Skip to content
SaidGig
Sign up.

Give me your email, I promise I won't do anything weird with it.

SOC Analyst for AI-Driven Investigation Systems

$70–$95/hr

RemoteContracttechnology
Apply Now

About this role

Role Overview

Validate, expand, and produce high-quality SOC investigations across SIEM, endpoint, cloud, and identity data to improve SOC automation and AI-driven investigation systems. This role applies real-world SOC analyst judgment to review alerts, confirm findings, and construct ground-truth investigations that guide automated and human workflows.

Key Responsibilities
  • Review, monitor, and evaluate SOC alerts and investigation outputs against predefined scenarios and criteria.
  • Distinguish true positives from false positives by validating investigative evidence and alert context.
  • Perform end-to-end investigations when required, including log analysis, entity pivoting, timeline reconstruction, and evidence correlation.
  • Assess the correctness, completeness, and quality of investigations produced by automated or human workflows.
  • Apply consistent investigative judgment while recognizing multiple valid investigation paths may exist for the same alert.
  • Make clear binary determinations, for example ACCEPT or PASS, and produce detailed ground-truth investigations when required.
  • Use Splunk extensively to pivot across logs, entities, and timelines, including reading and reasoning about SPL queries.
  • Maintain clear, accurate documentation of investigative steps, assumptions, evidence, and conclusions.
  • Collaborate with program leads and other expert annotators to uphold investigation and annotation quality standards.
  • Mentor or support other analysts where applicable, particularly in longer-term or lead annotator roles.
Qualifications

Required

  • At least 3 years of hands-on experience as a SOC analyst in a production SOC environment, Tier 2 or above strongly preferred.
  • Strong understanding of alert triage, incident investigation workflows, and evidence-based decision-making under time constraints.
  • Mandatory hands-on experience with Splunk, including conducting investigations with Splunk, reading and reasoning about SPL queries, and pivoting between logs, entities, and timelines.
  • Proven ability to evaluate SOC investigations and determine whether conclusions are valid, incomplete, or incorrect.
  • Strong investigative judgment and comfort making decisive evaluations.
  • Fluent English, written and spoken, with strong documentation and communication skills.

Nice to have

  • Experience with Endpoint Detection and Response tools such as CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOne.
  • Experience analyzing cloud security logs and signals, for example AWS CloudTrail and GuardDuty, Azure Activity Log and Defender for Cloud, or GCP Cloud Audit Logs.
  • Familiarity with identity and access management platforms such as Okta or Microsoft Entra ID.
  • Experience with email security tools like Proofpoint or Mimecast.
  • SOC leadership or mentoring experience.
  • Basic scripting experience, for example Python.
  • Security certifications such as GCIA, GCIH, GCED, Splunk certifications, Security Plus, CCNA, or cloud security certifications are optional.
Work Terms
  • Location: Remote.
  • Engagement type: hourly.
Compensation
  • Rate range: 70 to 95 per hour.
Eligibility
  • Fluent English, spoken and written, is required.
Why Join
  • Work on SOC automation and AI-driven investigation systems that shape future security operations.
  • Apply real-world SOC expertise to high-impact investigative evaluations and ground-truth cases.
  • Collaborate with experienced SOC practitioners, security engineers, and AI teams.
  • Join a global network of vetted security professionals and contribute to next-generation investigation tooling.

Related Jobs