Logs, SIEM, detection engineering, hardening and cloud: the tooling that runs a SOC.
Anyone can read an alert somebody else wrote. You get paid for turning "these logons feel off" into a rule that fires tomorrow morning and does not bury the queue in noise. That skill is the line between a junior analyst and the person who keeps the SOC running. The cloud half is the same job with a role instead of a host and a log source nobody switched on.