Skip to content

Building and Operationalizing a SOC for a Digital Bank

SOC operations lead and engineer · 2024

The bank already had QRadar and some operating-system logs. I helped build the SOC operation around that starting point.

Context

The environment required close integration across SOC, administration, GRC, IT and business teams.

Problem

The platform existed, but the wider operating model, application visibility, case workflows, detection content and analyst processes still needed to be established.

Approach

Build the operating model around analyst decisions, then connect telemetry, use cases, case management, escalation and reporting into one repeatable service.

Implementation

  • Expanded log-source onboarding and detection use cases.
  • Built TheHive with Cortex and n8n from scratch.
  • Created custom mail and Teams escalation connectors.
  • Produced daily shift reporting with case SLA calculation and breach flagging.
  • Defined playbooks, SOPs, shifts, escalation, stakeholder reporting and analyst development.

Decisions

Design workflows before adding automation

Automation should reinforce an agreed operating process.

Early effort goes into process definition rather than visible tooling.

Make SLA risk visible at handover

Daily reporting must surface cases requiring immediate management attention.

Case data quality must remain consistent.

Outcome

The bank moved beyond having a SIEM installed. Analysts had case workflows, escalation, reporting, playbooks and a clearer daily operating process.

Platforms & methods

QRadar · TheHive · Cortex · n8n · Microsoft Teams · GRC · SOPs