SOC T1 + T2 Analyst

As a SOC Analyst, youโ€™re the guardian of the network. In this program, youโ€™ll go from zero to becoming a fully-fledged Tier 1 and Tier 2 analyst, using realistic scenarios, professional tools, and a skill set that security teams recognize as immediately deployable.

  • No IT degree requiredโ€”but you do need analytical skills and the drive to grow.
  • 600 hours of practical trainingโ€”more than half of which is purely hands-on with Splunk, Microsoft Sentinel, Wireshark, and EDR.
  • Ready to work immediately as a Tier 1 or Tier 2 SOC Analyst at MSSPs, enterprise SOCs, and incident response teams.
  • Tier 1 and Tier 2 in a single program

Upcoming Start Dates

September 28, 2026
4 spots left

Who is this program for?

From career changers to IT professionals looking to transition into securityโ€”this program will train you to become a fully qualified SOC Analyst.

CAREER CHANGER

You want to work in one of the most in-demand roles in cybersecurity. No IT background requiredโ€”weโ€™ll help you build the technical foundation. From Windows and Linux to SIEM analysis and incident response. Through our network of partners, weโ€™ll actively help you find an employer whoโ€™s a good fit for youโ€”with no guarantees, but with genuine dedication.

IT PROFESSIONAL

Youโ€™re already working in IT and want to advance to a specialized security role. Your existing knowledge of networking or system administration gives you a head startโ€”weโ€™ll add the SOC layer: from alert management and log analysis to forensic investigation and cloud security.

STARTER

You want to enter the job market right away as a security specialist. With proven hands-on experience as a Tier 1 and Tier 2 SOC Analyst, preparation for international certifications, and a profile that makes you immediately employable, youโ€™ll enter the workforce with a stronger foundation than most graduates. Through our network of partners, we actively help you find the right fitโ€”with no guarantees, but with genuine dedication.

What will you learn?

No theory for theory's sake. You'll learn to work with the tools and methods that SOC analysts use every dayโ€”developed with and validated by experts in the security industry.
SIEM & ALERT MANAGEMENT

Youโ€™ll learn how to work with Splunk and Microsoft Sentinel: from setting up data connectors and parsing logs to writing your own correlation rules in KQL and SPL. Youโ€™ll triage high volumes of alerts, filter out false positives, and handle security alerts independently.

INCIDENT RESPONSE

You will learn to handle incidents according to the NIST/SANS lifecycle: from detection and containment to recovery. You will work with ticketing systems such as Jira and TheHive, conduct forensic investigations on disk and memory, and document every step to ensure a complete chain of evidence.

NETWORK & TRAFFIC ANALYSIS

You analyze network traffic using Wireshark, decrypt TLS connections, and identify attack patterns at the protocol level. You understand how firewalls, IPS, and WAFs work together and know where anomalies occur in the network.

CLOUD SECURITY & AI

You'll learn how to detect and respond to security incidents in AWS and Azureโ€”from IAM misconfigurations to container security. You'll also use AI tools to write queries faster, summarize incidents, and generate reports that are ready for management.

Structure of the Program

7 modules, ranging from IT fundamentals to advanced SOC operations. Each module combines theory with hands-on labsโ€”more than half of the 600 hours is purely hands-on, just like professional security teams do.
IT & SYSTEM FUNDAMENTALS

The foundation for every SOC analyst. Youโ€™ll dive deep into Windows administration: Active Directory, Kerberos, GPO, and the Windows kernel. Youโ€™ll learn Linux through the LPI Essentials program, including shell scripting for analysis tasks. Youโ€™ll also cover identity and access management: OIDC, SAML, NTLM, and VPN. Tools: VMware, Hyper-V, Windows Server, Linux CLI. Duration: 120 hours.

NETWORK & PACKET ANALYSIS

Youโ€™ll develop a deep understanding of network protocols: the OSI model, DNS, HTTP/S, SMTP, and SSL/TLS. Using Wireshark, youโ€™ll learn to decrypt TLS traffic, track sessions, and analyze traffic patterns. Youโ€™ll also learn how defensive hardwareโ€”firewalls, WAFs, IPSs, and proxiesโ€”work together in an enterprise network. Duration: 80 hours.

OFFENSIVE THINKING & MITRE ATT&CK

Youโ€™ll learn about attack techniques so you can better recognize and stop them. Using the MITRE ATT&CK framework, youโ€™ll link attacker behavior to specific detection rules. Youโ€™ll practice with Nmap, Metasploit, SQL injection, privilege escalation, and lateral movementโ€”so that, as an analyst, youโ€™ll understand how an attacker operates. Duration: 80 hours.

SOC TIER 1: SIEM & LOG ANALYSIS

The Essentials of Tier 1 Work. Youโ€™ll learn to understand and configure SIEM architecture, parse Syslog, EventLogs, and JSON payloads, and write your own KQL and SPL queries for correlation and threat hunting. Youโ€™ll practice handling high volumes of alerts and learn to quickly distinguish false positives from real threats. Tools: Splunk, Microsoft Sentinel. Duration: 100 hours.

SOC TIER 2: INCIDENT RESPONSE & FORENSICS

Youโ€™ll dive deeper. Youโ€™ll manage the entire incident response process using Jira and TheHive, perform forensic disk analysisโ€”MFT analysis, registry hives, prefetch logsโ€”and analyze memory using Volatility. Youโ€™ll build SOAR playbooks for automated threat containment. Duration: 80 hours.

AI FOR SOC PRODUCTIVITY

AI is changing the way SOC analysts work. Youโ€™ll learn how to use LLMs to write queries in SQL, SPL, and KQL, automatically summarize incidents, and generate management reports. Youโ€™ll also cover AI governance: data privacy and securing the AI pipeline. Tools: ChatGPT, Copilot, Gemini. Duration: 70 hours.

What should you include on your resume?

LPI Linux Essentials (010-160)

LPI

Included

CompTIA Security+ (SY0-701)

CompTIA

Ready for the Exam

ISC2 Certified in Cybersecurity (CC)

ISC2

Ready for the Exam

ISC2 Certified in Cybersecurity (CC)

ISC2

Ready for the Exam

In addition to your internationally recognized certificates, please bring the following:

  • Verifiable practical experience as a Tier 1 and Tier 2 SOC Analyst
  • SIEM Analysis: Splunk and Microsoft Sentinel, KQL and SPL Querying
  • Incident Response According to the NIST/SANS Lifecycle
  • Forensic Investigation: Disk, Memory, and Network
  • Cloud Security: AWS and Azure, Container Security
  • Using AI tools for faster analysis and professional reports
  • Ready for immediate deployment at MSSPs, enterprise SOCs, and incident response teams

Many training programs introduce you to security. Trivian makes you job-ready. With 330 hours of verifiable hands-on experience, Tier 1 and Tier 2 certifications on your resume, and AI as a daily work tool, youโ€™ll enter the job market as an analyst who can immediately contribute to a professional SOC team.

What do you get in return for your investment?

โ‚ฌโ€” excl. tax
Duration 600 academic hours
Course Load 12โ€“32 hours per week
Class Format online
Location Schiphol-Rijk

Included

Learning StyleHoursDurationDays
Full-time32 hours15 weeks4 days
2 weekdays4 p.m.6 months2 days
2 evenings8 hours10โ€“12 months2 evenings
  • Developed by security service specialists
  • Access to our own training environment with realistic attack simulations
  • Personal guidance and coaching throughout the entire program
  • Access to our alumni network and partner network โ€” for potential job placements, knowledge sharing, and continued growth
  • Your starting point, not your end point โ€” with opportunities to advance to advanced programs and higher-level positions

Financing Options

Finance4Learning

With Finance4Learning, you can easily spread out your investment. The application process is quick, and weโ€™re happy to help you work out what fits your situation. Final approval depends on your personal circumstances.

EMPLOYER PAYS

Many employers cover the full cost of the training. We will provide a detailed proposal.

TEAM QUOTE

Open classes for individual employees, or a customized team program. Weโ€™ll put together a well-reasoned proposal.

Upcoming start dates.

September 28, 2026
4 spots left

Frequently Asked Questions

Noโ€”and thatโ€™s exactly what sets us apart. Most SOC training programs assume you already have a foundation in IT. We build that foundation with you from the ground up: from Windows and Linux to network protocols and SIEM architecture. What we do require: analytical skills, a willingness to work hard, and the ability to read technical English.

A maximum of 16 students per groupโ€”this may vary for advanced training or customized courses. No lecture hallโ€”just a workspace where you receive daily feedback and truly learn by doing.

We do not offer a formal guarantee. What we do offer: a profile that is immediately applicable and recognized by employers, active placement support through our alumni network and partners, and a track record of graduates who go on to join SOC teams, become network administrators, and work as security consultants.

A SOC Analyst's salary typically starts around โ‚ฌ3,000 per month and can go up to โ‚ฌ5,500, depending on your level, specialization, and employer.

Classes are taught in Dutch. The course material, tools, and exams are in Englishโ€”which is also the standard practice in this field. A solid reading proficiency in English is sufficient to get started. A few times a year, we also offer a class taught entirely in Englishโ€”please contact us for the dates.

What sets this program apart: youโ€™ll be ready to work as a SOC Analyst in a relatively short time, youโ€™ll earn recognized certifications that employers actively seek, and the costs are significantly lower than those of a full-fledged college degree or individual commercial training courses. This is a job-focused programโ€”not a broad academic program, but direct preparation for the workplace. The decision is yours.

Upon completion, youโ€™ll be ready to take the exams for three internationally recognized certifications. The LPI Linux Essentials exam is included in the program, and youโ€™ll take it during the course. For CompTIA Security+ (SY0-701) and ISC2 Certified in Cybersecurity (CC), youโ€™ll complete the program fully prepared for the exam. These certifications are recognized worldwide by employers in finance, defense, healthcare, and high-tech.

Yes. The program is available in several formats, so you can choose the one that best suits your situation. The 600 hours can be spread out over 6 to 12 months, depending on your availability. All formats are hybrid: a combination of online and in-person sessions in Schiphol-Rijk. A fully online option is available upon request.

We don't offer any guaranteesโ€”that would be unfair. What we do offer: personalized guidance, small groups, and a learning environment where you're constantly challenged and supported. We're right by your side every step of the wayโ€”from the first class to the exam.

Ready for the next step?

Schedule a no-obligation consultation or view the start dates.

SOC T1 + T2 Analyst

Enter your information and we'll contact you within one business day. Together, we'll discuss whether this program is a good fit for your situation. You're not committing to anything yet.

By sharing your details, youโ€™ll receive our monthly newsletter with course start dates and cybersecurity insights. You can unsubscribe at any time.