SOC L1, L2 and L3 explained as three filters
SOC L1, L2 and L3 are the three tiers of analyst in a Security Operations Center, and each tier handles what the tier before could not settle. L1 is the first look: monitoring and triaging alerts. L2 is the investigation: confirming real incidents and starting to contain them. L3 is the expert layer: complex incidents, threat hunting and better detections. Picture three filters in a row, each catching what the last let through, so the most experienced people spend their time on the hardest problems.
The levels differ in what each is responsible for, which decisions each is trusted to make, how deeply each uses the tools, and where each sends a case next. This guide puts those side by side, follows one alert through all three levels and lists the questions interviewers ask at each. For the career path between the levels, our separate guide on SOC levels and growth covers that.
One limit to keep in mind: level names are not universal. Some companies add a Tier 0 for automation or a fourth level for management, and small SOCs blend levels. A title also does not always match the duties, so compare roles by what they actually ask you to do.
SOC L1, L2 and L3 side by side on five points
Read these as tendencies and not as fixed rules.
What each level is responsible for
L1 watches the alert queue, checks each alert against context, closes false positives and escalates the suspicious ones with notes. L2 takes escalated cases, correlates several log sources, confirms whether an incident is real and starts containment. L3 leads complex incidents, hunts for threats no alert caught and improves detection rules.
Which decisions each level is trusted to make
L1 decides whether an alert is a false positive or needs escalating, usually by following written steps. L2 decides whether an incident is confirmed, how severe it is and which containment step fits the playbook. L3 decides whether a rule or playbook must change. Taking a critical system offline usually needs approval higher still.
How deep each level goes in the tools
L1 uses the SIEM to view alerts, run prepared searches and write tickets. L2 writes its own searches across firewall, proxy, endpoint and mail logs, and uses CyberChef and Sysinternals for basic analysis. L3 tunes correlation rules, builds detections, hunts with MITRE ATT&CK and may script automation.
Where each level sends a case next
L1 escalates to L2 with a timeline and evidence, or closes the alert with a reason. L2 resolves the case, brings in service owners and IT teams, or passes the hardest cases up. L3 works with engineering to fix detection gaps and advises on major incidents.
How much of the shift is live alert work
L1 spends most of the shift on live alerts and tickets. L2 splits time between escalations and deeper investigation. L3 spends more time hunting, tuning and reviewing incidents, but is pulled in whenever something serious lands.
One strange DNS pattern handled at L1, then L2, then L3
This example is invented. The SIEM raises an offense: a finance application server has sent an unusually high number of DNS queries to one long, random-looking domain. At L1, the analyst confirms the server belongs to finance, checks it is not a backup or monitoring agent, sees the domain is new, writes a short timeline and escalates.
At L2, the investigator pulls DNS, firewall and endpoint data and sees the queries repeat at regular intervals, which resembles automated beaconing. The endpoint console shows which process is making them. Following the playbook, and with the service owner's approval, L2 isolates the server, preserves evidence and blocks the domain.
At L3, the questions widen. How did this get on the server, and is it anywhere else? The hunter searches all hosts for the same domain and pattern, maps the behaviour to a MITRE ATT&CK technique for DNS-based command and control, and writes a detection rule so the next case is caught sooner. Each level answered a different question about one alert.
Interview questions to be ready for at each level
These are typical, not a fixed script. Practise answering aloud.
- L1: Walk me through how you would triage a large number of failed logins on one account.
- L1: How do you decide an alert is a false positive, and what do you write in the ticket?
- L1: What is the difference between an event, an alert and an incident?
- L2: An alert shows a workstation contacting an unknown domain. Which sources do you check, and in what order?
- L2: How do you decide between containing a machine at once and gathering more evidence first?
- L2: Explain how you would analyse a suspicious email header and attachment.
- L3: How would you hunt for attacker persistence on Windows machines, using MITRE ATT&CK?
- L3: A rule produces many false positives. How do you tune it without creating a blind spot?
- L3: What goes into a post-incident review, and how do you turn it into better detection?
How to tell which level a SOC job listing really is
Titles can mislead. These six checks tell you what the job is.
Read the verbs and not the title
Monitor and triage point to L1. Investigate, correlate and contain point to L2. Hunt, tune, build detections and lead incidents point to L3.
Check whether the role owns the queue or receives escalations
An analyst who opens alerts first is working at L1, whatever the title says. One who receives cases from others is at L2 or above.
Look at how deeply the listing uses the tools
Viewing dashboards is different from writing searches and rules.
Ask who is allowed to contain a machine
The answer shows how much decision-making the role carries.
Ask about shifts, on-call and rotation
Higher levels may be on call for serious incidents, and providers may rotate people between levels.
Ask who tunes the rules and how analysts give feedback
A SOC where analysts can flag noisy rules and see them fixed is a better place to learn.
Where each starting point usually lands
You do not have to want L3 on day one.
Fresher with lab and SIEM practice
Aim at L1 roles such as SOC Analyst L1 and Security Monitoring Analyst. Show you can triage, document and escalate cleanly.
Network or systems administrator with a few years behind them
You may interview for L1 with a faster route to L2. Prove the security side with a SIEM project.
Current L1 analyst ready for more
Write your own searches, learn the incident response lifecycle and ask L2 for feedback on your escalations.
Analyst drawn to hunting and building detections
L3 roles usually expect experience, so study MITRE ATT&CK, threat intelligence and rule tuning while you work at L1 or L2.
Why we do not print a pay figure for each level
The only pay figures Skill IT publishes are two indicative ranges. For India it is about ₹3L to ₹9L a year, a typical entry-to-mid range for SOC Analyst (L1/L2), Security Monitoring Analyst and Junior Threat Hunter roles that rises with certifications and shift experience. For equivalent SOC Analyst and Incident Response roles in mature international markets it is about $50K to $95K a year. Both are broad, indicative ranges that vary by company, city, specialisation, shifts and experience, and neither is a promise.
We do not publish separate figures for L1, L2 or L3, and any single number you see for one level deserves care. To check current numbers, read recent job listings for each level in your city, talk to people in the role and compare the full cost to company on any offer, including shift allowance.
How Skill IT Education prepares you for each SOC level
Our five-month SOC Analyst programme in Madhapur, Hyderabad, touches all three levels, though most freshers begin at L1. It is preparation and support, not a promise.
A module that maps the tiers and the escalation path
In the module on life inside a Security Operations Center you study SOC structure and roles, walk a sample alert from Tier 1 to Tier 3 and write a SOC Operating Model Brief.
Fifty hours of SIEM practice for L1 work
IBM QRadar and Splunk labs cover dashboards, offense analysis, correlation rules, false positives and alert triaging.
Incident response skills that point toward L2
The response lifecycle, playbooks and runbooks, email header analysis and basic malware analysis are practised in an Incident Response Simulation.
A first taste of L3 thinking through threat hunting
MITRE ATT&CK, the Cyber Kill Chain and threat intelligence are used in a Threat Hunting Project.
Internship, profile building and level-specific mock interviews
Mock interviews rehearse the level questions above. The internship adds live exposure, resume, GitHub and LinkedIn work shapes your profile and hiring-partner support assists your search. Employers decide.
Quick answers about SOC levels
The level questions we hear most, answered briefly.
Is SOC L3 higher than L2 and L1?
Yes. L3 is the most senior analyst tier, above L2, which sits above L1. Cases move upward as they get harder, and above L3 there is usually a SOC lead or manager. Higher does not mean better in every way, because each level has a different job.
Can a fresher join a SOC directly at L2?
It is uncommon. Most freshers start at L1, where they learn the alerts and tools. Someone with related experience, such as systems administration or incident handling, and strong SIEM projects might be considered for L2, depending on the employer.
Do L1 analysts do incident response?
They take part, but do not usually lead it. L1 analysts detect and triage, gather first evidence, follow playbook steps they are cleared for and escalate. L2 and L3 analysts lead containment, eradication and recovery.
Who decides to isolate a machine in a SOC?
It depends on the playbook. Often L2 or an on-call lead decides, sometimes after checking with the system owner. Some SOCs let L1 isolate a device in pre-approved high severity cases, while business-critical servers usually need more approval than a laptop.
Are SOC tiers the same in every company?
No. Some use Tier 1 to Tier 3, others add a Tier 0 for automation or a Tier 4 for management, and small teams blend levels. Compare listings by duties and tools, not just the label.
Where to read next about SOC levels
The programme page lists the modules behind each level. The related guides cover the career path, pay for L1 and L2, and interview preparation.
Start by mastering the level in front of you
You do not need to choose your L3 destination today. Get good at the tier you are aiming for and practise one level above it. Share where you stand today and the admissions team will map a realistic first step.

