Skip to content

Building a SOC Team: Roles, Tools, and Operating Model

A security operations center (SOC) blends a tiered analyst roster with a SIEM/SOAR/EDR/TIP tooling stack to monitor, triage, and respond to incidents 24x7. Cover the org-design, the metric set (MTTD/MTTR), on-call patterns, and the hire-vs-MSSP breakeven math.

Comparison card: Building a SOC Team: Roles, Tools, and Operating Model

A security operations center (SOC) is an organizational unit that continuously monitors, detects, investigates, and responds to cybersecurity threats across an enterprise's entire technology surface. See also: container security.

Most teams that fail at building a SOC fail on org design, not tool selection. They hire two analysts, buy a SIEM, and discover six months in that overnight alerts go unanswered, MTTR drifts past 48 hours, and the budget cannot stretch to the headcount the rotation arithmetic actually requires. The operator-grade question is how to size the analyst tier ladder, the on-call pattern, and the five-tool stack against MTTD and MTTR targets that the business will defend in a board review.

This article maps the build decisions that determine whether a SOC clears its detection and response targets in year one or burns through analyst tenure trying to. The arithmetic is unforgiving: a 24/7 follow-the-sun rotation, a Tier-3 threat hunting cycle, and a tuned correlation ruleset all carry concrete FTE costs that the hire-vs-MSSP framework has to price out before the first hire signs.

SOC Analyst Tier Model: Roles and Responsibilities

Card showing Key Roles in a SOC Team: Tier 1 analyst, Tier 3 threat hunter and SOC manager

A SOC structures its analyst workforce as a three-tier ladder with distinct skill thresholds, escalation rights, and ownership of the operating metrics. The tier model is not a job-title hierarchy; it is a function map that allocates alert triage, incident response, and proactive threat detection across analysts whose experience and tooling access differ by an order of magnitude. The SOC Manager role sits outside this ladder as operational overhead, not as a fourth tier. The data-layer scope a SOC monitors is shaped by the pseudonymisation choices covered in the difference between encryption and tokenization, since tokenized fields generate different alert patterns than encrypted ones. The NIST SP 800-53 Rev 5 IR (Incident Response) and SI (System and Information Integrity) control families codify the function-to-tier mapping that most enterprise SOCs use as their reference baseline.

Tier-1: Alert monitor and triage analyst
Owns alert triage from the SIEM queue, performs initial classification against playbook criteria, and escalates verified incidents to Tier-2. Typically 1-2 years of SecOps experience. The Tier-1 cohort is the volume layer of the SOC; staffing it correctly is the precondition for 24/7 coverage.
Tier-2: Incident responder
Owns root-cause analysis, containment actions, and the MTTR clock once a Tier-1 escalation arrives. Investigates EDR artifacts, pivots across log sources, and authors the incident report. Typical experience floor is 3-5 years across SecOps and systems administration.
Tier-3: Threat hunter and senior analyst
Drives proactive threat detection through hypothesis-led hunts mapped to MITRE ATT&CK techniques, authors and tunes SIEM correlation rules, and serves as escalation backstop for novel incidents. Typically 6+ years and the rarest hire in the SOC market.
SOC Manager (overhead role, not a tier)
Owns shift scheduling, vendor relationships, metric reporting to leadership, and the analyst career ladder. The manager is a coordination role and does not carry an analyst caseload.

The escalation path runs Tier-1 to Tier-2 on incident confirmation, Tier-2 to Tier-3 on novelty or sustained adversary presence, and Tier-3 to the SOC Manager only for cross-functional coordination (legal, executive comms, breach disclosure). Shift handoffs happen on a structured handover at the start of every shift; the outgoing Tier-1 walks the incoming Tier-1 through open tickets, suppressed alerts, and any escalation in flight. The handover ritual is a control, not a courtesy. Without it, MTTD degrades on every shift boundary because context fails to transfer.

On-Call Rotation Patterns for 24/7 SOC Coverage

A SOC running 24/7 coverage is bound by rotation arithmetic before it is bound by tooling budget. The on-call rotation pattern dictates the minimum Tier-1 headcount, the annual FTE cost, and the recovery time the team can sustain through alert triage spikes and live incident response. Three patterns dominate enterprise SecOps team design, each with a different break-even point and a different MTTR profile.

Rotation patternMinimum Tier-1 FTEsAnnual loaded costMTTR impactBest fit
Follow-the-sun (3 regional pods)9 analysts (3 per pod)$900k-$1.2MSub-1-hour Tier-1 acknowledge any timezoneGlobal enterprise, 5,000+ employees
DuPont 12-hour rotation (4 teams, 8-week cycle)6 analysts (4 working, 2 reserve)$600k-$850kSub-2-hour Tier-1 acknowledge, shift-edge gapsMid-size SOC, 500-5,000 employees
4x10 plus on-call overlay4 analysts plus pager rotation$400k-$550k4-8 hour MTTR overnight, business-hours optimalSub-10-analyst SecOps team, sub-500 employees

The headcount floor matters more than the cost ceiling. A 24/7 follow-the-sun SOC requires a minimum of six Tier-1 FTEs before any Tier-2, Tier-3, or manager overhead is layered on; the headcount math accounts for vacation, sick leave, training, and the on-call rotation reserve that keeps a single resignation from collapsing weekend coverage. Teams that try to run 24/7 with four analysts always hit MTTD degradation by month four when accumulated leave days expose the gap.

MTTD and MTTR: The Operating Metrics That Drive SOC Decisions

Splunk MTTD and MTTR
Credit: Splunk

A SOC is graded by two operating metrics, and every staffing or tooling decision flows from them. Mean time to detect (MTTD) measures the elapsed time from initial adversary action to confirmed alert in the SecOps team's queue. Mean time to respond (MTTR) measures elapsed time from confirmed alert to contained or remediated incident. Industry-median MTTD for externally-detected breaches sits near 194 days in IBM X-Force and Ponemon reporting; SOC-run environments with a tuned SIEM and active threat hunting consistently target sub-24-hour MTTD for high-severity alerts and sub-1-hour MTTD for critical-priority detections. MTTR for critical incidents should hold under four hours of containment.

These two metrics cascade through the SOC operating plan. MTTR targets drive Tier-2 headcount because containment time is directly bounded by responder availability. MTTD targets drive SIEM tuning investment, detection rule coverage, and the Tier-3 threat hunting cadence because earlier detection requires better correlation logic, not more analysts. The NIST Cybersecurity Framework 2.0 DETECT and RESPOND function areas map directly onto these two metrics, and the CISA Cross-Sector Cybersecurity Performance Goals publish baseline detection and response targets that a SecOps team should benchmark against.

Four input variables determine MTTD in any SOC, and tuning each one yields a measurable improvement:

  1. Log ingestion latency. The elapsed time from event generation at the source to availability in the SIEM correlation engine. Above 15 minutes, sub-15-minute MTTD is architecturally impossible.
  2. Detection rule coverage. The percentage of MITRE ATT&CK techniques relevant to the environment that have an active correlation rule. Coverage gaps directly extend MTTD on any technique not modeled.
  3. Alert queue depth. The volume of pending Tier-1 alert triage items. Queue depth above 50 per analyst per shift produces context loss and missed correlations.
  4. Analyst shift gap. The gap between outgoing and incoming shift coverage at the handover boundary. Gaps as short as 15 minutes degrade MTTD on alerts that fire at the seam.

The SOC Tooling Stack: Five Integrated Layers

A SOC runs on five integrated tooling layers, and the integration matters more than the individual product choices. The SIEM is the event backbone; the SOAR layer reduces analyst load; EDR supplies the host-side evidence base; the threat intelligence platform supplies external adversary context; and ticketing integration binds the workflow to change management. Tool selection is downstream of this layer map, and the layer dependencies (SOAR requires SIEM as its event source; the threat intelligence platform enriches SIEM correlation rules) are non-negotiable. The NIST SP 800-92 Guide to Computer Security Log Management defines the log-management requirements that govern the SIEM ingestion layer and the retention policies a SOC has to enforce.

SIEM (security information and event management)
The log aggregation and correlation engine that ingests telemetry from every in-scope source and runs detection rules against it. Vendor selection at this layer drives total tooling cost; see Splunk vs QRadar pricing for the SIEM-tier vendor comparison.
security orchestration automation and response (security orchestration automation and response)
The playbook automation and case management layer that handles repeat alert triage actions without analyst intervention. Well-tuned playbook automation routinely cuts Tier-1 manual workload by 40-60% and is what makes a six-analyst SOC viable at enterprise alert volumes.
EDR (endpoint detection and response)
The endpoint telemetry and host-based detection layer that supplies the primary investigation artifacts for Tier-2 incident response. For vendor selection on this layer see Best CrowdStrike Alternatives For Endpoint Detection.
Threat intelligence platform (TIP)
The external adversary context layer that feeds indicator-of-compromise data and adversary tradecraft into SIEM correlation rules and Tier-3 hunting hypotheses. MITRE ATT&CK is the canonical mapping framework that the TIP layer normalizes incoming threat intelligence against.
Ticketing and ITSM integration
The incident lifecycle layer that ties SecOps team workflows to organizational change management, vendor escalation, and breach reporting obligations. Without this binding, incidents close in the SIEM but never close in the systems of record that auditors inspect.

Cloud telemetry feeds into this stack from the posture management layer; the upstream context of cloud-native event sources is covered in Best CSPM Tools For AWS. The application layer telemetry that Tier-1 analysts rely on for triage workflow is shaped by the logging requirements in the OWASP Application Security Verification Standard Section 7 (Error Handling and Logging), which most enterprise application teams cite as their log-instrumentation baseline.

Hire In-House vs MSSP: The Build Decision Framework

A SOC build decision is fundamentally a break-even calculation between in-house headcount and a managed security service provider (MSSP) contract. An in-house 24/7 SOC with seven to ten FTEs at $85k-$130k loaded cost runs $600k to $1.3M annually on labor alone, before SIEM licensing, EDR seats, threat intelligence platform subscriptions, and training budget. A typical MSSP contract ranges from $50k to $500k annually depending on log volume, SLA tier, and scope of incident response coverage. The decision turns on three variables: the all-in in-house cost, the MSSP price for an equivalent SLA, and the MTTD/MTTR differential between an in-house SecOps team on site and an MSSP shared-analyst pool covering many clients in parallel.

Decision factorBuild in-house SOCEngage an MSSP
Headcount profileExisting security engineering team, hiring pipeline openNo dedicated security hiring track, sub-200 employee org
Annual security budgetAbove $700k for tooling and staff combinedBelow $300k for full coverage scope
Data residency postureRegulated industry, log data cannot leave environmentNo residency constraint, vendor SOC-2 acceptable
M&A and change velocityFrequent acquisitions, novel scope every quarterStable footprint, predictable telemetry sources
MTTD and MTTR controlDirect ownership, in-house tuning of SIEM and playbooksVendor SLA, shared pool MTTR, contractual escalation path

A hybrid model often beats either pure option. The MSSP covers Tier-1 alert review overnight and on weekends, while an in-house Tier-2 and Tier-3 team handles daytime incident response, threat hunting, and SIEM tuning. The hybrid splits the cost curve roughly $200k-$400k MSSP contract plus three to four in-house FTEs and produces tighter mean time to respond on critical incidents than a pure MSSP can deliver, since the in-house responders have direct system access and contextual familiarity with the environment.

Further reading

Frequently Asked Questions

How many analysts does a 24/7 in-house SOC require at minimum?

A 24/7 in-house SOC requires a minimum of six Tier-1 analysts to sustain continuous coverage across three 8-hour shifts with one backup per shift rotation. That six-analyst floor assumes a DuPont or similar 4-team rotation model, accounts for vacation and sick leave, and does not include Tier-2 incident responders, Tier-3 threat hunters, or the SOC Manager role. Teams below six Tier-1 FTEs will experience coverage gaps on overnight and weekend shifts, which directly degrades MTTD for alerts that land outside primary business hours.

What is a realistic MTTD target for a well-tuned SOC?

A well-tuned SOC should target sub-24-hour MTTD for high-severity alerts, with a sub-1-hour MTTD goal for critical-priority detections triggered by SIEM correlation rules. Industry-wide median MTTD for breaches detected externally runs above 100 days; SOC-run environments with active threat hunting and tuned detection rules consistently outperform that baseline by an order of magnitude. The practical floor is set by log ingestion latency from endpoint and network sources. If raw telemetry takes 15-30 minutes to reach the SIEM, sub-15-minute mean time to detect is not achievable without architectural changes to the pipeline.

When does an MSSP become more cost-effective than an in-house SOC?

An MSSP becomes cost-effective when an organization's annual security operations budget is below approximately $400k-$500k, which is the rough breakeven point where a full-staffed in-house 24/7 SOC (headcount plus tooling) crosses MSSP contract pricing for equivalent SLA tiers. Below that budget, an managed security service provider with a dedicated account team typically delivers broader 24/7 coverage than an in-house team of two or three analysts. Above that threshold, in-house control of tooling, data residency, and investigation depth typically justifies the cost premium, particularly for regulated industries where log data cannot leave the organization's environment.

Share this guide

Daniel Brandt

Daniel Brandt covers threats, malware, and vulnerability disclosure for techshooked, from active exploit campaigns to the patch cycles that follow. His standard is operational: name the affected versions, separate a proof of concept from in-the-wild exploitation, and tell readers which fix to apply first.