HumanResourcely.
FreeJob description · mid

Threat Analyst job description.

A Threat Analyst monitors, investigates, and assesses cybersecurity threats to protect an organization's systems and data. They analyze indicators of compromise, track threat actor behavior, and produce actionable intelligence for security teams. The role requires technical depth in security tooling and clear reporting to both technical and executive stakeholders.

8 responsibilities·4 required + 3 preferred·US + AU
Ready to send

The Threat Analyst job description · $29

The full editable .docx — role summary, 8 worked responsibilities, qualifications, and skills, formatted for your letterhead. Delivered to your inbox within 24 hours — usually instantly.

Preview
HumanResourcely · Vol. I
Threat Analyst — Job Description

Role: Threat Analyst    Reports to: Security Operations Manager or CISO

A Threat Analyst monitors, investigates, and assesses cybersecurity threats to protect an organization's systems and data. They analyze indicators of compromise, track threat actor behavior, and produce actionable intelligence for security teams. The role requires technical depth in security tooling and clear reporting to both technical and executive stakeholders.

1. Key responsibilities
  • Monitor security alerts and identify indicators of compromise
  • Investigate and triage potential security incidents
  • Track threat actor tactics, techniques, and procedures (TTPs)
Full document with email opt-in
Composition

What's inside the document.

01Role summary

One-paragraph plain-English explanation of the role's outcome and scope.

02Responsibilities

8 responsibilities phrased the way the work is actually done.

03Required qualifications

4 qualifications a candidate must have to perform on day 30.

04Preferred qualifications

3 qualifications that would make a candidate excellent in year two.

05Skills

5 skill chips you can copy directly into your ATS.

06Reporting line

Security Operations Manager or CISO

What you receive

A complete document set.

  • Word document (.docx) — fully editable
  • PDF — signature-ready
  • Google Docs — one-click copy to your Drive
  • 12 months of updates to this document
  • Commercial-use licence for internal and client work
Responsibilities at a glance

The work, not the title.

  • Monitor security alerts and identify indicators of compromise
  • Investigate and triage potential security incidents
  • Track threat actor tactics, techniques, and procedures (TTPs)
  • Produce threat intelligence reports for security and leadership teams
  • Correlate data across SIEM, EDR, and network monitoring tools
  • Support incident response with analysis and containment recommendations
  • Maintain and tune detection rules based on emerging threats
  • Collaborate with IT and security engineering on vulnerability remediation
Qualifications

Required — and what would make a candidate excellent.

Required
  • Bachelor's degree in cybersecurity, computer science, or related field
  • 2+ years of experience in security operations or threat analysis
  • Working knowledge of SIEM and EDR platforms
  • Understanding of common attack frameworks (e.g., MITRE ATT&CK)
Preferred
  • Security certification such as Security+, GCIA, or GCTI
  • Experience with malware analysis or reverse engineering
  • Familiarity with scripting for automation (Python, PowerShell)
Skills
Threat intelligence analysisSIEM and EDR toolsIncident triageIndicator-of-compromise analysisSecurity reporting
How to use this template

Eight steps from download to publish.

  1. 01Open the Threat Analyst job description in Word or your one-click Google Docs copy.
  2. 02Replace placeholders for company name, reporting line, and location with your specifics.
  3. 03Tighten the summary to one paragraph that names the team's outcome, not just the role.
  4. 04Edit the responsibilities to match the actual scope of the seat — aim for 6 to 8 items, not 12.
  5. 05Separate required qualifications from preferred. Required is what a candidate must have to do the work on day 30; preferred is what would make them excellent in year two.
  6. 06Add salary range guidance using BLS, Payscale, or your own band data — do not copy generic figures.
  7. 07Have the hiring manager and one peer read it. Cut anything that wouldn't survive a candidate question.
  8. 08Publish to your ATS, intranet, and external careers page.
When to use this template

The right document at the right moment.

Use this Threat Analyst job description any time you are opening or reopening a seat at this level. The mid band sets the calibration — copy the document, tighten it to your specific scope, and circulate to the hiring panel before the first interview.

The reporting line (Security Operations Manager or CISO) and skills list are starting points. Override either if your org structure or stack differs from the norm — the template is a draft, not a contract.

FAQ

Honest answers before you download.

How does a Threat Analyst differ from a SOC Analyst?
A SOC Analyst typically monitors alerts in real time, while a Threat Analyst focuses more on investigating trends, actor behavior, and producing intelligence reports.
What certifications are most valued for this role?
Security+, GCIA, and GCTI are commonly recognized, though hands-on SIEM and incident response experience often carries equal weight.
Legal note

This Threat Analyst job description is a professionally drafted starting point for your hiring process and is not legal advice. Hiring practice varies by jurisdiction (e.g. pay-transparency laws differ across US states and AU jurisdictions). Adapt this document for your specific location and have employment counsel review any clauses you add before publishing. Salary varies by region, employer type, and experience. Reference BLS or current industry surveys for ranges. Full disclaimer.