Skip to content

Evolving a Monitoring-Focused SOC into a Multi-Disciplinary Cyber Defense Service

Cyber defense lead · 2026

The service started with monitoring. I grew the team and added the work needed to handle incidents, assessments, engineering and architecture.

Context

The team includes multiple analyst levels, administrators and engineers working across managed and resident delivery models.

Problem

The existing service centered on monitoring and needed the people, processes and engineering depth to handle investigations, assessments and capability improvement.

Approach

Build the team and operating model together, delegate through senior practitioners, and remain directly accountable for consulting, architecture, engineering and client-facing outcomes.

Implementation

  • Defined priorities, schedules, escalation and reporting across client work.
  • Added DFIR, compromise assessment, architecture and engineering workstreams.
  • Established mentoring and formal performance evaluation.
  • Developed service roadmaps, use-case practices, playbooks and technical integrations.

Decisions

Grow capability, not only headcount

Role clarity, mentoring and operating practices determine whether a larger team produces better defense.

Capability building competes with immediate delivery pressure.

Keep technical decisions distributed

Senior analysts and engineers need ownership while leadership remains accountable.

Delegation requires consistent review and standards.

Outcome

The team could take on more than monitoring. SOC operations, incident response, assessments and engineering now worked under the same delivery model.

Platforms & methods

MSOC · SIEM · SOAR · EDR · DFIR · MITRE ATT&CK · Service Management