Purpose of the Script
Your new SOC analyst has completed their first week, ticking off the HR checklist, attending compliance training, and receiving credentials. But have you asked the questions that predict whether they'll burn out in six months or thrive in your program?
This onboarding interview script integrates human-centered cybersecurity principles into your analyst intake process. It's designed to identify friction points, workflow mismatches, and cognitive load issues before they become ingrained problems. The NIST human-centered cybersecurity concept paper emphasizes empowering people as defenders, not just vulnerabilities. This script puts that principle into action during the critical first 30 days.
Use this during week two or three, after your new hire has enough context to answer honestly but before bad habits form.
Prerequisites
Before conducting this interview:
- Completed standard onboarding: The analyst has credentials, knows the basics, and has logged into primary tools.
- Initial exposure to workflows: They've shadowed at least three shifts and handled tickets under supervision.
- Psychological safety: Make it clear this isn't a performance evaluation. You're diagnosing your processes, not their competence.
- Note-taking capability: Capture specific pain points. Bring a document, not a form.
The Interview Script
Opening frame (say this verbatim to set the tone):
"I'm going to ask you about friction you've noticed in your first two weeks. I'm not testing whether you remember our procedures -- I'm testing whether our procedures make sense. If something feels clunky or confusing, that's data I need to fix the system, not evidence you're doing it wrong. There are no wrong answers here."
Section 1: Tool Cognitive Load
Objective: Identify dashboard sprawl, alert fatigue precursors, and navigation friction.
- "Walk me through the tools you opened during your last shift, in order. Which ones did you switch between most often?"
- "Which tool took you the longest to find the information you needed? What were you looking for?"
- "Have you written down any passwords, bookmarks, or process notes that aren't in our official documentation? Show me -- I won't confiscate them."
- "If you could delete one tool from your workflow without losing critical capability, which would it be and why?"
What you're listening for: Multiple logins, redundant data across dashboards, workarounds that signal your SIEM isn't surfacing what analysts actually need. If they've written down a password, your authentication flow is too complex. If they've bookmarked a workaround, your official process has a gap.
Section 2: Decision-Making Under Uncertainty
Objective: Surface judgment calls that create anxiety or require escalation you didn't anticipate.
- "Describe a ticket from this week where you weren't sure if you made the right call. What made it ambiguous?"
- "When you escalate to the senior analyst, what usually triggers that decision? Is it a specific indicator, a time threshold, or a gut feeling?"
- "Have you ever wanted to escalate something but didn't because you thought you'd look inexperienced?"
What you're listening for: If they can't articulate escalation criteria, your runbooks lack decision trees. If they're second-guessing low-stakes calls, you're not calibrating their confidence. If they're hesitating to escalate, your team culture penalizes questions.
Section 3: Interruption and Context-Switching
Objective: Detect workflow disruptions that fragment attention and increase error rates.
- "How many times during your last shift did you have to stop what you were doing to handle something urgent? What qualified as urgent?"
- "When you're deep in an investigation and an alert fires, how do you decide whether to context-switch immediately or finish your current task?"
- "What's the longest uninterrupted block of time you've had to work on a single complex ticket?"
What you're listening for: If they can't get 30 minutes of uninterrupted time, your alert tuning is broken. If "urgent" means "anything with a high severity tag," you're training them to treat everything as critical, which means nothing is.
Section 4: Training vs. Reality Gap
Objective: Identify where your documentation, training, or simulations diverge from actual operations.
- "What's something you learned in training that you haven't used yet in practice?"
- "What's something you do every shift that wasn't covered in training?"
- "If you were redesigning our onboarding, what's one thing you'd add and one thing you'd cut?"
What you're listening for: Training that focuses on edge cases instead of daily operations. Undocumented tribal knowledge that only exists in senior analysts' heads. Simulations that don't reflect your actual tool stack or threat profile.
Section 5: Emotional and Physical Sustainability
Objective: Detect early burnout indicators before they require intervention.
- "At the end of your shift, do you feel more mentally tired, physically tired, or both? What do you think causes that?"
- "Have you had trouble sleeping after a particularly intense shift? What made it intense?"
- "When you're stuck on a problem, how long do you struggle alone before asking for help? What stops you from asking sooner?"
What you're listening for: Burnout research on cybersecurity professionals shows that cognitive overload, lack of control, and isolation are primary drivers. If they're losing sleep over tickets they can't solve, your escalation paths aren't clear. If they're exhausted from context-switching rather than problem-solving, your workflow design needs attention.
Closing question (always ask this last):
- "If you could fix one thing about your daily workflow right now -- not a big strategic initiative, just one specific thing -- what would it be?"
What you're listening for: Specific, actionable friction. This is your highest-ROI fix.
How to Customize It
For smaller teams (5-15 people): Collapse Sections 2 and 3. You probably don't have formal escalation tiers, so focus on decision confidence and interruption patterns.
For 24/7 SOCs: Add a question about shift handoffs: "What information do you wish the previous shift had documented that they didn't?"
For teams with high turnover: Add Section 6 focused on retention signals: "What would make you excited to come to work tomorrow?" and "What would make you start looking for another job?"
For compliance-driven environments (HIPAA, PCI DSS 4.0, NYDFS): Add a question about security-versus-productivity tension: "Have you ever bypassed a security control to get your work done faster? What was the control and why did it slow you down?"
Validation Steps
After you run this interview with three to five new hires:
Step 1: Pattern analysis
Compile answers in a shared document. Look for repeated pain points. If three analysts mention the same tool or process, that's not coincidence -- it's a design flaw.
Step 2: Quick-win triage
Identify fixes you can implement in under two hours. Bookmark a frequently-used report. Consolidate two dashboards. Document an undocumented escalation path. Do these immediately.
Step 3: Roadmap the rest
For systemic issues (alert tuning, SIEM redesign, training overhaul), add them to your quarterly improvement backlog with the analyst's quote as evidence. When you present to leadership, you're not saying "I think we have a problem." You're saying "Three analysts in their first month independently reported this friction."
Step 4: Close the loop
Two weeks after the interview, tell the analyst what you changed based on their feedback. Even if it's small. This reinforces that their input shapes the system, which is the foundation of human-centered design.
Step 5: Repeat quarterly
Run abbreviated versions (questions 8, 14, and 17) every quarter with your entire team. Friction evolves as your threat landscape and tools change.
This isn't a performance review. It's a diagnostic. You're not measuring whether your analysts can adapt to a broken process -- you're measuring whether your process deserves their effort. The difference matters, and it shows up in your retention numbers six months from now.





