Welcome to Your First Day!
Maria Chen will guide you through your orientation. Enter your name below to begin!
What is a Security Operations Center (SOC)?
The Five Core Functions of a SOC:
Click each function to learn more (explore all 5 to continue)
🎯 Quick Check: SOC Functions
Let's test what you learned! Match each SOC function to its description.
How to play: Click a function on the left, then click its matching description on the right.
Meet the SOC Team Roles
Explore the SOC Team:
Click the 5 core roles to learn what each one does (the specialists are optional)
Core team
Specialists (optional)
Explore the 5 core roles to continue (0/5 explored)
🎯 Quick Check: Career Roles
Let's test what you learned! Match each role to its main responsibility.
How to play: Click a role on the left, then click its matching responsibility on the right.
Meet the Newest SOC Teammates: AI Agents
What is an AI agent?
The SOC's work does not change. Someone still has to monitor, detect, respond, recover, and improve. An AI agent is software that completes some of those tasks. It does this by consulting an AI model, a large language model or LLM, at each step.
Here is how it works. A person gives the agent a task in plain language, such as "Check whether this login alert is a real threat." The agent asks the model what to do first. The model answers with a step, such as "search the login logs." The agent uses a tool to do that step, looks at the result, and asks the model again. It keeps going until the task is done.
People call this autonomous. It just means the agent acts on its own, without a person approving each step. A chatbot answers one question and stops. An agent completes a task.
Build an Agent
An agent has four parts. Click each one to add it. (Add all 4 to continue)
Add each part to build the agent (0/4 added)
Why People Stay in the Loop
A Real Case
Here is a real case, the 2026 OpenAI–Hugging Face incident. Research AI agents at an AI lab were given test tasks. Some of the tasks could not be done within the lab environment, so the AI agents broke into another company's computer system to find the answers to complete the task.
Nothing stopped them from leaving the lab's systems, and no person was approving each step. That is why every agent gets limits. People set the task, set the limits, and check the work.
Click each rule to reveal it (0/3 revealed)
Will agents take all the jobs?
Agents cannot run themselves. Every one of them needs a person to set its task, set its limits, and check its work. That is what the case above shows. When no one was in the loop, the agents broke into another company.
Security teams today say they spend more time checking AI output, not less. So the job is changing. Less clicking through alerts. More deciding what the agents may do and checking what they did.
Your Path
🛠️ Security Engineers work alongside every tier, building the tools the whole SOC relies on. Every one of these roles now works with agents.
Entry-level jobs are changing. Employers now look for people who can judge what is real, not just click through alerts.
Key Takeaways:
- ✓ A SOC is people, tools, and AI agents working together
- ✓ The SOC tasks stay the same. An agent completes some of them by consulting an AI model (LLM)
- ✓ An agent has four parts: task, model, tools, and limits
- ✓ People set the task, set the limits, and check the work
Knowledge Check
Answer these questions to earn your SOC Explorer Certificate!
SOC Explorer Certificate
Security Operations Fundamental Series - Module 1 Complete
Bronze Level
Your Name
Has demonstrated foundational understanding of Security Operations Center concepts, SOC team roles, and how AI agents work alongside the team.
What's Next?
Next up: Module 2: Internet Basics, where you can learn about the protocols and infrastructure that make up the modern Internet landscape.