Beyond the Alert

DTCC's AJ Jarrett on Interview Questions That Predict SOC Performance


Listen Later

Andrew “AJ” Jarrett, Director of Cyber Monitoring & Incident Response at DTCC, applies emergency response frameworks from his firefighting career to build SOC teams that execute under pressure rather than panic. His approach centers on the Incident Command System, where establishing clear roles, management by objectives, and documentation unit leaders replaces ad-hoc crisis response. Even junior analysts cycle through incident commander roles, building muscle memory for when real incidents strike at 2AM. 

The apprenticeship pipeline in cybersecurity faces an existential threat as organizations rush to replace tier one analysts with AI. AJ identifies this as the critical challenge for the next 5 years, not because automation is wrong but because eliminating entry-level roles breaks the path to developing tier-three analysts and team leads. His interview process prioritizes soft skills over technical certifications, asking candidates about their stress management systems, ethical decision-making frameworks, and whether they have hobbies beyond studying more cybersecurity. 

Topics Discussed:

  • How the Incident Command System from emergency response creates SOC teams that execute rather than panic when incidents strike.
  • Why reducing signal-to-noise ratios through obsessive tuning matters more than adding new security tools for managing alert volume.
  • Interview questions that reveal whether candidates can handle SOC pressure, such as about their support systems and personal ethics.
  • Why promoting technical experts into people management roles without leadership development creates more bad managers.
  • How PTO as "prepare the others" ensures analysts can disconnect completely rather than remaining tethered to unfinished work.
  • The apprenticeship crisis emerging as organizations eliminate tier-one roles without preserving the pipeline for developing senior analysts.
  • Why AI analysts need extensive training from senior team members before junior analysts can learn from them without oversight.
  • Moving security budget conversations from fear, uncertainty, and doubt toward quantified risk management that executives can evaluate.
  • The shift from location-based security models to zero trust architectures accelerated by pandemic-driven remote work adoption.
  • Listen to more episodes: 

    Apple 

    Spotify 

    YouTube

    ...more
    View all episodesView all episodes
    Download on the App Store

    Beyond the AlertBy Dropzone AI