SECURITY OPERATIONS / LEADERSHIP
Building a more effective SOC
SOC strategy, response playbooks, and team development grounded in operational incident handling.
Klivvr · May 2024 – April 2025
The challenge
Security operations management spanning L1–L3 analysts, incident response, SIEM tuning, and threat intelligence.
My contribution
- Defined the SOC strategy, operating model, SLAs, and escalation paths.
- Rebuilt incident-response playbooks.
- Mentored SOC specialists and established shift models and performance KPIs.
- Deployed and tuned Microsoft Sentinel, Splunk, and SOAR with threat intelligence.
Results & outcomes
- 400+ incident-response cases led.
- 30% reduction in incident resolution time.
- 35% reduction in MTTR.
- 30% reduction in false positives.
Selected work summarized from my professional experience. Client-sensitive implementation details are not included.