Employer guide
How to hire a SOC Analyst
A practitioner-led checklist for hiring SOC L1, L2, and L3 analysts in India — what to test, what to ignore, and how long it should actually take.
L1 vs L2 vs L3 — what to look for
The most common mistake in SOC hiring is buying a job title. A senior-titled analyst who has only run tuned playbooks isn't an L3. Score by capability, not tenure.
L1 SOC Analyst
0–2 yearsTriage & alert handling
- SIEM basics (Splunk, Sentinel, QRadar) — searches, dashboards
- Windows/Linux event log fundamentals
- MITRE ATT&CK familiarity at technique level
- Phishing triage, IOC lookups, ticket hygiene
L2 SOC Analyst
2–5 yearsInvestigation & containment
- EDR deep-dive (CrowdStrike, Defender, SentinelOne)
- Packet & log correlation across identity + endpoint + network
- Detection tuning, false-positive reduction, playbook authoring
- Basic threat hunting hypotheses
L3 / Threat Hunter
5+ yearsHunting, detection engineering, IR lead
- Sigma/KQL/SPL detection authoring with tests
- Adversary emulation, purple-team exercises
- Malware triage, memory forensics, timelining
- Runs post-incident reviews and mentors L1/L2
The 5-stage technical vetting checklist
This is the same pipeline CipherForce runs before a SOC candidate reaches a client shortlist. Copy it, adapt it, or outsource it — but don't skip stages 3 and 4.
1. Resume & background screen
Verify claimed tools with dated project context, not just keywords. Reject candidates who list every SIEM ever built — real analysts specialise.
2. Practitioner-led technical interview
60 minutes with a working SOC lead. Walk through a real alert: what do you look at first, what do you rule out, when do you escalate?
3. Hands-on lab challenge
A time-boxed exercise on a live SIEM with seeded alerts. Score on investigation path, evidence quality, and the written escalation summary — not just the final verdict.
4. Scenario & judgement round
Business-impact scenarios: ransomware detonation, insider exfil, false-positive storm at 3 AM. Assess prioritisation, communication, and calm.
5. Reference & culture check
Two references from prior shift leads or SOC managers. Confirm shift discipline, documentation habits, and behaviour under pressure.
Red flags to reject early
- ✕Tool-list resumes with no incident stories to back them up
- ✕Cannot describe a single alert they investigated end-to-end
- ✕Confuses IOCs with TTPs, or MITRE tactics with techniques
- ✕No documentation samples — playbooks, runbooks, or handover notes
- ✕Zero questions about shift model, on-call, or escalation paths
Skip the pipeline — get a vetted shortlist in 7 days
CipherForce runs all 5 stages for you. You review 3–5 pre-vetted SOC analysts with challenge artefacts and vetting dossiers. No resume spam, 90-day replacement guarantee.