Tiers, roles and where you start

~25 min

(Quick review first: a SOC is the people who watch, detect and respond around the clock; the daily work is triage, investigation, response, tuning, hunting and documentation.)

Why tiers exist

A SOC handles a huge volume of alerts of wildly varying seriousness. Having your most experienced people read every routine alert would waste them; having juniors handle every major incident would be reckless. So SOCs organise into tiers — a pipeline that gets each alert to the right level of skill.

Understanding the tiers matters to you specifically, because you will start at the bottom of it, and knowing the whole pipeline tells you where you are heading.

The tiers

Tier 1 — Triage analyst. The front line, and where you begin. You monitor the alert queue, do initial triage on each alert — real or false, how serious — handle the routine ones, and escalate what needs more. High volume, fast decisions, and the foundation of everything. It is sometimes spoken of dismissively; it should not be. A good Tier 1 is the difference between a real attack being caught in the first hour and being buried under false positives — the filter that decides what the rest of the SOC even sees.

Tier 2 — Incident responder. Takes what Tier 1 escalates and investigates deeply. Determines what really happened, how far it spread, what the impact is, and drives containment and remediation. More experience, more autonomy, the investigation skills at full depth.

Tier 3 — Threat hunter / senior analyst. The most experienced. Proactively hunts for threats that evaded detection, handles the most serious incidents, does forensic analysis, and — crucially — builds the detections and improves the SIEM so that next time, the threat is caught automatically. Much of what you learn to build in this course is Tier 3 work, done early.

Around the tiers:

  • SOC Manager — runs the team, the rota, the metrics, the relationship with the rest of the business.
  • Detection Engineer — a specialised role, increasingly its own thing, dedicated to writing and maintaining detection rules. If you enjoy the rule-writing weeks of this course most, this is a career direction worth knowing exists.
  • Threat Intelligence Analyst — studies attackers and feeds that knowledge to the SOC.

The path

The usual progression is Tier 1 → Tier 2 → Tier 3, or a branch into detection engineering or threat intelligence. It is a genuine career with a genuine ladder, and demand comfortably outstrips supply — especially in Nigeria and across Africa, where the shortage of trained analysts is acute.

What gets you promoted is not time served. It is judgement, the ability to investigate independently, and the ability to make the SOC better — writing a detection that catches what was missed, tuning away the noise that was drowning the team, mentoring the analyst behind you. This course deliberately teaches the Tier 2 and Tier 3 skills early, because they are what move you up, and because an entry-level analyst who can already write a decent rule stands out sharply.

The reality of Tier 1

Be clear-eyed about your starting job, because the mismatch between expectation and reality causes good people to quit early.

Tier 1 can be repetitive. You will see the same false positives many times. There is shift work, sometimes nights. Some days are quiet to the point of boredom; others are relentless. This is normal, and it is survivable if you know it is coming and treat the quiet time as learning time.

The analysts who thrive use the routine to build deep familiarity with what normal looks like — which is exactly the foundation that makes them good at spotting the abnormal, and exactly what earns the promotion. The ones who struggle treat it as beneath them and stop paying attention, and inattention is how the one real alert in a thousand slips past. Your attention is the product. Guard it.

Try it now

Think about the pipeline as a system:

  1. Why is it a mistake to have your most senior people triaging every routine alert?
  2. Why is it a mistake to have juniors handle every major incident alone?
  3. What has to be true about Tier 1's work for the whole SOC to function — what happens downstream if Tier 1 triages badly?

Question 3 is the one to sit with. Everything the SOC does depends on the front line getting the first decision roughly right. Bad triage either floods the upper tiers with noise or lets real attacks through — and you are about to be that front line.

Sign in to track your progress.