October 15th, 2026 @5:30 PM – Aaron Long – So You Want to Build a SOC: The Business of Security Operations

Register:
This is a Hybrid meeting. A dinner meal will be served (Meal menu &pizza). REGISTER HERE for IN PERSON & ONLINE via MS Teams. Location: Microsoft Reston 11955 Freedom Dr., Reston, VA 20190. Location: Floor 2, the Garage Conference Room. Free parking directly across from location. Metro Station Accessible. In-person registration closes on Tuesday, October 13, 2026. Registrations received on October 14 and October 15, 2026 will be restricted to online participation via Microsoft Teams. No in-person attendance options will be available after October 13, 2026.

Abstract:
Every organization eventually faces the same decision: build a security operations capability in-house or buy one. Getting that right requires a deep, introspective analysis of your individual needs, and there is no one-size-fits-all answer.

This talk covers the build vs. buy calculus in depth. We start with an overview of operational needs and how to establish your key buildout criteria. From there we work through the different staffing models, along with guidelines for calculating how many FTEs each one actually requires. That headcount is only half the equation, so we then turn to a framework for evaluating technologies, vendors, and services objectively rather than by data sheet. With the model and the stack settled, we cover recruiting and training and provide strategies for how you find the right people and grow them once you have them. Finally, we close on metrics, and how to tell whether any of it is working in the first place.

Targeted at SOC managers and directors, and anyone who wants a deep dive into the business of security operations.

Speaker Bios:
Aaron Long is Field CISO at Sekoia.io and the CEO and founder of Triadelphia Information Security. He is a technical executive with more than 15 years in technology and cybersecurity, including over a decade leading global teams, and specializes in security operations, engineering, and incident response.

Aaron’s background spans managed detection and response, detection engineering, threat intelligence, and security product development, built across security leadership roles at Elastic, Tenstorrent, OneAxiom, ZeroFox, and Rapid7. Along the way he has stood up 24/7 SOC and MDR operations, led incident response engagements, and grown a security services who were scaling for hyper growth

At Sekoia, he works with customers, partners, and internal teams across North America, helping security leaders address a shifting threat landscape and maturing their security operations capabilities.