At Growing MSSP with Offensive Services, I combined SOC shift leadership with hands-on incident response in a seven-person team. The service supported 70,000+ endpoints across 150+ client organisations, including hospitality, aviation, education, law, finance and retail. Those environments had different operational constraints and required investigation and response decisions specific to each client.
I used Growing MSSP with Offensive Services's SIEM and SOAR platforms for alert triage and investigation, then followed the evidence through packet captures, process execution trees and logs from endpoints, network devices, cloud platforms and SaaS applications. Frequency analysis and timelines helped connect individual events to lateral movement, ransomware activity and other suspicious behaviour.
When an investigation required client action, I explained the observed activity, assessed root cause and impact, and guided containment and eradication. Technical reports translated the evidence into remediation decisions for operational contacts and senior stakeholders. I carried this responsibility alongside the investigation work documented in the linked cases.
Closer to the work
The operating environment
The seven-person SOC provided monitoring and incident response across a provider estate of 70,000+ endpoints and 150+ client organisations. My responsibilities combined shift management, alert and email triage, deeper investigation and client communication across first- through third-line support.
Open this detail ↗Investigation and communication
I correlated network traffic, process execution trees and endpoint, cloud and SaaS logs to reconstruct incident activity. Investigation reports connected the relevant evidence to root cause, impact and remediation, supporting containment and eradication decisions with the client.
Open this detail ↗Examples from the casework
The linked case studies examine compromised VPN accounts, Microsoft 365 account abuse, remote-support intrusion and staged malware execution. They show the underlying authentication, endpoint and network analysis behind the broader SOC responsibility.
Open this detail ↗Skills established through this work