What lands on an L2 analyst desk after L1 lets go
An L1 analyst decides whether an alert is worth worrying about. An L2 analyst, the Tier 2 role, picks up the ones that are. A suspicious login that L1 could not explain, a laptop that seems to be talking to a strange address, a phishing email that at least one person opened: these arrive with a short ticket and a request to find out what really happened. The work is slower, wider and more forensic than triage.
The salary answer follows the same honest pattern as the rest of this series. Skill IT publishes one indicative range for SOC Analyst (L1/L2), Security Monitoring Analyst and Junior Threat Hunter roles: roughly ₹3L to ₹9L a year in India, entry-to-mid level, and roughly $50K to $95K globally. It does not split the range by tier and it does not name an average for L2. The range is broad, varies by company, city, specialisation and experience, and is not a guarantee.
What you can rely on is the direction. The same range notes that pay rises with certifications and shift experience, and L2 is the tier where those two things start to compound, because you are trusted with larger incidents and you have usually already served time on the shift roster.
A route from L1 comfort to L2 depth
Whether you are already an L1 analyst or still preparing, these steps describe how to build the investigative habit that L2 roles look for.
Follow an alert past the point where L1 would stop
Take a lab offense and keep asking what happened before it and what happened after. Build a timeline of events across several log sources rather than reading one entry.
Learn to correlate across sources
Put firewall, proxy, Windows and Linux logs side by side and trace a single host or user through them. Cross-source thinking is the main difference between L1 and L2 work.
Practise email header and malware basics
Read a suspicious email header end to end and analyse a harmless sample with CyberChef and Sysinternals. These small investigations are typical L2 tasks.
Map what you find to a framework
Place each finding on the Cyber Kill Chain and in MITRE ATT&CK, so that your report shows where the attacker is in their plan, not only what they touched.
Write an incident playbook, then a runbook
Learn how the two differ, then write one of each for a scenario such as ransomware on a file server. Employers notice candidates who can write procedures, not only follow them.
Add a certification aimed at analyst work
Security+ and EC-Council Certified SOC Analyst are the two the SOC curriculum prepares you for, and CompTIA CySA+ is listed among the further pathways. Choose by what your target listings ask for.
Who should aim straight at L2 and who should start at L1
Most people reach L2 through L1, but not everyone has to wait the same length of time. Your background changes the sensible plan.
L1 analyst ready to move up
Show your manager that you already finish investigations on your own. A written case study from a real ticket, with details removed, is stronger than a request.
Systems or network administrator with strong log skills
You may be closer to L2 work than you think, because you already understand how hosts and networks behave. Fill the security gaps and apply to roles that mention investigation.
Fresher hoping to skip the L1 tier
It is rare, and worth being realistic about. Aim for L1, build a strong portfolio and internship record, and treat L2 as your second step rather than your first.
Pentester or security analyst curious about defence
Your attacker's view is useful in investigation. Learn the SIEM and incident response side and you can position yourself for SOC L2 or incident response roles.
Investigation skills an L2 analyst is expected to show
Interviews for Tier 2 roles move from what an alert is to what you would do about it. Be ready to speak about these.
- Building an event timeline across firewall, proxy, endpoint and Windows or Linux logs
- Reading email headers and judging links, attachments and sender infrastructure
- Basic malware analysis and using tools such as CyberChef and Sysinternals during an investigation
- Using indicators of compromise and indicators of attack to search for related activity
- Mapping activity to the Cyber Kill Chain and MITRE ATT&CK
- Running the incident handling lifecycle: preparation, identification, containment, eradication and recovery
- Tuning correlation rules and reference sets so that the queue L1 sees is cleaner
- Explaining a finding to a non-specialist in a short, accurate report
How the SOC Analyst programme trains for L2 work
The later modules of the programme at our Madhapur centre lean toward investigation, which is why they matter for this question.
A full incident response module
Module 5 runs an incident from identification through containment and recovery, and has you build a playbook for a specific attack scenario. Its list of target roles includes SOC Analyst (L2).
Threat hunting with real frameworks
You use MITRE ATT&CK and threat intelligence feeds to hunt for hidden threats, and the module produces a Threat Hunting Project for your portfolio.
Analysis tools used in the lab
CyberChef, Sysinternals and email header analysis are part of the practical work, so your investigation habits are built on tools you can name at an interview.
Internship across the whole incident cycle
The two-month internship exposes you to live monitoring, triage and incident response, which is the range of work an L2 analyst covers.
Resume, mock interviews and hiring partners
We help you present investigation projects on your resume, run mock interviews and support your applications through our hiring-partner network. This is help with the process, not a promise of a role or a salary.
How escalation works above and below an L2 analyst
An L2 analyst sits in the middle of a chain. Below is the Tier 1 analyst who hands up an alert with a note. Above is Tier 3, usually the most experienced people on the team, along with incident responders, threat hunters and the SOC lead. Your job is to take what arrives from below, resolve what you can, and pass up cleanly what you cannot.
A good escalation note answers four questions without being asked. What did we see? What have we already checked? What do we think it is? What do we need from you? A poor note simply says that something looks bad. The difference shows up quickly in a SOC, and analysts known for clear notes tend to be trusted with more.
That trust is part of how pay moves at this level, alongside the certifications and shift experience Skill IT's range mentions. Beyond that we do not publish an L2 figure, so check current numbers in recent listings, ask people who work in the role and compare offers on full cost-to-company before you decide.
Why L2 pay depends on what you own
Two L2 roles can look identical on a job board and feel completely different in practice. In one, you run an investigation from first alert to final report and advise the business on containment. In another, you review a slightly deeper slice of the queue and pass most cases on. The first carries more responsibility, and employers often price it that way.
On-call duties, the tools you are expected to run, the size of the client or business you protect and whether you mentor L1 colleagues all change the picture too. None of these has a published number here, so treat them as questions to ask rather than figures to expect.
Keep going from L2 to the wider picture
See where L2 fits against L1, how the two SOC roles compare with general security analyst work, or go to the programme page for the module breakdown.
Build one investigation you can walk an interviewer through
An L2 conversation becomes easy when you can describe a real investigation from first alert to final report. Build one in a lab, write it up, and talk to us if you would like guided practice with feedback.

