
Security has an attrition problem it keeps misdiagnosing as a hiring problem. Analysts do not leave because the work is hard. They leave because the work is hard in a way that never gets easier, and the pager makes sure they never fully rest.
The average SOC analyst tenure is barely two years. Exit interviews rarely blame the threats; they blame the queue. Triage that never ends, alerts that are almost always nothing, and the low-grade dread of the one that is not. Burnout in a SOC is not a wellness issue to be solved with a meditation app. It is an engineering failure, and it has engineering fixes.
The anatomy of SOC fatigue
Three mechanisms do most of the damage. Understanding them matters because each one has a different fix, and programs that treat them as one problem end up fixing none.
- Alert fatigue: when 9 out of 10 pages are false, the rational human response is to stop believing pages. The cost is paid the night the page is real.
- Interrupt load: triage is interrupt-driven work. A shift of 40 context switches leaves an analyst exhausted even if every alert was benign.
- Moral injury: analysts know real threats are slipping past while they close scanner noise. Doing work you believe is pointless is more corrosive than doing too much work.
People do not burn out from working hard. They burn out from working hard on things that do not matter, at hours that do not end.
Fix the queue before the rotation
Most burnout programs start with the schedule: longer rest windows, follow-the-sun, comp days. All good, none sufficient. If the queue is broken, a fairer rotation just distributes the damage more evenly. The order of operations matters: shrink and enrich the queue first, then design the rotation around what remains.
Shrinking the queue means being ruthless about detection precision, and honest about the detectors that have never produced a real finding. Enriching it means no alert reaches a human as a bare event: context, entities, timeline, and a recommended verdict should already be attached. An analyst who opens a pre-investigated case makes a decision. An analyst who opens a raw alert starts a scavenger hunt.
Rotation design that respects sleep
Once the queue is humane, rotation design has something to work with. The principles are borrowed from what SRE learned a decade ago, adapted for the reality that security incidents do not respect business hours.
- Shifts of one week maximum, with a hard handoff document. Two-week rotations measurably degrade sleep in week two.
- No solo on-call. A primary-secondary pair halves the fear factor, and the secondary only engages on confirmed escalation.
- Recovery time is work time. A night page earns late start the next day, automatically, without negotiation.
- Escalation budgets. If a rotation pages more than an agreed threshold, that is an engineering incident for the detection team, not a fact of life.
Give the 2 a.m. work a daylight payoff
The most underrated retention tool is making triage findings feed something that compounds. When an analyst's night-shift verdict retunes the detector that fired it, the analyst is doing engineering, not janitorial work. Rotate people through detection engineering, hunting, and automation sprints. The title on the badge matters less than whether this quarter's work makes next quarter's queue smaller.
See Port0 on your own data.
Bring your noisiest alert queue. Watch Soc0 investigate it live.






