Roadmap

SOC Analyst — Tier 2 / Threat Hunter

The investigator and hunter. Takes escalated incidents from T1 and runs deep investigations, while proactively searching for threats that bypassed automated detection entirely.

OPTIMISTIC 18 monthsREALISTIC 2–3 years

FAQ

Common questions

How long does it take to become a SOC Analyst — Tier 2?

18 months optimistic at 20–25 hours/week from zero, 2–3 years realistic. The most common path is SOC T1 → SOC T2 with 12–18 months at T1. T2 demands deeper investigation skills, scripting fluency, threat hunting instincts, and the ability to determine scope and impact independently. T2 roles are fewer than T1 but higher value — analysts who add scripting, detection engineering, and hunting skills command significantly higher compensation and face less competition.

Which certifications matter for SOC T2 roles?

GCIH (GIAC Certified Incident Handler) for IR-overlapping T2 work. CySA+ for analytical depth. GCDA (GIAC Certified Detection Analyst) for detection engineering specialization. SANS-track certs are expensive but the content is the gold standard for T2 progression. Splunk Power User or Enterprise Certified Admin signal SIEM platform depth.

Do I need a CS degree?

No. T2 is meritocratic — demonstrated investigation skills and threat hunting writeups outweigh credentials. Self-taught analysts with strong CTF DFIR challenge solutions and lab investigation portfolios compete effectively. What you do need: scripting (Python at minimum), SIEM platform depth, threat intelligence consumption fluency, and at least basic memory analysis (Volatility) experience.

What separates a hired SOC T2?

Documented threat hunting writeups. Detection rules you've authored, threat hunts you've executed (even in lab environments), and investigation narratives that demonstrate analytical reasoning. Generic 'I know KQL' candidates lose to candidates with portfolio investigation work. Detection Engineering is the fastest-growing exit path from the T2 track.

Building your own portfolio?

SEE PRICING →