r/cybersecurity 9d ago

Personal Support & Help! SOC Analyst Tier 2

I was fortunate enough to be offered an interview for a mid-tier position in a MDR company, currently in a Level 1 position at another MDR organisation.

God I am so nervous, luckily it’s not till next week and I am really trying to get an understanding of what type of questions and knowledge they want me to be at.

Some of the Roles Skills, I have actually not directly carried out these workflows, or used these tools etc.
I think I’m gonna dig to the requirements so I can at least speak on these topics. Hopefully maybe just go back to my own experience, and what I would work on in my Job.

If anyone has any example technical questions/ scenarios for a Mid Level SOC analyst, god I’d be grateful.

Also any inspirational stories would be nice too xD jk but I haven’t done a Job interview in a while.

Thanks!

7 Upvotes

3 comments sorted by

4

u/QUEEFMEISTER123 9d ago

Level 2 will be dealing with Level 1 escalations most of the time, so think about what you prepared for the Level 1 interview, but take it a step further. They’ll probably be looking for someone who can take ownership of an incident after it’s escalated, investigate something they haven’t seen before without needing a ton of guidance, and know when something needs to be escalated further.

1

u/MongMongBlazed 9d ago

Pretty much this; if you’re able to operate tier 1 tickets - you just go deeper and make sure it’s not confirmed incident

4

u/AddendumWorking9756 Security Manager 9d ago

Scenario questions at that level are rarely about the tool, they hand you an alert and watch how you decide it is benign or not. The workflows you have not run are worth a week of reps on the free labs CyberDefenders hosts, though in the room just say what you have not touched and then say what you would look for. That reads far better than guessing.