You're either deciding whether to become a SOC analyst or you're already in tier 1 and wondering what the next step pays and whether AI will take it. This guide answers both, in that order.
The short version is that a SOC analyst gets paid, and promoted, for making good calls, not for working through a queue. AI agents are taking over the queue work, so the way in and the way up are now the same thing. Show that you can investigate.
What does a SOC analyst do?
A SOC analyst turns alerts into decisions. A detection tool says something might be wrong. The analyst works out whether it is, how far it reaches, and what should happen next, then hands that answer to whoever responds.
Six activities make up most of the work, at every tier:
- Gathering context. Pulling the user, the host, the process, the network connection and the recent history around an alert from the SIEM (security information and event management), the endpoint tool and the identity provider.
- Building the timeline. Putting those pieces in order so the sequence of events is clear, which is where most false positives fall apart and most real threats start to make sense.
- Reaching a verdict. Deciding, with evidence, whether the alert is benign, a false positive, or a real threat, and how severe it is.
- Escalating or closing. Ruling out what can be ruled out and handing what can't to the next tier with the evidence attached.
- Handing off a plan. Telling response what to contain, what to watch and what to check afterward.
- Writing it down. The case notes, the shift handover and the reporting that turns one investigation into something the rest of the team and your management can use.
That work is changing. In a growing number of SOCs, AI agents now do the gathering and the first pass at the timeline, and the analyst spends the shift on the verdicts and the plans. The section on what AI changes covers that in detail.
What are the SOC analyst tiers, and what does each one do?
Tiers exist because the queue is deep, not because seniority needs a ladder. A SOC needs triage capacity at the front of the queue, deeper investigation on what gets escalated, and hunting for what never produced an alert at all.
Plenty of SOCs split that into three tiers with management above. Plenty run tierless and do the same work without the labels, and the field's standard SOC handbook says either arrangement can work.
The tiers are flattening. The 2026 SANS SOC Survey found lack of skilled staff is the top operational challenge, cited by 14 percent of respondents, and SIEM the most sought-after skill in hiring, with nearly double the demand of EDR (endpoint detection and response).
In SOCs that have adopted AI investigation, the gathering work that used to fill a tier 1 shift is done by agents before an analyst sees the alert, so the tier 1 job becomes a tier 2 job sooner.
Our post on what AI changes for tier 1, 2 and 3 analysts walks each tier through that shift.
Is SOC analyst an entry-level job?
Tier 1 is the entry point into security operations, and it's also a crowded one. Most postings still ask for a year or two somewhere adjacent, usually a service desk, network operations or sysadmin role, before they'll call a candidate entry level.
The 2025 ISC2 Cybersecurity Workforce Study, which surveyed 16,029 practitioners and decision-makers, puts entry and junior-level staff at 5 percent of its respondents. That's a share of the survey sample, not of open jobs, but it says something about how small the entry rung is next to the rest of the field.
If you're aiming at tier 1, the section on how to get in covers what separates the candidates who land it.
What is a SOC analyst salary in 2026, and what moves it?
SOC analyst salary depends on six things, roughly in this order, and no national figure captures your situation. Check live listings for your region and tier before you negotiate anything:
- Tier. The jump from tier 1 to tier 2 is typically the largest single pay move, because it's the point where you stop being paid to work the queue and start being paid to make the calls.
- Region and cost of living. The same tier 2 job pays very differently in a major metro and a smaller market, and remote roles increasingly pay a set band no matter where you live.
- Clearance. A government clearance, especially an active one, puts you in a smaller pool, and defense and federal contractors pay for that.
- Shift and on-call. Nights, weekends and on-call rotations carry differentials in most SOCs. Ask what they are and whether they're in the base or on top of it.
- Industry. Financial services, defense and large technology companies tend to pay more for the same tier. MSSPs vary widely with the client mix.
- Certifications. A relevant certification can get you the interview and sometimes a step within a band. It rarely moves you between bands on its own.
The way to turn those six factors into a number is to read three live postings against each other.
Pick three for the same tier in your region, one at a large enterprise, one at an MSSP and one in the public sector, and compare where the bands sit and what each one asks for. That spread is your market, and it's more current than any published average.
Two data points frame what to expect from year to year. The ISC2 2025 study found 57 percent of respondents received a raise of 1 to 9 percent over the past year, and 20 percent received none. Pay growth in this field is real for most analysts, and modest.
The other data point is about what keeps analysts in a job. The SANS 2026 survey found meaningful work and career progression are the top retention drivers for the third year running, and compensation has fallen to fourth place. When you evaluate an offer, ask about progression as hard as you ask about the number.
Base pay is also only part of the package, and the rest is easier to negotiate. Ask about these before you accept:
- Shift differential and on-call pay. Whether nights and weekends pay extra, and whether on-call is compensated or expected.
- Training budget and certification reimbursement. Who pays for the course and the exam, and whether study time is on the clock.
- Conference and course time. Days per year you can spend learning without using leave.
- Bonus structure. What it's measured on, and whether SOC metrics you don't control decide it.
- Schedule flexibility. Remote days, shift swaps and how rotations are set.
Is SOC a high-paying job?
It can be, and the ceiling isn't in the tiers. Tier 1 sits in the field's lower bands, and the top of the range is in specialization, such as detection engineering, threat hunting or incident response, and in leadership, where you're responsible for a whole program instead of a queue.
How do you become a SOC analyst?
Three routes account for most of the analysts who make it into tier 1:
- Adjacent IT into tier 1. Help desk, network operations or systems administration, where you learned how the environment works and picked up the logs and the tickets along the way. This route is common because it builds exactly the skills postings test for.
- Degree plus internship. A cybersecurity or computer science degree with a SOC internship or a co-op. The degree opens the door. The internship is what the interviewer asks about.
- Career change through a home lab and an entry certification. A lab you built, a SIEM you stood up, alerts you wrote and investigated, and one certification that proves the vocabulary. It works when the lab work is real and documented.
What postings ask for is more consistent than the routes:
- SIEM fluency. Searching, correlating and building a timeline from logs. It's the skill the SANS 2026 survey found employers want most.
- Endpoint and network fundamentals. How processes, users and connections behave on Windows and Linux, and what normal looks like on a network.
- Attack knowledge. Common techniques and the evidence they leave, usually referenced to MITRE ATT&CK.
- Writing. Investigation notes that a responder can act on. Postings rarely mention it. The interview comes down to it.
- One entry-level certification. Most postings name one; few name more than two.
The tier 1 pool is competitive, and evidence that you can investigate separates candidates more reliably than a longer certificate list.
How do you show you can investigate?
Bring three written-up investigations to the interview, from a lab, an internship or a previous role.
Each one fits on a page and follows the same steps the job does:
- The alert. What fired, from which tool, and what it claimed.
- The context you gathered. The user, host, process and connections you pulled, and where you pulled them from.
- The timeline you built. The sequence of events, in order, with the evidence for each step.
- The verdict. Benign, false positive or real, with the reasoning, and what you'd have escalated.
- What you'd tune. The detection change that would have made the alert clearer, or the false positive quieter.
If you're building the evidence from scratch, an open-source SIEM on a couple of virtual machines is enough. Write a handful of detections, trigger them, and investigate what fires. Three honest write-ups do more in an interview than any credential, because they show what the job is.
Which certifications and training do SOC analyst jobs ask for?
A small set appears in most tier 1 and tier 2 postings, and which one a given employer names depends on where they recruit. CompTIA Security+ is the most common entry-level requirement.
GIAC certifications come next, and the GCIH (incident handling) is the one that turns up most in incident-analyst postings. The GSOC (security operations) is the certification behind SANS SEC450, a course SANS now calls AI-Enabled Security Operations.
The CISSP (Certified Information Systems Security Professional) turns up more widely than its senior-role reputation suggests. In posting data it's among the most requested certifications for analyst jobs, not just for leadership ones. Pick the one your target postings name, earn it, and spend the rest of the time on lab work.
What does a tier 1 shift look like?
A tier 1 shift starts with the overnight queue and the handover. Then it's the live queue. Read the alert, pull the context, decide whether it's real, document it, escalate or close. Between alerts you tune what you can, note patterns in the false positives and prepare the handover for whoever's next.
When a serious alert lands, every routine changes. Whoever caught it escalates, tier 2 sizes it, the responders assemble, and the SOC moves from the queue to a single case until it's contained.
What skills and tools does a SOC analyst need in 2026?
The useful way to sort the skills is by where they're heading. Part of the work is moving to AI agents, and the skills that remain are the ones you're paid for.
Which skills are the AI agents absorbing?
- Routine lookups and correlation. Pulling the user, host, process and connection history for every alert, across four consoles.
- First-pass enrichment. Checking the indicator against intelligence and the asset against the inventory before anyone decides anything.
- Timeline assembly on the common cases. The login from a new device, the phishing report, the malware the endpoint tool already blocked.
- Playbook execution. The repeatable response steps that were always going to be automated.
You still need to be able to do all of it, because you can't check an agent's work without knowing how the work is done. You just stop spending the shift on it.
Which skills are you paid for?
- Reading evidence. Following a chain of reasoning, yours or an agent's, and spotting the step that doesn't hold.
- Deciding. Reaching a verdict on an unfamiliar case and owning it.
- Explaining. Writing the finding so a senior analyst can check it and a manager can act on it.
- Knowing what the tools can't see. The blind spots in the telemetry, the log source nobody onboarded, the alert that should have fired and didn't.
- Detection logic and scripting. Turning what a case taught you into a rule that holds, and automating the lookup you'd otherwise do fifty times a shift.
The tools are best understood as categories, because the specific product changes with the employer and the fundamentals don't:
- SIEM is where you search, correlate and build the timeline. It's the core tool at tier 1 and tier 2.
- EDR shows you the process tree, the file activity and the persistence on the endpoint.
- NDR (network detection and response) shows you what crossed the network and between which hosts.
- Threat intelligence platforms tell you whether the indicator or the technique in front of you has been seen before, and where.
- SOAR (security orchestration, automation and response) runs the repeatable responses the team has written playbooks for.
- AI SOC agents investigate alerts end to end and return findings with the reasoning and evidence attached, which changes what the analyst does with every tool above.
Will AI replace SOC analysts?
No, and the job is changing shape. The evidence for both halves of that answer comes from the same sources.
AI is already in the job description. The ISC2 2025 study found AI was the most pressing skill needed, cited by 41 percent of respondents, and that 70 percent of respondents hold or are pursuing AI qualifications.
The SANS 2026 survey found 79 percent of respondents use AI or ML tools, but only 36 percent have built them into a defined SOC workflow. Most SOCs have AI somewhere. Far fewer have changed how the SOC runs around it, and that gap is where the analyst's job is being redefined.
Gartner's definition in the Hype Cycle for Security Operations, 2026, which you can get from Dropzone AI's report page, puts it plainly. AI SOC agent solutions "use AI to help augment many of the common activities found within security operations."
The fear underneath the question is real. The tier 1 seat is changing faster than the job title, and the analyst in it is the first candidate for the work it's becoming.
There's a practical reason the job survives. When AI agents investigate every alert instead of the slice the team had time for, more real decisions come up, not fewer. The hunt that never got run finds something. The advisory nobody had time to act on turns out to matter.
Analysts have to set the limits on what the agents do on their own, and widen them as the agents earn trust. And when an analyst corrects a verdict or explains what's normal in this environment, that knowledge sticks and shapes the next investigation, instead of leaving when the analyst does.
What that looks like in practice is the same team covering far more. Zapier runs 85 percent less manual alert investigation with a three-person team. Coverage grew, and the three-person team got the work they trained for.
What does an analyst do when AI agents investigate the alerts?
The human analyst's role concentrates on five things, and none of them is the job of Dropzone AI's AI SOC Analyst, which is the software agent doing the investigating:
- Deciding. Every finding arrives with the reasoning attached, and the analyst owns the verdict.
- Setting the limits. What the agents can do autonomously, where they stop and ask an analyst, and what always needs a human decision.
- Reviewing the reasoning. Following how an agent reached a conclusion, then agreeing or correcting it.
- Correcting verdicts. Corrections stick and change the next investigation, so what the team knows about the environment stops living in one head.
- Hunting what the agents surface. The leads that never produced an alert.
The skills to build follow from the list. Judge AI findings on the evidence, not on how confident the output sounds, know what the tools can't see, and tune the agents to what's normal in your environment. Spot the edge cases that need your judgment. Learn to write a limit, a clear statement of what's allowed to happen without you.
What does the SOC analyst career path look like from tier 1 to leadership?
Progression in a SOC runs three ways, and the sooner you pick a direction the faster it goes.
- Up the tiers. Tier 1 to tier 2 to tier 3, then team lead, manager and director. It's the default path and the slowest, because each step waits on a seat opening above you.
- Into a specialty. Threat hunting, detection engineering, incident response, threat intelligence, forensics or security engineering. Specialists at tier 3 are often paid on a par with managers without managing anyone.
- Into leadership. Team lead, SOC manager, director of security operations. The skill that gets you there can be practiced from tier 2, by being the analyst who writes the incident summary the CISO forwards.
What do the SOC specialties do?
Each specialty is a tier 3 job you can start auditioning for at tier 2:
- Threat hunting. Hypothesis-driven search for what no alert fired on, across the SIEM, endpoint and cloud telemetry. Audition by hunting on your own time and writing up what you found, including the hunts that found nothing.
- Detection engineering. Turning what hunts and cases teach into detections that hold, and retiring the ones that only make noise. Audition by fixing the noisiest detection on your queue and showing the before and after.
- Incident response. Running the case from confirmation to recovery, including the stakeholders and the communication. Audition by being the analyst whose escalation notes the responders use.
- Threat intelligence. Reading advisories, deciding what applies to this environment, and giving the hunters something to look for. Audition by bringing one advisory a week to the team with the answer to "does this apply to us."
- Forensics. Evidence handling on the hard cases, where what you preserve and how you preserve it decides what can be proved later. Audition by writing case notes that hold up when the case is reopened.
Ask your employer about progression before you need it. The SANS 2026 survey found 59 percent of cyber leaders say management pays close attention to SOC hiring and retention needs, and only 32 percent of practitioners agree.
That 27-point gap is the difference between what leadership believes about your path and what you're experiencing on it, and it's worth closing in a conversation rather than an exit interview.
The retention data above is advice to you, not to your employer. If a role offers a raise and no path, that's the trade you're making.
Where the SOC analyst role is going
The category is moving toward the agentic SOC, a way of running security operations where a collective of specialized AI agents does the investigating, hunting and threat intel work around the clock and analysts make the decisions. Dropzone AI runs that model in production across 300+ deployments.
Gartner's 2026 Hype Cycle for Security Operations tracks where that category sits and names the vendors in it, and it's the right read for anyone planning a career around what the SOC will look like in three years.
If you want to see what an analyst works with when agents do the investigating, the self-guided demo lets you watch the AI SOC Analyst work real alerts and return findings with the evidence attached, and there's nothing to set up.
Key takeaways
- The path runs tier 1, tier 2, tier 3, leadership, and the tier 1 to tier 2 move is typically the biggest pay step.
- Pay moves on tier, region, clearance, shift, industry and certifications, in roughly that order. Read three live postings in your region against each other.
- Getting in takes evidence you can investigate, from an adjacent IT role, an internship or a documented lab, more than a long certificate list.
- The agents take the evidence gathering. Analysts keep the decisions, the limits and the corrections.
- Ask about the path as hard as the number. Progression outranks pay as the reason analysts stay.
Frequently asked questions
No, you don't. A degree plus an internship is one of three common routes, alongside moving over from help desk, network operations or systems administration, and a career change built on a home lab and one entry certification. Postings test for SIEM fluency, endpoint and network fundamentals, attack knowledge and writing, and the interview turns on written-up investigations more than on credentials.
In most SOCs, yes, and the structure matters more than the label. Ask whether the differential is a percentage of base or a flat add, whether it applies to the whole shift or only the hours after a cutoff, and whether on-call pays a standing stipend, a called-out rate, or nothing until you're paged. Get the answer in writing before you accept.
Both, and that's why job searches get confusing. Dropzone AI's AI SOC Analyst is a software agent that investigates alerts end to end. Postings for "AI SOC analyst" roles almost always mean a human analyst who works with agents, reviews their findings, sets the limits they work within and owns the verdict.
A SOC analyst works alerts and cases, gathering context, building the timeline and reaching a verdict. A security engineer builds and maintains what the analyst works with, the detections, the log pipelines and the tooling. Tier 3 straddles the two, since detection engineering and hunting are where analysis turns into engineering, and it's a common path from one role to the other.
There's no reliable published number, and it varies by SOC. What shortens the wait is a manager who lets tier 1 finish investigations rather than escalate on pattern, and a written record of the ones you took further. What lengthens it is a queue so deep that nobody at tier 1 ever gets past the playbook, which is worth asking about in the interview.







.png)