SOC Analyst Tiers (L1/L2/L3)
Overview
SOC teams organize work into tiers based on experience, technical depth, and authority to take action — useful both operationally and for planning your own career path into the field.
Key concepts
- L1: monitoring and initial triage
- L2: deeper investigation and containment
- L3: threat hunting, forensics, detection engineering
How it works
SOC analyst tiers organize security operations work by experience, technical knowledge, investigation depth, and authority to take response actions. Exact responsibilities vary by organization, but most SOC teams use Level 1, Level 2, and Level 3 roles.
| Tier | Focus | Typical work |
|---|---|---|
| Level 1 | Continuous monitoring and initial triage | Monitors SIEM dashboards, reviews incoming alerts, performs basic log analysis, follows documented playbooks, documents findings in tickets, escalates what needs deeper investigation. Commonly handles failed logins, suspicious email alerts, malware detections, unusual network connections, and basic endpoint alerts. |
| Level 2 | Deeper investigation, containment, response coordination | Reviews escalated cases, correlates evidence across log sources, determines incident scope, identifies affected systems/accounts. Investigates suspicious processes, malware activity, persistence mechanisms, unauthorized account use, and network anomalies. May isolate endpoints, disable compromised accounts, block malicious IPs/domains, and recommend further containment. |
| Level 3 | Advanced investigation, threat hunting, long-term improvement | Handles complex incidents involving advanced threats, multiple systems, persistent attacker access, or major business impact. Performs advanced malware analysis, digital forensics, memory analysis, root-cause analysis, and threat hunting. Creates/improves detection rules, tunes SIEM use cases, develops automation, and identifies gaps in security visibility. |