Building and Leading Security Operations Centres
A course for the people who run the security operations centre rather than work a queue in it. Ten weeks on operating model, detection strategy, staffing, tooling and metrics for a SOC that improves instead of only surviving.
You will design a SOC end to end for a given organization, then defend the trade-offs: what you automate, what you outsource, and what you deliberately choose not to cover.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Choose an operating model and coverage window that matches real risk and budget
- Decide whether to tier your team, and justify the decision either way
- Build a detection strategy around threat relevance rather than rule count
- Specify SIEM and EDR requirements and evaluate managed service alternatives
- Define triage, escalation and handover processes analysts will follow under pressure
- Set SOC metrics that reflect detection quality, not just alert throughput
- Design analyst career paths and rotations that reduce attrition
- Present a SOC funding case with staffing and licensing costs separated
Course outline
6 modules
- In house, hybrid and managed models with their real cost profiles
- Coverage windows: business hours, follow the sun and on call
- Defining SOC scope against IT operations, incident response and engineering
- Setting a charter and service definition stakeholders sign
- Deciding what you will deliberately not monitor
What you need before you start
- Experience in security operations, incident response or detection engineering
- Familiarity with SIEM and EDR concepts at a working level
- A leadership role now or a move into one within the year
- Around five hours a week outside class for the SOC design project
Who this course is for
- SOC managers and team leads running an existing operation
- Security managers about to stand up an in house SOC
- Senior analysts and detection engineers moving into leadership
- Managed service leads responsible for client detection quality
Where this leads
Prepares you for
CISM
Awarded by ISACA
Operating model, programme and incident management content supports the ISACA CISM syllabus. ISACA runs the examination and confers the certification following its own experience verification. This course is instruction and design practice, nothing more.
Questions about this course
More in security leadership and governance
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



