I will write a clear incident response runbook or security sop
About this Gig
No documented process for handling security alerts? I'll fix that.
I'm a SOC L1 analyst working hands-on daily with Splunk, Microsoft Sentinel, and Cortex XSOAR. I write clear, structured runbooks and SOPs based on real SOC triage workflows the kind your team can actually follow under pressure, not vague theory.
Each runbook tells your team exactly what to check, in what order, and when to escalate. No missing steps, no unexplained jargon.
Common runbook types I write:
- Phishing email reported by a user
- Malware or beacon alert
- Brute force / failed login spike
- Suspicious outbound traffic or DNS activity
What you get:
- Clear, numbered triage steps for your chosen alert type
- Defined escalation criteria
- Clean, reusable document (PDF and/or Word)
- Optional flowchart diagram for visual teams (Premium)
Ideal for small security teams, IT teams without a formal SOC, or startups needing a real starting playbook instead of a blank page.
Not sure which alert types to prioritize? Message me before ordering happy to help you figure out what your team needs most.
Delivery style preference
Please inform the freelancer of any preferences or concerns regarding the use of AI tools in the completion and/or delivery of your order.
FAQ
Do I need to give you access to my systems or live environment?
No. I only need a description of your process or the alert type you want documented — no live access to your SIEM, network, or systems is required.
What alert types or scenarios can you write runbooks for?
Common ones include phishing reports, brute force login attempts, malware/beacon alerts, and suspicious outbound traffic. If your scenario isn't listed, message me first — I can likely still help.
I'm not in cybersecurity — can you still write general SOPs for my team?
Yes. While I specialize in security runbooks, the same structured, step-by-step approach works for any process-driven SOP. Message me with details and I'll confirm fit before you order.
What format will I receive the runbook in?
PDF by default. Standard and Premium packages also include an editable Word document so your team can update it over time.
Can you match our existing documentation style or template?
Yes — if you have a template or style guide, share it in the requirements and I'll format the runbook to match.
How many revisions are included?
1 revision on Basic, 2 on Standard, 3 on Premium. Additional revisions can be added as a Gig Extra if needed.

