SOC Continuity & Service Leadership

Keeping response operational through an MDR transition

Led SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.

UK Water UtilitySenior Cyber Security Analyst2 min read

When the incumbent MDR provider became unavailable, the internal SOC had to absorb work that had been delivered externally. I led preservation of the provider’s operational knowledge, supported interim L1 incident handling and threat hunting, and applied emergency tuning while getting to grips with inherited Sentinel detections and parsers.

I engineered the CALLOUT process, which went live on 1 August 2025. It gave incidents requiring internal SOC involvement a defined out-of-hours escalation route, with operational procedures the team could use during the transition.

For the replacement service, I worked with the project manager and technical teams on the incident lifecycle across Microsoft Sentinel, ServiceNow Security Incident Response and XSOAR. I translated SOC needs into requirements for assignment, investigation context, escalation, reporting and audit trails, then tested the resulting workflows before and after go-live.

My contribution also covered joiner, mover and leaver processes and service access. I helped distinguish integration defects from expected analyst actions and advised on readiness for go-live within the wider delivery programme.

Closer to the work

Interim operations

I preserved the outgoing supplier’s knowledge base and helped the SOC take on interim L1 handling, tuning and hunting. Understanding the inherited Sentinel analytic rules and parsers was part of making those procedures usable: analysts needed to know what had triggered, what evidence to examine and when to escalate.

Open this detail ↗
An out-of-hours escalation route

CALLOUT established an out-of-hours route for incidents requiring the internal SOC. I engineered the process and brought it into operation on 1 August 2025, connecting escalation behaviour to the interim operating model.

Open this detail ↗
Replacement service requirements

I worked through how a Sentinel incident, a ServiceNow SIR and an XSOAR case should relate across assignment, comments, status, closure and redirection. Requirements also covered service access, reporting and auditability. I contributed SOC requirements and end-to-end acceptance testing alongside the project and platform teams.

Open this detail ↗

Skills established through this work

This work connects to

SOC engineeringSecurity leadership

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.