SOC tiers are the hierarchical levels of a Security Operations Center, each representing a different level of analyst expertise, alert complexity, and operational responsibility.
The tiered model exists for a practical reason: not every alert requires the same level of expertise to handle. A high volume of routine, low-complexity alerts can be processed efficiently by analysts with foundational skills. Complex investigations, advanced threat analysis, and strategic security decisions require deeper expertise that should not be consumed by routine triage work.
Tiering allows organizations to allocate analyst expertise efficiently — routing work to the appropriate level, escalating when complexity exceeds tier capability, and ensuring that senior expertise is applied where it delivers the greatest security value.
Most SOC models define three primary tiers, with some organizations adding a fourth for strategic and leadership functions.
Tier 1 — Alert Triage and Monitoring
Tier 1 is the entry point for security alerts in most SOC models. Tier 1 analysts are responsible for continuous monitoring, initial alert triage, and first-line investigation — determining whether incoming alerts represent genuine security events that require further attention.
Core Tier 1 responsibilities include:
- Monitoring security dashboards and alert queues continuously
- Triaging incoming alerts — assessing severity, validating whether the alert represents a genuine threat, and closing false positives
- Performing initial investigation steps — gathering basic context, checking asset information, and reviewing recent activity
- Escalating confirmed or suspected incidents to Tier 2 for deeper investigation
- Documenting alert handling and maintaining incident records
Tier 1 is the highest-volume tier — processing the largest number of alerts and handling the most routine security events. It is also the tier most directly affected by alert fatigue and the alert volume challenge that faces modern SOCs.
In AI-augmented SOC models, many traditional Tier 1 functions — alert triage, false positive filtering, initial enrichment — are handled by automated systems, with human Tier 1 analysts focusing on the alerts that AI cannot resolve with sufficient confidence.
Tier 2 — Incident Investigation and Response
Tier 2 analysts handle escalations from Tier 1 — conducting deeper investigations into confirmed or suspected security incidents and coordinating initial response actions.
Where Tier 1 determines whether an alert represents a genuine threat, Tier 2 determines what the threat is, how far it has progressed, and what response is required.
Core Tier 2 responsibilities include:
- Conducting in-depth investigation of escalated incidents — analyzing logs, correlating events, reconstructing attack timelines, and determining scope and impact
- Identifying affected systems, accounts, and data
- Executing or coordinating containment and remediation actions
- Engaging with Tier 3 for incidents that require specialist expertise or advanced analysis
- Managing the incident through to resolution and documenting findings
Tier 2 analysts require deeper technical skills than Tier 1 — including knowledge of attacker techniques, forensic investigation methods, and the specific security tools and environments used by the organization.
In AI-augmented SOCs, AI-assisted investigation tools compress the time Tier 2 analysts spend gathering evidence and reconstructing attack timelines — enabling faster, better-informed response decisions.
Tier 3 — Advanced Analysis and Threat Hunting
Tier 3 represents the highest level of technical expertise in the SOC — handling the most complex incidents, conducting proactive threat hunting, and providing specialist knowledge that Tier 1 and Tier 2 cannot.
Core Tier 3 responsibilities include:
- Investigating the most complex and high-severity security incidents — advanced persistent threats, sophisticated ransomware campaigns, nation-state activity
- Conducting proactive threat hunting — searching for evidence of threats that have evaded automated detection
- Developing and refining detection logic — building new detection rules, tuning existing ones, and closing coverage gaps identified through investigation and hunting
- Performing malware analysis and digital forensics on compromised systems
- Providing technical guidance and mentorship to Tier 1 and Tier 2 analysts
- Engaging with external threat intelligence sources and contributing organizational context back to the broader security community
Tier 3 analysts are the most experienced and specialized members of the SOC — and typically the scarcest, given the depth of expertise required. Their time is most valuable when applied to work that genuinely requires their skill level, rather than being consumed by alert triage or routine investigation that lower tiers can handle.
Learn more: What Is AI Threat Hunting?
Tier 4 — SOC Management and Strategic Oversight
Some SOC models define a Tier 4 encompassing SOC management, security engineering, and strategic security leadership — the functions responsible for directing the SOC’s operations rather than performing frontline security analysis.
Core Tier 4 responsibilities include:
- SOC management — overseeing daily operations, managing analyst teams, and ensuring that the SOC is meeting performance objectives
- Security architecture and engineering — designing and maintaining the technology stack that the SOC operates on
- Compliance and reporting — ensuring that security operations meet regulatory requirements and producing the reporting that governance and audit functions require
- Strategic threat intelligence — understanding the broader threat landscape and ensuring that SOC priorities and capabilities reflect the organization’s actual risk environment
- Program development — continuously improving SOC processes, tooling, and capability in response to evolving threats and organizational requirements


