SCHOOLREGISTRY ACADEMY · COURSE GUIDE

Security Operations Tier 1 Certificate

A ten-week certificate course in Tier 1 security operations, taught on a real SIEM inside Greyfern Security Operations, a fictional managed SOC with two clients: Tamarind Pay, a Lagos fintech, and Brasswick Manufacturing in Denver. Twelve alert classes with runbooks, 60 scripted incidents, the auto-closure sample every shift, the SIEM outage drill, and the ticket that carries what you do not know yet. Every lesson maps to CompTIA Security+ SY0-701 objectives. Two lanes chosen at enrolment: the Lagos SOC market, or the US market for work-authorised residents.

Start: October 12, 2026 · 11 AM WAT (Nigeria).
Fee: ₦200,000 for this track, or two ₦100,000 installments with the balance due three weeks later.
Format: Ten weeks: eight of lessons, assignments and one live class a week, then two practicum weeks of timed shifts on the track's job simulator. Your track’s live-session day and time are confirmed at enrolment.

What you will learn

Your curriculum

Week 1: What a Tier One analyst does, and for whom

The SOC, its tiers and its clients; the shift, the queue and the log; the analyst's line; the ticket someone else can act on; the tools of the desk; severity and priority; the two lanes.

Week 2: Security fundamentals as they look in logs

The CIA triad; threat actors in outline; attack surfaces; the kill chain and MITRE ATT&CK; phishing, malware, brute force, web attacks, MFA fatigue and cloud misconfigurations as they appear in the logs.

Week 3: Networks and endpoints for an analyst

Addresses, ports and DNS; HTTP and TLS in outline; the endpoint agent and the process tree; Windows event ids and Linux auth logs; the identity provider; service accounts; reading, never configuring.

Week 4: The SIEM

What a SIEM is and is not; Wazuh from the console; searching and pivoting; saved searches; the second client in Elastic; reading a detection rule and its Sigma rule; noise, tuning and the auto-closure sample.

Week 5: Triage and investigation

The four verdicts; the runbook in order; evidence and the chain; the phishing wave; the brute force that is a service account; the AI verdict you validate; the ticket; time to triage; escalations that bounce.

Week 6: Incidents from the analyst's seat

Incident response in outline; containment requested, never executed; the ransomware precursor; the manager who wants a ticket closed; the executive who wants a name; the SIEM outage drill; the six-hour miss reported as it is.

Week 7: Identity, vulnerabilities, compliance and data

Least privilege and your own access; vulnerability findings as tickets and CVSS read not computed; CBN and the NDPA named for the Lagos SOC, CMMC, NIST 800-171 and SOC 2 named for the US client; evidence never leaves the environment; the analyst as a target.

Week 8: Working the job, and the capstone

The handover and the weekly report; metrics read honestly; the portfolio of simulator work; Security+ SY0-701 and confirming the live exam code before you book; the two markets honestly; interview questions answered with your own tickets; the capstone.

Week 9: Practicum, part one

Timed shifts on Greyfern with alerts arriving at realistic rates on both clients, the auto-closure sample every shift, and every ticket graded on its evidence chain and its open questions.

Week 10: Practicum, part two

More shifts including the SIEM outage drill, the six-hour miss reported as it is, the request you must refuse, and a tutor-marked capstone. Passing needs zero critical errors.

Prepare to participate

Plan for a computer, headset, reliable internet, a quiet practice space, and time for assignments. Review the student handbook for assessment, access, and policy details before payment.

Certification

Issued by SchoolRegistry Academy when the track’s assessment requirements are met. It is not third-party accreditation and does not promise job placement.

View the course and enroll ↗

Questions: hello@schoolregistry.ng

Use Print → Save as PDF for a PDF copy. Course guide · September 2026.