Live, Instructor-Led Programme
Security Operations
Monitor threats. Investigate alerts.Respond with confidence.

8 Weeks
6.5 hrs/week
across two class days
Instructor-Led, Virtual
C$999
Security Operations Programme
Transition into High-ImpactSecurity Operations & Analyst Roles
This live, hands-on programme teaches you how SOC teams work every day. You'll learn SIEM monitoring and detection, vulnerability management, threat intelligence, incident response, malware analysis, and endpoint detection and response.
Practical & Applied
Hands-on labs, tools and scenarios that mirror real SOC workflows.
Real-World Investigations
Investigate alerts and build reports using realistic case studies.
Expert Instructors
Learn from practitioners with deep SOC and IR experience.
Threat-Informed
Work with current threat intel and attack techniques.
Career Confidence
Build skills and artefacts that strengthen your analyst profile.
Certificate of Completion
Earn a ReveCyber Certificate upon successful completion.
Security Operations Programme
C$999
Instructor-Led, Virtual
8 Weeks
6.5 hrs/week
across two class days
Small class size
Live sessions, not recorded
Have questions?
Our advisors are here to help.
Secure your seat today.
Places are limited.
Practical Work You Will Complete
By the end of the programme, you will build a portfolio of security operations artefacts you can apply on the job.
SIEM DetectionUse Cases
Alert InvestigationReport
VulnerabilityManagement Plan
Threat IntelligenceBrief
Incident ResponsePlaybook
Malware AnalysisReport
EDR Investigation& Response
A Structured Eight-Week Learning Journey
- How a SOC is structured: tiers, roles and escalation
- Core processes: monitoring, triage, escalation and reporting
- Log sources and security telemetry across the estate
- The tooling landscape: SIEM, EDR, SOAR and threat intel
- Log ingestion, parsing and normalisation
- Writing detection rules and use cases
- Building dashboards and monitoring views
- Tuning to reduce false positives
- Triage workflow and severity assessment
- Pivoting across logs, hosts and network data
- Documenting findings and evidence
- Writing clear analyst investigation reports
- Scanning, asset coverage and validation
- CVSS scoring and risk-based prioritisation
- Remediation tracking and SLAs
- Reporting vulnerability posture to stakeholders
- Strategic, operational and tactical intelligence
- IOCs, TTPs and the MITRE ATT&CK framework
- Enriching alerts with threat context
- Producing a concise threat intelligence brief
- The IR lifecycle: prepare, detect, contain, eradicate, recover
- Building and running incident playbooks
- Communication, escalation and stakeholder updates
- Post-incident review and lessons learned
- Static and dynamic analysis basics in a safe lab
- Behavioural indicators and persistence techniques
- Investigating endpoints with EDR telemetry
- Containment and response actions on the endpoint
- End-to-end SOC capstone scenario
- Executive and technical reporting
- Assembling your analyst artefact portfolio
- Interview preparation for SOC analyst roles
Designed for aspiring SOC Analysts, Security Operations Analysts and incident response professionals.
Career changers, IT support and infrastructure professionals, and analysts moving into detection and response.
