| Aspect | Tier 3 Soc Analyst | Tier 2 Soc Analyst |
|---|
| Certifications | SIEM, CISSP, GCIH | Security+ or CEH |
| Work Environment | Advanced threat analysis, incident response, escalation | Monitoring, initial incident detection, triage |
| Responsibilities | Handling complex incidents, threat hunting, root cause analysis | Monitoring alerts, basic incident investigation |
Tier 3 Soc Analysts focus on advanced threat detection, incident escalation, and complex investigations, while Tier 2 Soc Analysts handle initial monitoring and basic incident response. Tier 3 roles require more specialized certifications and experience, making them suitable for more complex security challenges.