Security Operations & SOC Analyst Program
Hands-on security operations — log analysis, SIEM detection engineering, MITRE ATT&CK, alert triage, threat hunting, incident response and reporting — built around realistic attack scenarios.
Covers CompTIA Security+ / CySA+ operations domains
- Duration
- 4 days
- Level
- Intermediate
- Delivery
- Live Online · Classroom · On-Site Corporate
- Location
- Live Online · Dubai · GCC
- Certificate
- Certificate of Completion
- Format
- Instructor-Led
Course overview
Designed for organisations building or upgrading SOC capability. Participants investigate real attack chains in a lab SIEM and leave with a repeatable triage and response methodology.
Who should attend
- SOC analysts (tier 1–2)
- IT staff moving into security
- Security teams in banks, government and critical infrastructure
Prerequisites
- Networking and operating system fundamentals
Learning objectives
- 1Analyse logs from endpoints, networks and cloud
- 2Write and tune detections in a SIEM
- 3Triage alerts using MITRE ATT&CK
- 4Run structured incident response
- 5Hunt for threats proactively
Detailed curriculum
01Foundations
- Threat landscape and attacker tradecraft
- Log sources and telemetry
- SIEM architecture
02Detection
- Detection engineering and rules
- MITRE ATT&CK mapping
- Tuning and false positives
03Response
- Triage workflow
- Incident response phases
- Containment and eradication
- Reporting and lessons learned
04Hunting & Practice
- Threat hunting hypotheses
- Attack simulation walkthroughs
- Metrics and SOC maturity
Day-by-day agenda
Day 1
- Foundations
Lecture, whiteboard analysis, exercises and lab time.
Day 2
- Detection
Lecture, whiteboard analysis, exercises and lab time.
Day 3
- Response
Lecture, whiteboard analysis, exercises and lab time.
Day 4
- Hunting & Practice
Lecture, whiteboard analysis, exercises and lab time.
Hands-on exercises & labs
- Investigate a phishing-to-ransomware chain in the lab SIEM
- Write and tune detection rules
- Full incident response exercise with reporting
Skills gained
Instructor
Instructor profile — to be added
Name, engineering background and delivery experience of the assigned instructor will be published here. No credentials are shown until confirmed.
Training methodology
Instructor-led
Concepts explained by engineers with delivery experience, at whiteboard depth.
Trace & case driven
Real message flows, counters and scenarios connect theory to network behaviour.
Hands-on
Labs and design workshops matched to the program and delivery mode.
Available locations
Live online region-wide. Classroom and on-site delivery available in Dubai and across major GCC locations, arranged per cohort or corporate engagement.
Upcoming schedule
| Delivery | Location | Duration | Next cohort | |
|---|---|---|---|---|
| Classroom | Dubai | 4 days | Q4 2026 · Dates to be announced | Register Interest |
| Live Online | Live Online | 4 days | Q1 2027 · Dates to be announced | Register Interest |
Cohort dates are published when confirmed. Register interest to be notified first, or request a corporate delivery on your own dates.
Frequently asked questions
Live online programs are delivered in real time by an instructor over video with shared labs and interactive Q&A. Classroom programs are delivered face to face in Dubai or other GCC locations, with the instructor and lab environment in the room. Both use the same curricula and instructors.
Programs are built on 3GPP, O-RAN and industry standards and are vendor-agnostic by default. Corporate deliveries can include vendor-specific parameter mapping and scenarios where required.
Participants who complete a program receive a Teleriu certificate of completion. Teleriu programs are professional technical training and are not affiliated with any certification body unless explicitly stated.
Related programs
Cloud Security & Compliance (AWS / Azure)
Banking IT Resilience & Cybersecurity
Bring SOC Analyst to your engineering team
Customised for your vendors, architecture and objectives — delivered on-site, in the classroom or live online.