SIEM vs. SOAR vs. EDR
Three security-operations tools that show up together on SOC analyst resumes. A SIEM collects logs from across the company and raises alerts. SOAR automates the response to those alerts with playbooks. EDR watches individual laptops and servers for malicious activity and can isolate them. An analyst who 'worked with Splunk' monitored alerts; one who built SOAR playbooks or tuned detections did engineering.
How to tell them apart on a resume
SIEM (collect and alert)
Splunk, Microsoft Sentinel, QRadar, ArcSight, Elastic, writing detection rules or queries, log sources — the SOC's main screen.
SOAR (automate response)
Splunk SOAR (Phantom), Cortex XSOAR, Sentinel playbooks, Python scripting, automated triage — reducing analysts' manual work.
EDR / XDR (endpoints)
CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black, isolating machines, threat hunting on devices.
The question that settles it
“Did you mostly respond to alerts others had set up, or write the detection rules and automation yourself — and in which tool?”
Read the full definitions
Open the full tool for the other look-alike pairs, role profiles, and the JD decoder.