Skip to main content
Back to all roadmaps

Roadmap

SOC Analyst — Tier 2 / Threat Hunter

The investigator and hunter. Takes escalated incidents from T1 and runs deep investigations, while proactively searching for threats that bypassed automated detection entirely.

OPTIMISTIC 18 monthsREALISTIC 2–3 years

This roadmap is interactive. Check off each competency as you learn it and your progress saves in your browser, free, with no signup. Come back any time and pick up where you left off.

FAQ

Common questions

How long does it take to become a SOC Analyst — Tier 2?

18 months optimistic at 20–25 hours/week from zero, 2–3 years realistic. The most common path is SOC T1 → SOC T2 with 12–18 months at T1. T2 demands deeper investigation skills, scripting fluency, threat hunting instincts, and the ability to determine scope and impact independently. T2 roles are fewer than T1 but higher value — analysts who add scripting, detection engineering, and hunting skills command significantly higher compensation and face less competition.

Which certifications matter for SOC T2 roles?

GCIH (GIAC Certified Incident Handler) for IR-overlapping T2 work. CySA+ for analytical depth. GCDA (GIAC Certified Detection Analyst) for detection engineering specialization. SANS-track certs are expensive but the content is the gold standard for T2 progression. Splunk Power User or Enterprise Certified Admin signal SIEM platform depth.

Do I need a CS degree?

No. T2 is meritocratic — demonstrated investigation skills and threat hunting writeups outweigh credentials. Self-taught analysts with strong CTF DFIR challenge solutions and lab investigation portfolios compete effectively. What you do need: scripting (Python at minimum), SIEM platform depth, threat intelligence consumption fluency, and at least basic memory analysis (Volatility) experience.

What separates a hired SOC T2?

Documented threat hunting writeups. Detection rules you've authored, threat hunts you've executed (even in lab environments), and investigation narratives that demonstrate analytical reasoning. Generic 'I know KQL' candidates lose to candidates with portfolio investigation work. Detection Engineering is the fastest-growing exit path from the T2 track.

Work through any roadmap and you are building proof of work as you go. A resume says it. A portfolio shows it. LabList is the living portfolio built for exactly this.

Building your own portfolio?

START YOUR 14-DAY TRIAL →