Security Operations Leadership

CNI SOC leadership and investigation standards

Onboarded six SOC colleagues, defined investigation quality criteria and coached analysts on AiTM, NAT and identity attacks while providing management cover.

UK Water UtilitySenior Cyber Security Analyst2 min read

At UK Water Utility, I helped develop the analysts and investigation practices supporting a critical national infrastructure SOC. I contributed to recruitment and personally onboarded six analysts and engineers, introducing colleagues to the team's operational work and investigation expectations.

I defined criteria for triage notes, evidence, root cause, impact and response, then introduced review of investigation records against those expectations. This work formed part of a standards library developed with colleagues. My technical teaching covered Adversary-in-the-Middle investigations, tracing traffic through NAT, email authentication and Pass-the-Ticket guidance, alongside practical support for analysts.

I also provided management cover during recorded absences and maintained operational handovers. Work with external partners on response playbooks and IT/OT incident ownership connected the investigation standards to decisions about who should act and how the response should proceed.

Closer to the work

Recruitment and onboarding

I participated in interviews and shared hiring decisions for six analysts and engineers, then personally onboarded all six. The contribution combined recruitment with the practical transfer of SOC context and investigation expectations.

Open this detail ↗
Practical technical teaching

I delivered sessions on Adversary-in-the-Middle investigation and tracing the origin of traffic behind NAT. Supporting knowledge material covered email authentication, the significance of hosting IP addresses and Pass-the-Ticket investigation guidance.

Open this detail ↗
Management cover and standards

I covered management responsibilities during two documented absences in 2025. Alongside operational handovers, I defined investigation expectations and introduced case-note review covering triage, evidence, root cause, impact and response. The wider ticket-writing standard and standards library were collaborative.

Open this detail ↗

Skills established through this work

This work connects to

Security leadershipSOC & incident response

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.