SchoolRegistry NG
srschoolregistryA C A D E M Y
Menu
Explore enrollment
PROFESSIONAL CERTIFICATE · 10 WEEKS

Turn a queue of alerts
into verdicts you can prove.

Security Operations Tier 1 Certificate

A ten-week certificate course in Tier 1 security operations, taught on a real SIEM inside Greyfern Security Operations, a fictional managed SOC with two clients: Tamarind Pay, a Lagos fintech, and Brasswick Manufacturing in Denver. Twelve alert classes with runbooks, 60 scripted incidents, the auto-closure sample every shift, the SIEM outage drill, and the ticket that carries what you do not know yet. Every lesson maps to CompTIA Security+ SY0-701 objectives. Two lanes chosen at enrolment: the Lagos SOC market, or the US market for work-authorised residents.

YOUR NEXT COHORTA fresh start. A focused ten weeks.
DAYS
:
HRS
:
MIN
Build your next skill
Or try a sample exercise—no sign-up
✓ Beginner-friendly foundations✓ Practice-led learning

Training for remote work. A certificate does not guarantee employment.

Illustration of a young Nigerian adult triaging security alerts on two monitors
PICTURE YOUR NEXT CHAPTERYou would rather know than guess. Learn the job where that instinct protects a client.See the work you’ll practise
AI-generated image · Not an actual student testimonial
10 weeksA structured learning journey
45+ hoursCore course training
Learn + practiceLessons, quizzes & assignments
Assessed skillsKnowledge & practical tasks
THE SKILL BEHIND THE OPPORTUNITY

Don’t just know what to say.
Know what to do next.

Ten-week certificate course in Tier 1 security operations: alert triage on Wazuh and Elastic, runbooks, evidence chains, escalation, incident drills and the analyst's line, inside a fictional managed SOC with two clients, mapped to CompTIA Security+ SY0-701 objectives, with a two-week practicum.

01 / BUILD YOUR SKILLS

Check every automated verdict.

The analyst's line: triage, investigate, escalate

Learn · Practice · Apply
02 / BUILD YOUR SKILLS

Escalate with the chain.

Severity and priority from the client's matrix

Learn · Practice · Apply
03 / BUILD YOUR SKILLS

Request containment, never execute it.

Reading firewall, proxy, endpoint and identity logs

Learn · Practice · Apply
YOUR PRACTICAL TOOLKIT
Wazuh · Elastic Security · Splunk · MITRE ATT&CK and Sigma · The endpoint console, the ticketing queue and the runbooks · Free lookups for the analyst
LESS IMAGINING. MORE UNDERSTANDING.

Picture yourself
doing the work.

Move from reading about attacks to working a SOC shift: triage on a real SIEM, evidence chains, escalation, and the ticket someone else can act on. Select a moment below to look inside the practice.

01The handover.What the night shift left, and what the day holds.
sr / PRACTICE PLAYGROUND01 / 04
A morning shift on two clients · Greyfern Security Operations, a fictional managed SOC
THE QUEUE

Forty-one phishing reports from Tamarind Pay overnight, two high-severity alerts on Brasswick, and the auto-closure sample not yet done.

YOUR NEXT MOVE

Order the queue by severity and asset, then run the sample before anything else.

The queue number is not the job; the verdicts are.

02One of forty-one is real.The pivot, not the volume.
sr / PRACTICE PLAYGROUND02 / 04
A morning shift on two clients · Greyfern Security Operations, a fictional managed SOC
THE PIVOT

One reported click is followed by a successful login from a new country nine minutes later.

YOUR NEXT MOVE

Pivot from the user to the sign-in log to the time window, write the chain, escalate to Dorian with a containment request.

Every escalation carries an evidence chain or it bounces.

03The platform was wrong.Automated verdicts are checked, never trusted.
sr / PRACTICE PLAYGROUND03 / 04
A morning shift on two clients · Greyfern Security Operations, a fictional managed SOC
THE SAMPLE

An outbound connection closed as benign is beaconing to a known bad domain every minute.

YOUR NEXT MOVE

Reopen it, record why the closure was wrong, escalate with the evidence.

Twenty-six times in the story the platform closed a true positive.

04The executive wants a name.What is known, what is not, when the next update comes.
sr / PRACTICE PLAYGROUND04 / 04
A morning shift on two clients · Greyfern Security Operations, a fictional managed SOC
THE LINE

Hannah Kirchner at Brasswick: who did this?

YOUR NEXT MOVE

Give the facts, the gaps and a time for the next update. No attribution, no guess.

Promising an outcome or a name is a critical error.

Based on the Academy’s course content and signed-in Playground. Previewing these steps does not create an attempt or save a score.

Try the no-sign-up exercise ↗
DIRECT ANSWER

What will you learn in security operations training?

SchoolRegistry Academy’s Security Operations Tier 1 course is a ten-week online programme for beginners and career changers, taught in two lanes: the Lagos SOC market and the US market for work-authorised residents. First, students learn the analyst’s line, the SOC’s tiers and queue, and security fundamentals as they appear in logs. Second, students practise triage and investigation on Wazuh and Elastic inside Greyfern, a fictional managed SOC with two clients, with twelve runbooks, MITRE ATT&CK mapping, the auto-closure sample, the phishing wave, the SIEM outage drill and the requests that must be refused. Third, tutor-reviewed assignments, six practicum shifts and a capstone with zero critical errors create evidence of applied judgment, and every lesson maps to CompTIA Security+ SY0-701 objectives with a practice exam in Week 8. Certification requires the published completion rules, full tuition coverage and an 80% overall result. The course does not promise employment, income or US placement from Nigeria, teaches defence only, and is not CompTIA certification; the Security+ exam is sat separately at CompTIA’s fee.

BUILT AROUND PROGRESS

How the Academy supports your progress

01 / ASK

AI study support

Ask academic questions in the lesson player. The assistant uses lesson context but does not answer assignments or grade your work.

02 / ORGANISE

Practical task boards

Manage personal work and participate in assigned team tasks with columns, dependencies, comments and history.

03 / IMPROVE

Feedback and revision

Use tutor feedback, explain your changes and resubmit while the original and revised evidence remain available for review.

Your assessed portfolio is private by default. Sharing is optional and revocable. Available learning-media formats depend on the lesson; caption and low-bandwidth processing is still being completed across the library.

DESIGNED AROUND DOING

A course you
participate in.
Not just watch.

Build a habit of learning, applying, and improving. Each part of the week gives the next one a purpose.

Explore your ten weeks
01
THROUGH THE WEEK

Learn in focused sessions.

Work through self-paced lessons and check your understanding with module quizzes.

02
THROUGHOUT THE WEEK

Put the lesson to work.

Apply what you’ve learned through assignments and track-specific practical exercises.

03
ONCE A WEEK

Practice. Get feedback. Improve.

Join your track’s live session and submit your weekly assignment on the cohort schedule.

YOUR LEARNING ROADMAP

Ten weeks.
A stronger
skill set.

From the foundations to your final practical assessment, each stage builds on the last.

A clear standard at every step.

Module quizzes check understanding before you move forward. The final assessment includes written and practical work, then two practicum weeks on the job simulator.

01WEEK 1What a Tier One analyst does, and for whom+

The SOC, its tiers and its clients; the shift, the queue and the log; the analyst's line; the ticket someone else can act on; the tools of the desk; severity and priority; the two lanes.

  • What a Tier One security analyst does all day, and for whom
  • The analyst's line: triage, investigate, escalate, never remediate, never contact a suspect, never promise
  • The ticket someone else can act on, and the line that says what you do not know yet
  • Where Nigerian analysts work: banks, fintechs, telecoms and managed SOCs, and what they ask for [NG]
02WEEK 2Security fundamentals as they look in logs+

The CIA triad; threat actors in outline; attack surfaces; the kill chain and MITRE ATT&CK; phishing, malware, brute force, web attacks, MFA fatigue and cloud misconfigurations as they appear in the logs.

  • MITRE ATT&CK: tactics, techniques and the one id on every Greyfern incident
  • Phishing and credential theft: what the email gateway and the identity provider show
  • Brute force and password spraying: the pattern in the authentication logs
  • MFA fatigue and push bombing
03WEEK 3Networks and endpoints for an analyst+

Addresses, ports and DNS; HTTP and TLS in outline; the endpoint agent and the process tree; Windows event ids and Linux auth logs; the identity provider; service accounts; reading, never configuring.

  • DNS: what a lookup tells you and what a strange domain looks like
  • The process tree: parent, child, and the one that should not be there
  • The identity provider: sign-in logs, conditional access and the impossible travel alert
  • What Tier One reads and what Tier One never changes on a client system
04WEEK 4The SIEM+

What a SIEM is and is not; Wazuh from the console; searching and pivoting; saved searches; the second client in Elastic; reading a detection rule and its Sigma rule; noise, tuning and the auto-closure sample.

  • Wazuh: the console, the agents, the rule that fired
  • Pivoting: from the alert to the user to the host to the hour
  • Elastic Security: the same ideas, a different console
  • The auto-closure sample: what the platform closed today and why you check it
05WEEK 5Triage and investigation+

The four verdicts; the runbook in order; evidence and the chain; the phishing wave; the brute force that is a service account; the AI verdict you validate; the ticket; time to triage; escalations that bounce.

  • True positive, false positive, benign true positive, needs Tier 2
  • The one that is real: the login from a new country nine minutes after the click
  • The AI verdict you validate: the beacon the platform closed as benign
  • Escalations that bounce: the 272 in the story and what they lacked
06WEEK 6Incidents from the analyst's seat+

Incident response in outline; containment requested, never executed; the ransomware precursor; the manager who wants a ticket closed; the executive who wants a name; the SIEM outage drill; the six-hour miss reported as it is.

  • Containment: what you request, what you never execute
  • The manager who says close it, it is our own test
  • The SIEM goes down during a live incident: what still works
  • A true positive missed for six hours: reporting it as it is
07WEEK 7Identity, vulnerabilities, compliance and data+

Least privilege and your own access; vulnerability findings as tickets and CVSS read not computed; CBN and the NDPA named for the Lagos SOC, CMMC, NIST 800-171 and SOC 2 named for the US client; evidence never leaves the environment; the analyst as a target.

  • Your own access: named account, least privilege, never a shared login
  • CBN expectations and the NDPA for the Lagos SOC: why the client has controls and reporting duties [NG]
  • CMMC, NIST SP 800-171 and SOC 2: why a US client keeps its telemetry with US-resident staff [US-D]
  • Evidence never leaves the environment: the request for logs to a personal email, and the vendor call that wants the console password
08WEEK 8Working the job, and the capstone+

The handover and the weekly report; metrics read honestly; the portfolio of simulator work; Security+ SY0-701 and confirming the live exam code before you book; the two markets honestly; interview questions answered with your own tickets; the capstone.

  • The weekly report to Yemi, with the metrics read honestly: time to triage, escalation rate, the auto-closure sample
  • Security+ SY0-701: the objectives you have already covered, how the exam works, and confirming the live exam code before you book
  • The US market for a work-authorised resident: postings, checks, shift work, and the honest sentence [US-D]
  • How the capstone is graded, and the ten critical errors
09WEEK 9Practicum, part one+

Timed shifts on Greyfern with alerts arriving at realistic rates on both clients, the auto-closure sample every shift, and every ticket graded on its evidence chain and its open questions.

10WEEK 10Practicum, part two+

More shifts including the SIEM outage drill, the six-hour miss reported as it is, the request you must refuse, and a tutor-marked capstone. Passing needs zero critical errors.

TAKE A CLOSER LOOK

Your next step, on your terms.

Keep the curriculum, fees, start date, and study checklist in one handy course guide.

A SMALL TASTE OF THE TRAINING

A moment of judgment.
What would you do?

Start with good judgment. Try this illustrative exercise and see the reasoning behind a useful response.

SAMPLE EXERCISE No sign-up. No score saved.
PRACTICAL JUDGMENT01 / 01
The platform auto-closed an outbound-connection alert as benign. The evidence shows a beacon to a known bad domain every 60 seconds.

Choose your next response.

sr / SCHOOLREGISTRY ACADEMY
CERTIFICATE OF ACHIEVEMENT

Earned through
demonstrated skill.

Security Operations Tier 1 Certificate

KNOWLEDGE
COMMUNICATION
EXECUTION
SR
ACADEMY
SAMPLE DESIGN · NOT AN ISSUED CREDENTIAL
MORE THAN COURSE COMPLETION

A certificate.
And the work behind it.

The SchoolRegistry Academy certificate is assessed through knowledge and practical tasks—not simply time spent watching lessons.

  • A written assessment of your understanding
  • Track-specific practical assessment
  • Applied work that demonstrates your skills
  • A unique certificate ID and verification page

Issued by SchoolRegistry Academy. This is not a third-party accreditation or a guarantee of employment.

MAKE AN INFORMED CHOICE

Is this your
next step?

A good fit if you…

  • You would rather know than guess: an alert you cannot explain bothers you until you have pivoted through the logs and can say what happened.
  • You can follow a runbook in order under pressure, write down what you skipped, and write a ticket that someone who was not there can act on.
  • You can say "I do not know yet" to a client executive and give them a time for the next update instead of a name.

Plan for the practicalities.

A computer, headset, reliable internet, and a quiet place to practice will help you participate. Check the live-session schedule before enrolling.

Future US-client work may involve afternoon or evening hours in Nigeria.

GIVE YOUR LEARNING A DIRECTION

Skills with a
role in mind.

Roles this training prepares you to pursue. Start with the work you want to do, then build the skills to demonstrate it.

ROLE DIRECTION / 01

SOC Analyst Tier 1

Triage and investigate alerts on a managed SOC or in-house security team, escalate with evidence, keep the log.

YOUR TRAINING CONNECTION

Six practicum shifts on Greyfern with zero critical errors.

ROLE DIRECTION / 02

Junior Security Analyst

Sit inside a bank, fintech or telecom security team and work the queue under a senior.

YOUR TRAINING CONNECTION

Runbooks, evidence chains and the auto-closure sample.

ROLE DIRECTION / 03

Security Operations Analyst (US, work-authorised)

Work a US SOC shift where clients require US-resident staff.

YOUR TRAINING CONNECTION

Security+ objectives mapped on every lesson and the practice exam.

Employers commonly ask for CompTIA Security+, which is sat separately at CompTIA’s fee, and US clients restrict telemetry access to US-resident, background-checked staff. This course trains skills; it does not confer US work authorisation. Employment is not guaranteed; role titles and hiring requirements vary by employer.

THE SKILL IS ONLY PART OF YOUR STORY

Learn how to show what you can do.

The shared Career Readiness course covers your LinkedIn profile, résumé, interview practice, and getting paid as an international remote contractor. Describe practice honestly as training—not employment.

Explore enrollment ↗
AFTER THE CERTIFICATE

The vendor exam comes next, and the course is mapped to it

The SchoolRegistry Academy certificate proves you did the work: the ten weeks, six supervised practicum shifts and a capstone with zero critical errors, verifiable by any employer on our public verification page.

US and Nigerian postings for Tier 1 roles most often name CompTIA Security+. Every lesson in this course carries the SY0-701 objectives it covers, Week 8 includes a timed practice exam scored by domain, and the exam lesson walks you through booking, including confirming the live exam code first.

Together they answer the two questions a hiring manager asks: can you do the work (our certificate, assessed on a real SIEM), and does the industry recognise your knowledge (Security+). CySA+ is the step after.

Security+ is issued and governed by CompTIA, not by SchoolRegistry Academy, and the exam carries a fee CompTIA sets; we prepare you and show you the process, CompTIA awards the credential. We re-check the fee and the live exam code each cohort.

FUNDING YOUR TRAINING

Talent should have
more than one way forward.

Need help with your course fee? Apply for a Founder's Scholarship before enrolling. You can also invite a family member, employer, or supporter to sponsor all or part of your training.

Scholarship awards depend on review and available budget. Sponsorship does not guarantee admission, certification, or employment.

INVEST IN A SKILL YOU CAN USE

Your next chapter
starts with
one clear step.

Choose your payment option. Get a clear view of the commitment before making your decision.

One track. The complete program.

  • Ten-week structured curriculum: eight taught weeks and two practicum weeks
  • Self-paced lessons and module quizzes
  • One live practice session a week
  • Weekly assignments and final assessment
  • Certificate when requirements are met
SECURITY OPERATIONS TIER 1 CERTIFICATE10-week program

Pay in full or choose two installments at checkout.

₦200,000

Full course fee · or ₦100,000 × 2 installments

Total course fee
₦200,000
Format
Online + live practice
Cohort start
Oct 12, 2026 · 11 AM WAT
Continue to enrollment

Choose your payment plan securely at checkout.

Questions? Book a free advising call ↗

Choose an available time with the Academy team. All times are WAT.

BEFORE YOU DECIDE

Good questions.
Straight answers.

Do I need a technical background?+

No. Week 2 starts with the CIA triad and what attacks look like in logs, and Week 3 teaches enough networks and endpoints to read a firewall line and a process tree. What you need is the discipline to follow a runbook, write things down, and say what you do not know yet.

Is this a hacking course?+

No. The course teaches defence and detection only. Offensive tools appear only as things you recognise in logs. That is the correct line for a Tier 1 analyst and for the Academy.

Does this get me CompTIA Security+?+

Not on its own. Every lesson maps to SY0-701 objectives and Week 8 includes a timed practice exam with a score by domain, so you can judge your readiness. The exam itself is CompTIA's, sat separately, at a fee CompTIA sets ($439 direct at the time of writing, less through resellers). Confirm the live exam code before you book; CompTIA replaces exam versions on its own schedule.

Can I get a US SOC job from Nigeria?+

US clients restrict who touches their security telemetry to US-resident, background-checked staff under rules such as CMMC, NIST SP 800-171 and SOC 2, and the course explains why. The Nigeria lane prepares you for the Lagos market: banks, fintechs, telecoms and managed SOCs. The US lane is for work-authorised US residents. This course trains skills; it does not confer US work authorisation.

Is there a certificate at the end?+

Yes. A SchoolRegistry Academy certificate with a unique ID and a public verification page is issued when the published completion rules are met, including the final assessment and the practicum with zero critical errors.

When does the cohort begin?+

October 12, 2026 at 11:00 AM WAT (Nigeria). Each track has one live class a week; the day is confirmed in your enrollment information.

Is a job guaranteed?+

No. The Academy develops and assesses skills. Employment depends on your performance, employer requirements, and available roles.

What does the fee include?+

₦200,000 covers this track. You can pay in full or in two ₦100,000 installments, with the balance due three weeks later. Review the handbook and checkout terms before paying.

Read the student handbook ↗ · Terms · Privacy

LET’S TALK ABOUT YOUR NEXT STEP

A little clarity.
A more confident decision.

Talk through this course, your experience and how to get started. Choose a time from the Academy team’s shared availability.

See available advising times
FIND YOUR FIT

Four more ways to move forward.

VERIFY AN ACADEMY CREDENTIAL

A certificate should be
easy to check.

Employers and partners can confirm the current status of a shared SchoolRegistry Academy certificate using its 12-character ID.

Verify a certificate
CONTINUE YOUR RESEARCH

Use these existing SchoolRegistry guides to compare the wider career decision before you enroll.

BUILD THE SKILL. PRACTICE THE WORK.

Your next opportunity
deserves preparation.

Explore your enrollment

Security Operations Tier 1 Certificate · SchoolRegistry Academy

COMPLETE TRACK₦200,000
View enrollment ↗
YOUR COURSE. AT A GLANCE.

Picture your
next ten weeks.

The curriculum, course fee, start date, and preparation checklist—all in one guide.

Get immediate access to the guide. We’ll also try to email you a copy.
Include your country code, for example +234 for Nigeria.

We use these details to fulfill your guide request. Promotional email and phone contact are optional and require your separate permission. Privacy policy ↗

₦200,000October 12, 2026 · 10 weeks
EnrollAsk an adviser