Build Hybrid Threat Detection SOC
Budget: $15 – $25 USD
I need an experienced security professional to help me stand up a full-featured Security Operation Center focused squarely on threat detection and rapid response. The SOC will watch over a hybrid estate—mixing on-prem servers with multiple cloud workloads—so the design must collect and correlate telemetry from both sides without gaps.
Core technologies are already chosen: a SIEM for log aggregation and correlation, network-based IDS/IPS for east-west and north-south traffic, and an Endpoint Detection & Response platform for host-level visibility. I’m open to specific vendor recommendations—Splunk, ELK, QRadar, Suricata, Snort, CrowdStrike, SentinelOne, etc.—as long as they integrate cleanly and can scale.
To keep expectations clear, here’s what I need delivered:
• A high-level SOC architecture diagram, bill of materials, and implementation roadmap.
• Installation, configuration, and tuning of the SIEM, including log onboarding from firewalls, servers, SaaS services, and cloud audit trails.
• Deployment and fine-tuning of IDS/IPS sensors across on-prem and cloud network segments.
• Rollout plan and baseline policy set for the EDR agent fleet.
• Alert rules, correlation searches, and automated playbooks for triage and response.
• Documentation and knowledge-transfer session so my internal team can operate the stack confidently.
Acceptance criteria: at least 95 % of critical log sources ingested, test attacks detected within agreed thresholds, and all runbooks validated in a tabletop exercise.
If you’ve built or operated a hybrid SOC before and can move quickly from design to production, let’s talk.
Core technologies are already chosen: a SIEM for log aggregation and correlation, network-based IDS/IPS for east-west and north-south traffic, and an Endpoint Detection & Response platform for host-level visibility. I’m open to specific vendor recommendations—Splunk, ELK, QRadar, Suricata, Snort, CrowdStrike, SentinelOne, etc.—as long as they integrate cleanly and can scale.
To keep expectations clear, here’s what I need delivered:
• A high-level SOC architecture diagram, bill of materials, and implementation roadmap.
• Installation, configuration, and tuning of the SIEM, including log onboarding from firewalls, servers, SaaS services, and cloud audit trails.
• Deployment and fine-tuning of IDS/IPS sensors across on-prem and cloud network segments.
• Rollout plan and baseline policy set for the EDR agent fleet.
• Alert rules, correlation searches, and automated playbooks for triage and response.
• Documentation and knowledge-transfer session so my internal team can operate the stack confidently.
Acceptance criteria: at least 95 % of critical log sources ingested, test attacks detected within agreed thresholds, and all runbooks validated in a tabletop exercise.
If you’ve built or operated a hybrid SOC before and can move quickly from design to production, let’s talk.
Related categories:
Cisco
Network Administration
Internet Security
Splunk
Cloud Security
Network Security
Data Protection