phishing kill chain in your sleep, and you are wondering if this job has a ceiling or a ladder.

It has a ladder. Detection engineering is the natural next rung for SOC analysts who want to build the rules instead of just chasing them. It also happens to be one of the more durable contract security roles right now, because every organization running a SIEM needs someone who can write detections that actually catch things without drowning the team in false positives.

This is the concrete path, not a motivational one: what you need to learn, what you need to prove, and which certs are worth your money.

The real progression, tier by tier

Job titles vary by employer, but the skill progression is consistent across most SOCs and MSSPs.

  • SOC Analyst Tier 1 (0-18 months): alert triage, ticket hygiene, basic log review, escalation judgment.
  • SOC Analyst Tier 2 (1-3 years): investigation depth, correlation across log sources, incident scoping, tuning noisy rules.
  • Detection Engineer (2-4+ years): writing and maintaining detection logic, mapping coverage to adversary behavior, working with threat intel and red/purple teams.

The jump from Tier 2 to detection engineer is not about seniority alone. It is about shifting from reacting to alerts to authoring the logic that generates them. That shift requires four specific skill sets.

SIEM fluency beyond dashboards

Every SOC analyst can click through a SIEM console. Detection engineers write the query language natively: Splunk SPL, Microsoft Sentinel KQL, Elastic Query DSL, or Chronicle YARA-L, depending on the stack. You need to be able to write a detection from a blank query bar, not just tune a template someone else built.

Equally important is log source enrichment. Raw logs from firewalls, EDR, identity providers, and cloud audit trails rarely arrive in a usable shape. Detection engineers normalize fields, join identity context to network events, and enrich alerts with asset criticality so an analyst downstream is not investigating blind. If you have never mapped a raw Windows Event ID to a normalized schema field, that is your next hands-on project.

MITRE ATT&CK mapping, done properly

Every job posting mentions ATT&CK. Few candidates can actually use it as a working framework instead of a poster on the wall.

Detection engineers use ATT&CK to answer three questions on every rule they write:

  1. Which technique and sub-technique does this detection cover (e.g., T1059.001, PowerShell)?
  2. What data source is required to see it, and do we actually collect that data source?
  3. Where are our coverage gaps, and which gap matters most given our threat model?

Build yourself a coverage matrix, even informally in a spreadsheet, mapping your organization's or lab's detections against the ATT&CK Enterprise matrix. That artifact alone, brought to an interview, tells a hiring manager more than any bullet point on a resume.

Writing detections and surviving purple team feedback

A detection is not done when it fires. It is done when it fires accurately, at a rate the SOC can actually triage, with a documented false-positive rationale. Learn to write a detection rule with three components every time: the logic, the expected data source, and a tuning threshold based on observed baseline noise.

Purple team exercises are where this gets tested for real. A red team or pen tester runs a technique, you validate whether your detection caught it, and you tune or write new logic based on the gap. Contract consultants who can say, credibly, that they have sat in a purple team session and shipped a detection improvement afterward stand out immediately from those who only have SOC ticket metrics on their resume.

Certifications: what earns its cost, what does not

Certs help you get past resume screens for contract roles, but not all of them carry equal weight for detection engineering specifically.

If you can only fund one cert this year, GCDA or a Splunk-specific credential will move a detection engineering resume further than a broad management cert like CISSP, which is better suited to later, leadership-track roles.

What a contract detection engineer resume needs to show

  • A named SIEM platform with query language fluency, not just "SIEM experience"
  • At least one documented detection rule you wrote from scratch, with the ATT&CK technique it maps to
  • Evidence of log source normalization or enrichment work
  • Any purple team, tabletop, or red team collaboration, even informal
  • A cert that matches your target stack, not a generic one

Contract clients hiring for detection engineering want someone who can walk in and improve coverage in the first sprint. Specificity on your resume is the fastest way to prove you can do that.

If you are mapping out this move and want a second opinion on which contracts and clients actually value this skill set, the team at Josh Pros LLC works with security consultants across SOC and detection engineering roles nationwide. Reach out at contact@joshpros.com or visit https://joshpros.com to talk through your next step.

#DetectionEngineering #SOCAnalyst #CyberSecurityCareers #MITREATTACK #SIEM #SecurityEngineer #ContractIT #ThreatDetection #PurpleTeam #ITStaffing #SecurityCertifications #CyberCareerPath

Talk to a real recruiter, not a bot.

We'll tell you the rate, the client, and the terms before you interview. And if we're not the right fit, we'll say so.

Back to all insights

Equal opportunity. Josh Pros LLC is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, protected veteran status, citizenship status, or immigration status, consistent with Title VII, the Immigration and Nationality Act (8 U.S.C. §1324b), and applicable state and local law.

Information on this website about work authorization and immigration is general information, not legal advice. Confirm your individual situation with a licensed immigration attorney.