SOC Manager
About the role
UDT is a national technology solutions provider that modernizes, connects, secures, and manages technology environments for commercial enterprises, state and local governments, and educational institutions. The trusted advisor to many of the nation's top K-12 school districts and corporate leaders across a spectrum of industries including hospitality, health care, financial services and more – UDT offers one of the most robust suites of customizable, end-to-end technology solutions in the industry. With a portfolio that spans IT managed services, endpoint lifecycle solutions, cybersecurity, networking, computing, cloud, connectivity, and voice services, UDT helps clients align technology with their most important business priorities – empowering insight-driven IT strategies that accelerate innovation, streamline costs, and reduce risk. Founded in 1995 and headquartered in Miramar, Florida, UDT has more than 400 professionals nationwide and growing operational facilities in Florida, Tennessee, Texas, and South Carolina.
This position is hybrid, located in Miramar, FL.
Responsibilities
- SOC Operations Management: Lead and manage the daily operations of the 24x7x365 SOC, ensuring timely detection, triage, investigation, and response to security events across all delivery paths.
- Supervise and develop the SOC team — Supervisors, Analysts (Levels 1, 2, and 3), and the dispatcher pool — providing direction, coaching, and accountability.
- Own the escalation matrix and serve as the standing intermediate tier within the UDT escalation chain (SDM to SOC Manager to senior leadership), ensuring escalations follow a defined path.
- Maintain and refine incident-response playbooks, standard operating procedures (SOPs), runbooks, and escalation protocols so that response procedures are documented, repeatable, and independent of any individual.
- Ensure the SOC operates in accordance with UDT security policies, contractual scope, and client SLAs.
- Coverage, Shift Discipline, and On-Call: Establish and own a defined, rotating, documented on-call tier so that after-hours and weekend escalation follows a published rotation.
- Establish a formal shift-handoff process at each shift overlap — a structured written and verbal pass of open incidents, watch items, pending customer callbacks, and in-flight investigations, logged in ConnectWise — to maintain continuity across the shift overlaps (Shifts 1, 2, and 3) and at the UDT-partner boundary.
- Define and enforce after-hours coverage standards, ensuring overnight and dispatcher coverage follows documented response procedures rather than automated notification alone.
- Incident Detection and Response: Oversee all phases of incident management — detection, triage, investigation, containment, and post-incident review — across UDT's detection stack: Huntress (Managed EDR/MDR/ITDR — Ransomware Canaries, Persistent Footholds), Google Chronicle (SIEM, SOAR, and threat-intelligence plane), CrowdStrike (alternate endpoint MDR engine), Microsoft Defender (managed endpoint telemetry), Datto SIRIS (backup and disaster recovery), and KnowBe4 (security awareness).
- Act as the senior point of escalation for high-severity incidents, coordinating the SOC, NOC, PS Cyber, the customer, and, where engaged, legal and executive leadership.
- Operate within UDT's defined control boundaries: Infrastructure containment follows a SOC-to-NOC handoff — the SOC raises the ticket and the NOC executes — managed to avoid delay at the handoff. Major-incident response command resides with PS Cyber. The SOC detects, confirms true-positive status and indicators of compromise, and provides support.
- Support the adoption of pre-authorized emergency incident-response authorization so that containment of a confirmed breach is not delayed pending contractual approval.
- Ensure breach-notification requirements — for example, contractual 24-hour written notification for regulated accounts — are tracked and met, escalating legal determinations to counsel.
- Partner and Vendor Operational Governance: Assume operational ownership of UDT's co-delivery and managed-SIEM partner relationships, including participation in partner quarterly business reviews with a UDT-maintained coverage, escalation, miss-rate, and SLA scorecard, and governance of the UDT-partner handoff.
- Manage the operational fit of SOC subcontractors and partners with respect to coverage, shift, and escalation. Cost decisions route to Finance.
- Evaluate detection and response tooling for operational effectiveness and recommend stack changes to SecOps.
- Detection Coverage and Tuning Quality: Build and maintain a single, UDT-owned, validated MITRE ATT&CK coverage baseline spanning the Huntress and Chronicle paths, including customer-tenant Sentinel, mapped to ingested log sources, with gaps ranked and tracked.
- Maintain a detection-tuning and false-positive backlog feeding the SIEM/SOAR platform and governing tool-direct alert volume. Detection quality is addressed through tuning; alert suppression is not an acceptable substitute.
- Partner with the SIEM/SOAR platform's detection-engineering function — parser and UDM mapping, use-case authoring, and detection scoring — so that UDT's coverage view consumes those outputs rather than duplicating them.
- SLAs, Metrics, and Reporting: Maintain outcome-based SLAs and SLOs. MTTA, MTTD, and MTTR are measured against the defined, severity-based classification-completion clock, including the 60-day Service Alignment Phase and documented pause states.
- Own the monthly Customer Service Review (CSR) and quarterly business review (QBR) cadence: coverage assessment, MITRE use-case coverage, alert breakdown, and gap reporting via UDT HUB, ARMED, and Smart Analytics.
- Report metrics that accurately reflect risk reduction and response performance, including known gaps.
- Team Development and Mentorship: Provide leadership, mentorship, and career development for the SOC team; conduct performance reviews and identify training and certification paths.
- Partner with Human Resources on role standards and professional development plans to build out the Level 1 to Level 2 to Level 3 analyst progression and senior-bench depth. Indicative certification path: Security+, CrowdStrike Falcon, BTL1, MITRE ATT&CK, and CySA+, advancing toward CISSP, CISM, or GCIH for senior roles.
- Compliance and Stakeholder Engagement: Ensure SOC activities align with applicable frameworks and regulations across the client base, including NIST, ISO 27001, CIS, MITRE ATT&CK, HIPAA, PCI-DSS, and GLBA for regulated accounts, and others as contracted.
- Serve as a primary SOC point of contact for senior leadership and clients regarding SOC performance, the threat landscape, and incidents.
- Other: Enter time and all work — activities, service tickets, and project tickets — into the ConnectWise Manage PSA as it occurs.
- This position is based at UDT's headquarters in Miramar, FL and follows a hybrid schedule; occasional travel to customer sites may be required.
- Other duties related to the scope of the department and the business may be assigned.
Education and experience
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field; master's degree preferred.
- Seven or more years in security operations, including at least three years in a SOC leadership or management role.
- Demonstrated experience managing SOC teams and directing high-severity incidents in a fast-paced, multi-client MSSP or MSP environment.
- Experience operating a co-delivery or partner-fronted MDR model (managed SIEM and EDR delivered through partners) is strongly preferred.
Technical skills
- Working fluency with a modern MDR stack: EDR and MDR platforms (Huntress, CrowdStrike, Microsoft Defender); SIEM and SOAR platforms (Google Chronicle, or comparable platforms such as Microsoft Sentinel or Splunk); and ticketing and PSA-driven escalation.
- Familiarity with ConnectWise Manage is a strong plus.
- Strong command of incident management, threat intelligence, forensic fundamentals, and vulnerability-management processes.
- Working knowledge of MITRE ATT&CK as a coverage-design and validation discipline.
- Understanding of cybersecurity frameworks and regulatory regimes, including NIST, ISO 27001, HIPAA, PCI-DSS, and GLBA.
Certifications
- Manager-level security certification required or strongly preferred: CISSP or CISM.
- Governance, risk, and audit credentials, one or more strongly preferred: CISA or CRISC.
- Hands-on detection and incident-response credentials, one or more a plus: GCIH, GCIA, GIAC, or CEH.
- Baseline expected: CompTIA Security+ or CySA+.
- Operational excellence, a plus: ITIL Foundation and a process-improvement credential such as Lean Six Sigma (Green Belt or above).
Required knowledge, skills, and abilities
- Cross-functional leadership, with the ability to lead and achieve results with a strong customer orientation.
- Strategic planning across a 6- to 12-month horizon, with the discipline to operationalize the plan.
- Excellent written and verbal communication, including the ability to translate complex technical matters to technical, non-technical, executive, and client audiences.
- Direct technical engagement — comfortable working within the toolset (Huntress, Google Chronicle, CrowdStrike, ConnectWise) producing reports, extracting metrics, and authoring playbooks personally. This is a working management position rather than a purely supervisory one.
- The ability to operate independently with a record of taking ownership of an objective and executing it with limited day-to-day direction.
- An improvement orientation with experience assessing an established operation objectively, applying industry best practices, and strengthening operational discipline.
- Customer-facing composure with skill in conflict resolution and in conducting client conversations with professionalism and credibility.
- Strong leadership and team-building skills, with the ability to motivate and develop a diverse, multi-tier SOC team.
- Sound judgment under pressure during high-severity incidents.
- Strong organizational and prioritization skills in a 24x7, multi-client environment.