Building and Operationalizing a SOC for a Digital Bank
SOC operations lead and engineer · 2024
The bank already had QRadar and some operating-system logs. I helped build the SOC operation around that starting point.
Context
The environment required close integration across SOC, administration, GRC, IT and business teams.
Problem
The platform existed, but the wider operating model, application visibility, case workflows, detection content and analyst processes still needed to be established.
Approach
Build the operating model around analyst decisions, then connect telemetry, use cases, case management, escalation and reporting into one repeatable service.
Implementation
- Expanded log-source onboarding and detection use cases.
- Built TheHive with Cortex and n8n from scratch.
- Created custom mail and Teams escalation connectors.
- Produced daily shift reporting with case SLA calculation and breach flagging.
- Defined playbooks, SOPs, shifts, escalation, stakeholder reporting and analyst development.
Decisions
Design workflows before adding automation
Automation should reinforce an agreed operating process.
Early effort goes into process definition rather than visible tooling.
Make SLA risk visible at handover
Daily reporting must surface cases requiring immediate management attention.
Case data quality must remain consistent.
Outcome
The bank moved beyond having a SIEM installed. Analysts had case workflows, escalation, reporting, playbooks and a clearer daily operating process.
Platforms & methods
QRadar · TheHive · Cortex · n8n · Microsoft Teams · GRC · SOPs