Evolving a Monitoring-Focused SOC into a Multi-Disciplinary Cyber Defense Service
Cyber defense lead · 2026
The service started with monitoring. I grew the team and added the work needed to handle incidents, assessments, engineering and architecture.
Context
The team includes multiple analyst levels, administrators and engineers working across managed and resident delivery models.
Problem
The existing service centered on monitoring and needed the people, processes and engineering depth to handle investigations, assessments and capability improvement.
Approach
Build the team and operating model together, delegate through senior practitioners, and remain directly accountable for consulting, architecture, engineering and client-facing outcomes.
Implementation
- Defined priorities, schedules, escalation and reporting across client work.
- Added DFIR, compromise assessment, architecture and engineering workstreams.
- Established mentoring and formal performance evaluation.
- Developed service roadmaps, use-case practices, playbooks and technical integrations.
Decisions
Grow capability, not only headcount
Role clarity, mentoring and operating practices determine whether a larger team produces better defense.
Capability building competes with immediate delivery pressure.
Keep technical decisions distributed
Senior analysts and engineers need ownership while leadership remains accountable.
Delegation requires consistent review and standards.
Outcome
The team could take on more than monitoring. SOC operations, incident response, assessments and engineering now worked under the same delivery model.
Platforms & methods
MSOC · SIEM · SOAR · EDR · DFIR · MITRE ATT&CK · Service Management