SOC Analyst Job Description Template (Tier 1, 2 and 3)
A copy-ready SOC analyst job description template for Tier 1, 2 and 3 roles, plus the common requirements to cut because they filter out good candidates.
A SOC analyst job description should describe the real work of the role at its tier, list only the requirements a person truly needs on day one, and say how you will assess candidates. Below are copy-ready templates for Tier 1, Tier 2 and Tier 3 roles, followed by the requirements most SOC adverts should cut, because they filter out good candidates without improving the shortlist.
Replace the text in square brackets with your own details.
Tier 1 SOC analyst job description template
Job title: SOC Analyst (Tier 1)
Location: [City / hybrid / remote] | Hours: [Shift pattern, including any nights or weekends]
About the role
You will be part of our security operations centre, monitoring alerts across
[our SIEM, for example Microsoft Sentinel] and endpoint detection tools. You will
decide which alerts are benign and which need investigating, and escalate the
real ones clearly so the team can act fast.
What you will do
- Triage alerts from the SIEM, endpoint detection and email security tools
- Investigate suspicious sign-ins, phishing reports and malware alerts
- Close benign alerts with evidence, and escalate suspicious ones with clear notes
- Follow and help improve our playbooks
- Share what you see that is noisy or missed, so detections get better
What you will need
- An understanding of common attacks, such as phishing, malware and password attacks
- The ability to read logs and spot what does not belong
- Clear written communication
- Curiosity, and the willingness to say "I don't know yet, I'll find out"
Nice to have
- Experience with a SIEM or a query language such as KQL or SPL
- Experience in IT support, networking or a home lab
How we hire
Our process starts with a short, practical task: you will triage a few realistic
alerts in a real environment. No trick questions. Then an interview where we talk
through your answers.
Tier 2 SOC analyst job description template
Job title: SOC Analyst (Tier 2)
Location: [City / hybrid / remote] | Hours: [Shift pattern and on-call]
About the role
You will investigate the alerts our Tier 1 analysts escalate, work out what
happened and how far it reaches, and lead containment. You will also coach
Tier 1 analysts and help improve our detections.
What you will do
- Investigate escalated alerts across endpoint, identity, email and cloud logs
- Build timelines, scope incidents and recommend or take containment actions
- Write clear incident notes for technical and non-technical readers
- Coach Tier 1 analysts and review their escalations
- Feed what you learn back into detections and playbooks
What you will need
- Experience investigating security incidents in a SOC or similar team
- Strong log analysis and correlation across several data sources
- Confidence with a SIEM query language, such as KQL or SPL
- Good judgement about when to contain and when to escalate further
Nice to have
- Experience with endpoint detection and response tools
- Experience mapping activity to MITRE ATT&CK
How we hire
Our process starts with a practical investigation in a real environment. Then an
interview where we walk through your findings and some scenarios.
Tier 3 SOC analyst job description template
Job title: Senior SOC Analyst / Threat Hunter (Tier 3)
Location: [City / hybrid / remote] | Hours: [Working pattern and on-call]
About the role
You will handle our most complex investigations, hunt for threats our detections
miss, and improve the detections themselves. You will be a technical lead for the
SOC and a point of escalation for the hardest cases.
What you will do
- Lead complex investigations and incident response
- Run threat hunts based on intelligence and hypotheses
- Write, test and tune detections to improve coverage and reduce noise
- Mentor Tier 1 and Tier 2 analysts
- Work with incident response, threat intelligence and engineering teams
What you will need
- Significant experience in security operations or incident response
- Strong threat hunting and detection skills in a query language such as KQL or SPL
- A deep understanding of attacker techniques and the telemetry that shows them
- The ability to explain findings to leadership
Nice to have
- Experience with Sigma or detection-as-code practices
- Scripting in Python or PowerShell for automation
How we hire
Our process starts with a hands-on task, such as a hunt or a detection to tune,
followed by an interview focused on your approach and experience.
Which requirements should you cut from a SOC analyst job description?
These appear in most SOC adverts. Each one removes good candidates without making the shortlist better.
| Requirement to cut | Why it hurts | What to do instead |
|---|---|---|
| Certifications as essential for Tier 1 | Removes capable career changers and self-taught candidates | Test the skill with a practical task |
| A degree as essential | Many strong analysts came through IT support or home labs | List the skills, not the route |
| Years of experience with one specific tool | Tools are learned in weeks; judgement takes longer | Ask for experience with any SIEM or query language |
| A long list of every tool you own | Reads as a wish list and puts people off | Name the core tools and say the rest can be learned |
| ”Must thrive under pressure” with no detail | Says nothing useful | Describe the real shift pattern and on-call |
| A Tier 3 skill list on a Tier 1 role | Nobody applies, or the wrong people do | Match the list to day-one tasks for the tier |
What makes a SOC analyst job description work?
- It describes a normal week. Candidates want to know what they will actually do, not a list of values.
- It is honest about shifts. Night and weekend work is a dealbreaker for some people; better they know now.
- It says how you will assess. A practical task signals you hire on ability, which attracts the people who have it.
- It keeps “essential” short. Every extra requirement narrows the field.
For the rest of the process, see how to hire a SOC analyst, and for the interview, these SOC analyst interview questions.
Frequently asked questions
What should a SOC analyst job description include?
The tier and what that means in practice, the main tasks, the tools, the shift pattern, a short list of essential requirements, a few nice-to-haves, and how candidates will be assessed.
What are the main responsibilities of a SOC analyst?
Monitoring and triaging security alerts, investigating suspicious activity, escalating real incidents with clear notes, and helping improve detections and playbooks. At higher tiers, also containing incidents, hunting for threats and tuning detections.
Should a SOC analyst job description ask for certifications?
As a nice-to-have, not an essential, especially for Tier 1. Making them essential filters out capable candidates and does not guarantee the ones who hold them can do the job.
How CyberHire helps once the advert is live
CyberHire is cyber technical screening that turns your job description into a hands-on assessment. Paste the description and generate a SOC assessment calibrated to the tier, or pick the ready-made SOC analyst skills test. Candidates triage real alerts and investigate real logs, and you shortlist from what they did rather than from their CVs.
See the wider guide on how to hire a cyber security analyst. If you would rather not build the assessment yourself, our team will build it with you.
Advert written?
Turn your job description into a hands-on assessment, free.
Send us the job spec. Within 48 hours we send you a hands-on SOC assessment built around it, in your branding. Test before you shortlist.