A Security Operations Center (SOC) is organized into tiers. Tier 1 Analysts triage alerts, Tier 2 Analysts perform deep investigation, and Tier 3 analysts handle advanced threat hunting.
Beyond the analyst tiers, Security Engineers build and tune detections, while Security Architects design the overall defensive infrastructure and data pipelines.