Roles and responsibilities in Threat Intel Management
A Threat Intel Management (TIM) analyst may have a different persona in the SOC. In some organizations, the TIM analyst is part of the SOC analyst’s definition of work, but they have different workflows and use cases. The daily work of SOC analysts and TIM analysts are different.
| Roles | Responsibility |
| ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Security Analyst (SOC Tier-1) | <ul><li>Triage Specialist</li><li>Monitor, manage, and configure security tools</li><li>Review cases to assess their urgency</li><li>Escalate cases when necessary</li></ul> |
| Threat Intel Analyst (SOC Tier 2-3) | <ul><li>Case responders and threat hunters</li><li>Remediation of escalated cases from Tier 1 - investigation, response, and assessments</li><li>Proactive work to remove infrastructure weaknesses</li></ul> |