Security Analysts

SOC analyst level 1 to level 2: how to get promoted in the SOC

Moving from L1 to L2 usually comes down to one change: you stop handing tickets up and start owning them to the end. L2 analysts run the investigation, decide what happened, write it up, and fix the noise that caused the alert in the first place.

Every SOC defines the tiers a little differently, so the first step is to get your own team's criteria in writing. Below are the things L2 usually means in practice, how to show each one before you have the title, and how to ask your manager what the bar is.

Talk to Carmen

Your AI career coach

Say it the way you’d say it to a friend. Carmen will ask what she needs to know.

Free, no sign-up to start.

$129,180 a year

Median information security analyst pay, May 2025

BLS Occupational Outlook Handbook

$75,090

Lowest 10 percent of information security analysts earned less than, May 2025

BLS Occupational Outlook Handbook

$199,850

Highest 10 percent earned more than, May 2025

BLS Occupational Outlook Handbook

What L2 means in practice, and how to show it

  • Own investigations end to end

    L1 triages and escalates. L2 takes the alert, scopes it, pulls the evidence, reaches a verdict and closes it or hands it to incident response with a clear summary. Managers promote people they already trust to finish a case.

    First step
    On your next escalation, add your own scoping notes and a proposed verdict before you hand it up, then ask the L2 who takes it what you missed.
  • Write up incidents clearly

    An L2 write-up says what happened, when, what was affected, what was done and what should change. Leads read these, and some go to people outside security. Clear writing is one of the most visible signs you are ready.

    First step
    Take a closed incident from the last month and write a one-page timeline and summary, then ask your lead to mark it up.
  • Tune detections

    L2 analysts are usually expected to spot why a rule is noisy and suggest a fix, and sometimes to write new rules. Showing that you reduce noise for the whole team is a strong promotion signal.

    What it takes
    Working knowledge of your SIEM's query language, such as SPL or KQL.
    First step
    Pick the rule that fires most often with no real finding, document why it misfires, and propose a tuned version with a test case.
  • Mentor L1 analysts

    L2s answer the questions newer analysts are afraid to ask the lead. Helping others shows you understand the work well enough to explain it, and it frees your lead's time.

    First step
    Write a short runbook for the alert type new analysts struggle with most and share it with the team.
  • Script the repetitive parts

    Many L2 roles expect some Python or PowerShell for enrichment, parsing logs, or pulling data from APIs. A small script that saves the team time is easy to point to in a promotion conversation.

    What it takes
    Free. Basic Python takes a few weeks of evenings.
    First step
    Automate the lookup you do most often, such as a hash or IP reputation check, and share it with your lead.
  • Learn threat hunting basics

    Hunting means looking for activity no alert caught, starting from a hypothesis. L2s are often asked to run simple hunts, so a documented one shows initiative beyond the queue.

    First step
    Choose one MITRE ATT&CK technique relevant to your environment, write a hypothesis, run a query for it, and record what you found, even if it was nothing.
  • Ask your manager for the criteria

    Promotions stall when the bar is vague. Ask directly what separates L1 from L2 on your team, which examples would count as evidence, and when the next review happens. Then send a short follow-up email so the answer is in writing.

    First step
    Book fifteen minutes with your manager and ask: "What would I need to show you in the next six months for you to put me forward for L2?"

Sample conversation

How a conversation with Carmen starts

Carmen asks before she suggests. An illustrative example, not a real person.

I've been L1 for eighteen months. My reviews are good but nobody says when L2 happens.

Good reviews and no timeline usually means the bar has not been spelled out. Do you know what your manager counts as L2 work?

Not really. I think it's closing more complex tickets?

Let's find out instead of guessing. Want to draft the questions for a fifteen minute talk with your manager, and then list the evidence you already have?

Work it out with Carmen, free

30 free minutes with Carmen and the team. No card needed.

Questions & answers

How long does it take to go from L1 to L2 in a SOC?
It varies by team, size and turnover, and there is no standard timeline. The faster route is to learn your own team's criteria early and start producing evidence against them, such as write-ups, tuned rules and investigations you owned.
Do I need a certification to get promoted to L2?
Some teams require one, many do not. Ask your manager directly. Evidence of the work itself (investigations, write-ups, detections) usually carries more weight in an internal promotion than a certificate.
What if my SOC has no L2 opening?
Ask whether promotion depends on an opening or on meeting the bar. If there is no path on your team, the same evidence makes you a strong L2 candidate elsewhere, and Carmen can help you practice that interview.
How do I ask my manager about promotion without sounding pushy?
Frame it as wanting to know the bar: what L2 looks like on this team and what evidence would count. Most managers prefer that to guessing, and it gives you both something to check against at your next review.

More for security analysts

Grow in my role