Build Hybrid Threat Detection SOC

Job ID: 40016332

Budget: $15 – $25 USD

I need an experienced security professional to help me stand up a full-featured Security Operation Center focused squarely on threat detection and rapid response. The SOC will watch over a hybrid estate—mixing on-prem servers with multiple cloud workloads—so the design must collect and correlate telemetry from both sides without gaps.

Core technologies are already chosen: a SIEM for log aggregation and correlation, network-based IDS/IPS for east-west and north-south traffic, and an Endpoint Detection & Response platform for host-level visibility. I’m open to specific vendor recommendations—Splunk, ELK, QRadar, Suricata, Snort, CrowdStrike, SentinelOne, etc.—as long as they integrate cleanly and can scale.

To keep expectations clear, here’s what I need delivered:

• A high-level SOC architecture diagram, bill of materials, and implementation roadmap.
• Installation, configuration, and tuning of the SIEM, including log onboarding from firewalls, servers, SaaS services, and cloud audit trails.
• Deployment and fine-tuning of IDS/IPS sensors across on-prem and cloud network segments.
• Rollout plan and baseline policy set for the EDR agent fleet.
• Alert rules, correlation searches, and automated playbooks for triage and response.
• Documentation and knowledge-transfer session so my internal team can operate the stack confidently.

Acceptance criteria: at least 95 % of critical log sources ingested, test attacks detected within agreed thresholds, and all runbooks validated in a tabletop exercise.

If you’ve built or operated a hybrid SOC before and can move quickly from design to production, let’s talk.