Employer guide

How to hire a SOC Analyst

A practitioner-led checklist for hiring SOC L1, L2, and L3 analysts in India — what to test, what to ignore, and how long it should actually take.

Typical time-to-hire
14 days
Shortlist size
3–5 profiles
Vetting stages
5

L1 vs L2 vs L3 — what to look for

The most common mistake in SOC hiring is buying a job title. A senior-titled analyst who has only run tuned playbooks isn't an L3. Score by capability, not tenure.

L1 SOC Analyst

0–2 years

Triage & alert handling

  • SIEM basics (Splunk, Sentinel, QRadar) — searches, dashboards
  • Windows/Linux event log fundamentals
  • MITRE ATT&CK familiarity at technique level
  • Phishing triage, IOC lookups, ticket hygiene

L2 SOC Analyst

2–5 years

Investigation & containment

  • EDR deep-dive (CrowdStrike, Defender, SentinelOne)
  • Packet & log correlation across identity + endpoint + network
  • Detection tuning, false-positive reduction, playbook authoring
  • Basic threat hunting hypotheses

L3 / Threat Hunter

5+ years

Hunting, detection engineering, IR lead

  • Sigma/KQL/SPL detection authoring with tests
  • Adversary emulation, purple-team exercises
  • Malware triage, memory forensics, timelining
  • Runs post-incident reviews and mentors L1/L2

The 5-stage technical vetting checklist

This is the same pipeline CipherForce runs before a SOC candidate reaches a client shortlist. Copy it, adapt it, or outsource it — but don't skip stages 3 and 4.

  1. 1. Resume & background screen

    Verify claimed tools with dated project context, not just keywords. Reject candidates who list every SIEM ever built — real analysts specialise.

  2. 2. Practitioner-led technical interview

    60 minutes with a working SOC lead. Walk through a real alert: what do you look at first, what do you rule out, when do you escalate?

  3. 3. Hands-on lab challenge

    A time-boxed exercise on a live SIEM with seeded alerts. Score on investigation path, evidence quality, and the written escalation summary — not just the final verdict.

  4. 4. Scenario & judgement round

    Business-impact scenarios: ransomware detonation, insider exfil, false-positive storm at 3 AM. Assess prioritisation, communication, and calm.

  5. 5. Reference & culture check

    Two references from prior shift leads or SOC managers. Confirm shift discipline, documentation habits, and behaviour under pressure.

Red flags to reject early

  • Tool-list resumes with no incident stories to back them up
  • Cannot describe a single alert they investigated end-to-end
  • Confuses IOCs with TTPs, or MITRE tactics with techniques
  • No documentation samples — playbooks, runbooks, or handover notes
  • Zero questions about shift model, on-call, or escalation paths

Skip the pipeline — get a vetted shortlist in 7 days

CipherForce runs all 5 stages for you. You review 3–5 pre-vetted SOC analysts with challenge artefacts and vetting dossiers. No resume spam, 90-day replacement guarantee.

Related