SOC Roles and Responsibilities
The SOC team consists of 4 different tiers of SOC analysts and dedicated managers.
Triage Specialist
Tier 1 analysts are responsible for collecting raw data and analyzing alarms and alerts. Their duties include verifying, evaluating, and adjusting alert severity while enhancing them with relevant contextual insights.
Incident Responder
Tier 2 analysts manage escalated high-priority security incidents. They perform a more in-depth analysis uing threat intelligence to assess the attack's scope and pinpoint the affected systems.
Threat Hunter
Tier 3 analysts are the most experienced professionals in a SOC, tasked with handling critical incidents escalated by incident responders. They lead or execute vulnerability assessments and conduct penetration testing to uncover potential attack vectors.
SOC Manager
SOC managers supervise the security operations team, ensuring smooth coordination and offering technical guidance as needed. Their primary responsibility is to lead the team, ensuring optimal efficiency and effectiveness in security operations.