The first hour of an L1 shift and what the job is paid for
Imagine sitting down at the start of a shift and finding the alert queue already full. Some alerts are a user who typed a password wrong too many times. Some are a link that a colleague clicked in a suspicious email. One might be the first sign of a real intrusion. An L1 analyst, also called a Tier 1 analyst, is the person who opens each one, decides quickly whether it is noise or a genuine concern, and records the decision. That sorting is the heart of the job, and it is what the employer is really paying for.
On pay, the position is simple and slightly frustrating. Skill IT publishes one indicative range for SOC Analyst (L1/L2), Security Monitoring Analyst and Junior Threat Hunter roles: roughly ₹3L to ₹9L a year in India, at entry-to-mid level, rising with certifications and shift experience. There is no separate published number for L1 alone, and we would rather say so than guess. Like every range on this site it is broad, varies by company, city and specialisation, and is not a guarantee.
What is known is the shape of the role. L1 is where the queue is worked and the escalations begin. Because it is the doorway into the SOC, it is also the tier where fresh graduates and IT support engineers most often arrive, and where a well-prepared candidate can stand out from a crowd of equally certified ones.
Seven things to practise before an L1 interview
L1 interviews rarely ask for theory alone. They put an alert in front of you and watch how you think. Practise these until they feel automatic.
Sort a busy queue by what matters first
Take a list of ten mixed alerts and decide the order you would open them in, and why. Interviewers like candidates who can explain their priorities out loud.
Check a suspicious IP or link the moment it appears
Build the habit of running a reputation check on any odd address or URL before forming a view. Do it in your lab until it takes seconds, not minutes.
Learn what a false positive looks like
Work with correlation rules and see how they fire on harmless activity. Being able to explain why an alert is safe is as valuable as spotting one that is not.
Write a ticket a stranger can act on
State what fired, what you checked, what you found and what you recommend, in a few plain lines. Practise on lab alerts until your notes read cleanly.
Decide in advance when you would hand an alert up
Write down your own escalation triggers, such as signs of malware running or a compromised account, so that your answer in the room is calm and specific.
Prepare honest answers about nights and weekends
Most L1 roles involve shift patterns. Know what you can commit to, and ask sensible questions about rotation and handover rather than avoiding the topic.
Sit a mock interview built around a live alert
Ask a friend or a trainer to hand you an alert with no warning. Talking through a triage decision while someone watches is the closest rehearsal you can get.
Who is asking about L1 pay and what to do next
Most people searching this question are close to their first SOC application. Your next move depends on the point you are starting from.
Fresh graduate with no experience
L1 is your natural target. Spend your time on networking, log reading and one SIEM, and bring a written project to every interview.
Helpdesk or desktop support engineer
You already triage tickets under pressure. Add the security layer, meaning alerts, logs and attack types, and the move to L1 becomes a short step.
Working professional worried about night work
Ask directly how the roster runs before you accept. Some SOCs fix the shift, others rotate, and the difference matters more than a small change in pay.
Career changer comparing L1 with a pentest path
L1 gives steady exposure to real incidents and is a sound base if you later want investigation or hunting. If you want to attack systems for a living, the Cyber Security programme is closer to that goal.
What an L1 analyst is expected to know cold
Nobody expects an L1 to know everything. They do expect these basics to be solid.
- How the OSI and TCP/IP models, IP addressing and subnetting fit together in a normal network
- Windows and Linux command line skills for checking users, processes and connections
- What a SIEM does: collecting events, correlating them and raising offenses
- The main log sources: firewalls, proxies, IPS or WAF devices and Windows and Linux hosts
- Common attacks by name and behaviour, including phishing, malware, password attacks and DoS or DDoS
- How to read an email header and judge a link or attachment as suspicious
- The difference between an indicator of compromise and an indicator of attack
- The escalation path from Tier 1 to Tier 2 and Tier 3, and what each tier expects from a handover
What the SOC Analyst programme gives an aspiring L1
The programme at our Madhapur centre is built around the tasks an L1 is actually handed on day one.
Alert triage practice inside a SIEM
In the SIEM module you work through correlation rules, false positives and alert triage on IBM QRadar and Splunk, using log types from real security devices.
A module on how a SOC is run
Module 3 covers SOC structure, roles, the tier system and how a sample alert moves from Tier 1 to Tier 2 to Tier 3, which is the ground interviewers cover first.
Labs that end in a written project
Each module closes with a lab exercise or project, and the programme produces at least five documented projects for your portfolio and resume.
Internship exposure to live triage
The two-month internship gives real-time exposure to SOC monitoring, triage and incident response, so your first shift is not your first look at the work.
Mock interviews and hiring partner support
We help with your resume, run mock interviews and support your applications through our hiring-partner network. It is assistance, not a promise of a job or pay.
What shift life really looks like for an L1 analyst
A SOC watches an organisation around the clock, so someone has to be there when the office is empty. Depending on the employer that can mean a fixed day roster, a fixed night roster or a rotation across all three. Ask which one you are being offered, because it changes your sleep, your evenings and the way you feel about the same salary.
At the end of each shift comes the handover. The outgoing analyst tells the incoming one what is open, what is waiting for someone else and what looked odd but unproven. Good handover notes are one of the clearest markers of a professional, and they are a skill you can practise before you are hired.
Skill IT's indicative range notes that pay rises with certifications and shift experience. That is a fair reason to take shift work seriously, but do not treat it as a trade you must accept. Compare offers on the full cost-to-company, including any shift allowance, and be honest with yourself about what schedule you can sustain.
Where an L1 analyst can go next
L1 is a starting tier rather than a ceiling, and the SOC Analyst programme maps several routes out of it.
Into deeper investigation as an L2 analyst
After building steady triage habits, many analysts move to Tier 2, where you investigate the alerts that L1 hands up. The programme lists SOC Analyst (L2) as a role its final module points toward.
Into SIEM and detection work
If tuning rules and building dashboards appeals more than incident work, the SIEM and Security Engineer track and the Log Analysis Engineer role are natural neighbours.
Into threat hunting and intelligence
Hunting for threats that alerts never surface, using MITRE ATT&CK and threat intelligence, leads toward Junior Threat Hunter and Threat Intelligence Analyst roles.
Keep going from L1 to the next question
Read what changes at L2, see the broader SOC pay picture, or open the programme page to see how the modules are laid out.
Get your first alert triage practice booked
An L1 offer goes to the person who can sort a queue calmly, write a clean ticket and explain a decision. Start building those habits in a lab now, and talk to us if you want a guided route with feedback along the way.

