When the incumbent MDR provider became unavailable, the internal SOC had to absorb work that had been delivered externally. I led preservation of the provider’s operational knowledge, supported interim L1 incident handling and threat hunting, and applied emergency tuning while getting to grips with inherited Sentinel detections and parsers.
I engineered the CALLOUT process, which went live on 1 August 2025. It gave incidents requiring internal SOC involvement a defined out-of-hours escalation route, with operational procedures the team could use during the transition.
For the replacement service, I worked with the project manager and technical teams on the incident lifecycle across Microsoft Sentinel, ServiceNow Security Incident Response and XSOAR. I translated SOC needs into requirements for assignment, investigation context, escalation, reporting and audit trails, then tested the resulting workflows before and after go-live.
My contribution also covered joiner, mover and leaver processes and service access. I helped distinguish integration defects from expected analyst actions and advised on readiness for go-live within the wider delivery programme.
Closer to the work
Interim operations
I preserved the outgoing supplier’s knowledge base and helped the SOC take on interim L1 handling, tuning and hunting. Understanding the inherited Sentinel analytic rules and parsers was part of making those procedures usable: analysts needed to know what had triggered, what evidence to examine and when to escalate.
Open this detail ↗An out-of-hours escalation route
CALLOUT established an out-of-hours route for incidents requiring the internal SOC. I engineered the process and brought it into operation on 1 August 2025, connecting escalation behaviour to the interim operating model.
Open this detail ↗Replacement service requirements
I worked through how a Sentinel incident, a ServiceNow SIR and an XSOAR case should relate across assignment, comments, status, closure and redirection. Requirements also covered service access, reporting and auditability. I contributed SOC requirements and end-to-end acceptance testing alongside the project and platform teams.
Open this detail ↗Skills established through this work