Summary
Regardless of the number of personnel on a team, certain roles must be fulfilled. Communication will play a critical role at all stages of the threat hunt and from all members of the team. This process will be overseen by the team lead position. Whether there are 2 individuals or 25, there will always be a team lead.
Host- and network-based analyst roles are a little more flexible and can be combined if it is the right fit for the hunt. Additionally, a TI analyst will always be a major boost for a hunt team, so fight for them to be included. Incident response (IR) personnel are a part of an organization's remediation process—threat-hunt analysts are not. When in doubt, leverage NIST Special Publication 800-181 Revision 1, Workforce Framework for Cybersecurity (NICE Framework), to build out the hunt team's capability requirements and training pathways.
There is no one correct way to build a team—each hunt will be unique, and the team should be tailored...