Threat Analyst job description.
A Threat Analyst monitors, investigates, and assesses cybersecurity threats to protect an organization's systems and data. They analyze indicators of compromise, track threat actor behavior, and produce actionable intelligence for security teams. The role requires technical depth in security tooling and clear reporting to both technical and executive stakeholders.
The Threat Analyst job description · $29
The full editable .docx — role summary, 8 worked responsibilities, qualifications, and skills, formatted for your letterhead. Delivered to your inbox within 24 hours — usually instantly.
Role: Threat Analyst Reports to: Security Operations Manager or CISO
A Threat Analyst monitors, investigates, and assesses cybersecurity threats to protect an organization's systems and data. They analyze indicators of compromise, track threat actor behavior, and produce actionable intelligence for security teams. The role requires technical depth in security tooling and clear reporting to both technical and executive stakeholders.
- Monitor security alerts and identify indicators of compromise
- Investigate and triage potential security incidents
- Track threat actor tactics, techniques, and procedures (TTPs)
What's inside the document.
One-paragraph plain-English explanation of the role's outcome and scope.
8 responsibilities phrased the way the work is actually done.
4 qualifications a candidate must have to perform on day 30.
3 qualifications that would make a candidate excellent in year two.
5 skill chips you can copy directly into your ATS.
Security Operations Manager or CISO
A complete document set.
- Word document (.docx) — fully editable
- PDF — signature-ready
- Google Docs — one-click copy to your Drive
- 12 months of updates to this document
- Commercial-use licence for internal and client work
The work, not the title.
- Monitor security alerts and identify indicators of compromise
- Investigate and triage potential security incidents
- Track threat actor tactics, techniques, and procedures (TTPs)
- Produce threat intelligence reports for security and leadership teams
- Correlate data across SIEM, EDR, and network monitoring tools
- Support incident response with analysis and containment recommendations
- Maintain and tune detection rules based on emerging threats
- Collaborate with IT and security engineering on vulnerability remediation
Required — and what would make a candidate excellent.
- Bachelor's degree in cybersecurity, computer science, or related field
- 2+ years of experience in security operations or threat analysis
- Working knowledge of SIEM and EDR platforms
- Understanding of common attack frameworks (e.g., MITRE ATT&CK)
- Security certification such as Security+, GCIA, or GCTI
- Experience with malware analysis or reverse engineering
- Familiarity with scripting for automation (Python, PowerShell)
Eight steps from download to publish.
- 01Open the Threat Analyst job description in Word or your one-click Google Docs copy.
- 02Replace placeholders for company name, reporting line, and location with your specifics.
- 03Tighten the summary to one paragraph that names the team's outcome, not just the role.
- 04Edit the responsibilities to match the actual scope of the seat — aim for 6 to 8 items, not 12.
- 05Separate required qualifications from preferred. Required is what a candidate must have to do the work on day 30; preferred is what would make them excellent in year two.
- 06Add salary range guidance using BLS, Payscale, or your own band data — do not copy generic figures.
- 07Have the hiring manager and one peer read it. Cut anything that wouldn't survive a candidate question.
- 08Publish to your ATS, intranet, and external careers page.
The right document at the right moment.
Use this Threat Analyst job description any time you are opening or reopening a seat at this level. The mid band sets the calibration — copy the document, tighten it to your specific scope, and circulate to the hiring panel before the first interview.
The reporting line (Security Operations Manager or CISO) and skills list are starting points. Override either if your org structure or stack differs from the norm — the template is a draft, not a contract.
Honest answers before you download.
- How does a Threat Analyst differ from a SOC Analyst?
- A SOC Analyst typically monitors alerts in real time, while a Threat Analyst focuses more on investigating trends, actor behavior, and producing intelligence reports.
- What certifications are most valued for this role?
- Security+, GCIA, and GCTI are commonly recognized, though hands-on SIEM and incident response experience often carries equal weight.
Other documents in this neighbourhood.
Threat Intelligence Analyst
A Threat Intelligence Analyst researches and synthesizes information about emerging cyber threats, threat actors, and attack campaigns to inform an organization's security posture.
SOC Analyst
A SOC Analyst monitors an organization's security infrastructure to detect, investigate, and respond to cybersecurity threats.
Chief Information Security Officer
A Chief Information Security Officer leads an organization's information and cyber security strategy, protecting systems, data, and infrastructure from threats.
This Threat Analyst job description is a professionally drafted starting point for your hiring process and is not legal advice. Hiring practice varies by jurisdiction (e.g. pay-transparency laws differ across US states and AU jurisdictions). Adapt this document for your specific location and have employment counsel review any clauses you add before publishing. Salary varies by region, employer type, and experience. Reference BLS or current industry surveys for ranges. Full disclaimer.