Skip to main content
Career roadmaps

What each security role actually involves

Six roles, mapped honestly: the skills that matter, the tools you will live in, what the day looks like, and where the role leads next.

About the salary ranges: these are indicative bands for the Indian market and vary widely by city, sector and company size. Treat them as orientation, not a forecast — and never as something we are promising.

SOC Analyst — Tier 1

Entry level · 0–2 years

₹4–8 LPA

The front line of security operations. You work the alert queue, decide what is real, and escalate what you cannot close.

Core skills

  • Alert triage and prioritisation
  • Log analysis across endpoint, network and identity
  • Phishing investigation
  • Incident documentation
  • MITRE ATT&CK fluency

A typical day

  • Working a shift queue and hitting response-time targets
  • Investigating alerts and recording the reasoning
  • Escalating with enough context that Tier 2 does not restart the work
  • Shift handovers and daily briefings

Next step: SOC Analyst Tier 2 or Detection Engineer

SOC Analyst Path

SOC Analyst — Tier 2

Mid level · 2–4 years

₹8–16 LPA

You take the cases Tier 1 escalates, run deeper investigations, and start owning detection quality.

Core skills

  • Deep-dive investigation and timeline reconstruction
  • Detection rule authoring and tuning
  • Threat hunting
  • Incident scoping and containment
  • Mentoring Tier 1 analysts

A typical day

  • Investigating escalated and complex multi-stage cases
  • Reducing false positives on noisy detections
  • Running hunts when nothing has alerted
  • Improving playbooks after each incident

Next step: Detection Engineer, Incident Responder or SOC Lead

SOC Analyst Path

Detection Engineer

Mid to senior · 3–6 years

₹14–28 LPA

You build the detection content the SOC runs on, and you are accountable for whether it works.

Core skills

  • Detection-as-code and version-controlled content
  • Coverage measurement against ATT&CK
  • Adversary emulation and validation
  • Data pipeline and log source engineering
  • Query performance and cost awareness

A typical day

  • Translating threat intelligence into deployed detections
  • Validating detections against emulated attacks
  • Owning coverage gaps and arguing for log sources
  • Reviewing detection changes from the team

Next step: Senior Detection Engineer or Security Architect

SOC Analyst Path

Cloud Security Analyst

Entry to mid · 1–3 years

₹8–18 LPA

You monitor and investigate the cloud estate, and turn posture findings into work that actually reduces risk.

Core skills

  • Cloud identity and access fundamentals
  • Control-plane log analysis
  • Misconfiguration triage and prioritisation
  • Cloud sign-in and access investigation
  • Shared-responsibility reasoning

A typical day

  • Investigating suspicious cloud sign-ins and access changes
  • Working through posture findings and deciding what matters
  • Reviewing access requests and permission changes
  • Documenting cloud investigations

Next step: Cloud Security Engineer

Cloud Security Path

Cloud Security Engineer

Mid to senior · 3–7 years

₹16–35 LPA

You are responsible for whether the cloud estate is defensible, monitored and recoverable.

Core skills

  • Cloud identity and privileged access architecture
  • Policy-as-code and drift prevention
  • Infrastructure-as-code security review
  • Container and serverless workload security
  • Cloud incident investigation

A typical day

  • Reviewing architecture and infrastructure changes
  • Building guardrails that developers can live with
  • Designing detection coverage across the estate
  • Investigating control-plane anomalies

Next step: Cloud Security Architect or Head of Cloud Security

Cloud Security Path

Incident Responder

Senior · 4–8 years

₹18–36 LPA

You lead the response when something significant has happened, and you are the calmest person in the room.

Core skills

  • Incident command and coordination
  • Digital forensics and evidence handling
  • Containment decision-making
  • Stakeholder and executive communication
  • Post-incident review facilitation

A typical day

  • Running major incidents across multiple teams
  • Determining scope, root cause and impact
  • Briefing leadership, legal and sometimes regulators
  • Turning findings into permanent improvements

Next step: IR Lead or Security Manager

Enterprise Security Path
Getting there

Every one of these roles starts in the same place

With the ability to investigate properly. Specialisation comes after that, and specialising too early is the most common way to stall.

Next cohort enrolling

Which role fits what you already have?

Bring your background to a consultation and a mentor will map it against these roles, including the gaps you would need to close.

Prefer email? connectbluelayersacademy@gmail.com

What the call actually is

  • 45 minutes, with a mentor rather than a sales team
  • A written recommendation you keep either way
  • An honest answer if a program is not right for you yet

We do not guarantee placement, and we will say so on the call. What we are accountable for is whether you finish able to do the work.