Back to jobs

Remote | SOC Investigation Analyst — $50–$70/hour

24-MAGAnywhereAdded 1w ago
SOC Analyst
Contractor
Remote
Apply on company siteCraft my tailored resume free

Free to start · No card

Job description

We are sharing a specialised part-time consulting opportunity for experienced SOC investigation professionals with strong backgrounds in alert triage, incident investigation, Splunk-based log analysis, evidence correlation, timeline reconstruction, and security investigation quality review. This role supports current and upcoming remote consulting opportunities focused on SOC investigation evaluation, alert validation, security evidence review, investigation workflow assessment, and high-quality technical documentation. Selected professionals may apply hands-on experience across SIEM, endpoint, cloud, and identity environments to review, validate, and construct accurate security investigations based on real-world scenarios. Key Responsibilities Professionals in this role may contribute to: SOC Alert Review & Investigation Evaluation Review, monitor, and evaluate SOC alerts and investigation outputs based on predefined scenarios and criteriaDistinguish true positives from false positives by validating alert context, investigative evidence, and supporting signalsAssess whether security investigation conclusions are correct, incomplete, unsupported, or inaccurateApply consistent investigative judgment while recognizing that more than one valid investigation path may exist for the same alert Splunk-Based Investigation & Log Analysis Use Splunk to pivot across logs, entities, timelines, alerts, and investigation artifactsRead, understand, and reason about SPL queries in the context of security investigationsPerform log analysis, entity pivoting, timeline reconstruction, and evidence correlation when requiredIdentify relevant signals across SIEM data and explain how evidence supports an investigation conclusion Security Evidence & Ground-Truth Review Evaluate the correctness, completeness, and quality of SOC investigations produced through structured workflowsMake clear quality determinations while also producing detailed ground-truth investigations when requiredReview investigation steps, assumptions, supporting evidence, and final conclusions for accuracy and consistencyHelp ensure investigation outputs reflect practical SOC judgment and evidence-based security reasoning Documentation & Quality Standards Maintain clear and accurate documentation of investigative steps, assumptions, evidence, and conclusionsProvide structured feedback on investigation quality, alert handling, and technical reasoningCollaborate with project leads and other security specialists to uphold high-quality investigation standardsSupport or mentor other analysts where applicable, particularly in long-term or lead reviewer roles Ideal Profile Strong candidates may have: 3+ years of hands-on experience as a SOC analyst in a production SOC environmentTier 2 or higher SOC analyst experience is strongly preferredStrong understanding of alert triage, incident investigation workflows, security evidence, and time-sensitive decision-makingMandatory hands-on experience with Splunk, including conducting investigations, reading SPL queries, and pivoting between logs, entities, and timelinesProven ability to evaluate SOC investigations and determine whether conclusions are valid, incomplete, or incorrectStrong investigative judgment and comfort making clear, evidence-based evaluationsFluent English communication skills, with strong written documentation abilityAbility to work independently in a remote, project-based environment Educational Background A degree in Cybersecurity, Computer Science, Information Security, Information Systems, Digital Forensics, or a related technical field is helpfulEquivalent professional experience in SOC analysis, incident response, threat detection, or security investigation work is also highly relevant Nice to Have Experience with Endpoint Detection & Response tools such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or comparable platformsExperience analyzing cloud security logs and signals, including AWS CloudTrail, GuardDuty, Azure Activity Log, Microsoft Defender for Cloud, or GCP Cloud Audit LogsFamiliarity with Identity & Access Management platforms such as Okta Identity Cloud or Microsoft Entra IDExperience with email security tools such as Proofpoint, Mimecast, or similar platformsSOC leadership, mentoring, or lead analyst experienceBasic scripting experience with Python or comparable languagesSecurity certifications such as GCIA, GCIH, GCED, Splunk certifications, Security+, CCNA, or cloud security certifications Why This Opportunity Flexible, remote consulting work aligned with your SOC investigation and security analysis expertiseOpportunity to contribute to high-impact security investigation evaluation and ground-truth case reviewSuitable for experienced SOC professionals who enjoy evidence-based investigation, structured review, and technical decision-makingProject-based work that can align with part-time availability and remote schedules Contract Details Independent contractor engagementFully remote and flexible schedulingPart-time, project-based availabilityExpected commitment may vary by project, with many opportunities ranging from approximately 15–30 hours per weekCompetitive hourly compensation in the range of $50–$70/hour, depending on project scope, experience, and fitPayments are made weekly via Stripe or Wise based on services renderedProjects may be extended, shortened, adjusted, or concluded based on project needs and performanceEligible locations include Albania, Austria, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, India, Ireland, Italy, Kosovo, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, and the United KingdomCandidates requiring H1-B or STEM OPT sponsorship support are not eligible at this timeWork must not involve sharing confidential or proprietary information from any employer, client, or institution About the Platform This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams. By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.