Role Overview
Apply real-world SOC analyst judgment to review, validate, and produce high-quality security investigations across SIEM, endpoint, cloud, and identity environments. You will evaluate automated and human-produced investigation outputs, perform end-to-end investigations when needed, and help shape AI-driven SOC automation by providing accurate ground-truth cases.
Key Responsibilities- Review, monitor, and evaluate SOC alerts and investigation outputs against predefined scenarios and criteria.
- Validate investigative evidence and alert context to distinguish true positives from false positives.
- Perform end-to-end security investigations when required, including log analysis, entity pivoting, timeline reconstruction, and evidence correlation.
- Assess correctness, completeness, and quality of investigations produced by automated or human workflows.
- Apply consistent investigative judgment while recognizing multiple valid investigation paths may exist for the same alert.
- Make clear binary determinations, for example ACCEPT or PASS, and produce detailed ground-truth investigations when required.
- Use Splunk extensively to pivot across logs, entities, and timelines, including reading and reasoning about SPL queries.
- Maintain clear, accurate documentation of investigative steps, assumptions, evidence, and conclusions.
- Collaborate with program leads and other expert annotators to uphold investigation and annotation standards.
- Mentor or support other analysts in long-term or lead annotator roles where applicable.
- Minimum 3 years of hands-on experience as a SOC analyst in a production SOC environment, Tier 2 or above strongly preferred.
- Strong understanding of alert triage, incident investigation workflows, and evidence-based decision-making under time constraints.
- Mandatory hands-on experience with Splunk, including conducting investigations with Splunk, reading and reasoning about SPL queries, and pivoting between logs, entities, and timelines.
- Proven ability to evaluate SOC investigations and determine whether conclusions are valid, incomplete, or incorrect.
- Strong investigative judgment and comfort making decisive evaluations.
- Fluent English, written and spoken, with strong documentation and communication skills.
- Experience with Endpoint Detection and Response tools such as CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOne.
- Experience analyzing cloud security logs and signals, for example AWS CloudTrail and GuardDuty, Azure Activity Log and Defender for Cloud, or GCP Cloud Audit Logs.
- Familiarity with Identity and Access Management platforms such as Okta Identity Cloud or Microsoft Entra ID (Azure AD).
- Experience with email security tools like Proofpoint or Mimecast.
- SOC leadership or mentoring experience.
- Basic scripting experience, for example Python or similar.
- Security certifications such as GCIA, GCIH, GCED, Splunk certifications, Security+, CCNA, or cloud security certifications are a plus.
- Work on cutting-edge SOC automation and AI-driven investigation systems used by high-growth technology and enterprise partners.
- Apply and influence how real-world SOC expertise is encoded into future security investigations and response processes.
- Own high-impact investigative evaluations and ground-truth security cases.
- Collaborate with experienced SOC practitioners, security engineers, and AI teams.
- Join a global network of vetted security professionals.
- Location: Remote.
- Employment type: Hourly engagement.
70 - 95 hourly.
Eligibility- Fluent English, written and spoken, is required.