Remote | SOC Investigation Analyst — $50–$70/hour

Other Jobs To Apply

No other job posts for this day.

We are sharing a specialised part-time consulting opportunity for experienced SOC investigation professionals with strong backgrounds in alert triage, incident investigation, Splunk-based log analysis, evidence correlation, timeline reconstruction, and security investigation quality review.

This role supports current and upcoming remote consulting opportunities focused on SOC investigation evaluation, alert validation, security evidence review, investigation workflow assessment, and high-quality technical documentation. Selected professionals may apply hands-on experience across SIEM, endpoint, cloud, and identity environments to review, validate, and construct accurate security investigations based on real-world scenarios.

Key Responsibilities

Professionals in this role may contribute to:

SOC Alert Review & Investigation Evaluation

  • Review, monitor, and evaluate SOC alerts and investigation outputs based on predefined scenarios and criteria
  • Distinguish true positives from false positives by validating alert context, investigative evidence, and supporting signals
  • Assess whether security investigation conclusions are correct, incomplete, unsupported, or inaccurate
  • Apply consistent investigative judgment while recognizing that more than one valid investigation path may exist for the same alert

Splunk-Based Investigation & Log Analysis

  • Use Splunk to pivot across logs, entities, timelines, alerts, and investigation artifacts
  • Read, understand, and reason about SPL queries in the context of security investigations
  • Perform log analysis, entity pivoting, timeline reconstruction, and evidence correlation when required
  • Identify relevant signals across SIEM data and explain how evidence supports an investigation conclusion

Security Evidence & Ground-Truth Review

  • Evaluate the correctness, completeness, and quality of SOC investigations produced through structured workflows
  • Make clear quality determinations while also producing detailed ground-truth investigations when required
  • Review investigation steps, assumptions, supporting evidence, and final conclusions for accuracy and consistency
  • Help ensure investigation outputs reflect practical SOC judgment and evidence-based security reasoning

Documentation & Quality Standards

  • Maintain clear and accurate documentation of investigative steps, assumptions, evidence, and conclusions
  • Provide structured feedback on investigation quality, alert handling, and technical reasoning
  • Collaborate with project leads and other security specialists to uphold high-quality investigation standards
  • Support or mentor other analysts where applicable, particularly in long-term or lead reviewer roles

Ideal Profile

Strong candidates may have:

  • 3+ years of hands-on experience as a SOC analyst in a production SOC environment
  • Tier 2 or higher SOC analyst experience is strongly preferred
  • Strong understanding of alert triage, incident investigation workflows, security evidence, and time-sensitive decision-making
  • Mandatory hands-on experience with Splunk, including conducting investigations, reading SPL queries, and pivoting between logs, entities, and timelines
  • Proven ability to evaluate SOC investigations and determine whether conclusions are valid, incomplete, or incorrect
  • Strong investigative judgment and comfort making clear, evidence-based evaluations
  • Fluent English communication skills, with strong written documentation ability
  • Ability to work independently in a remote, project-based environment

Educational Background

  • A degree in Cybersecurity, Computer Science, Information Security, Information Systems, Digital Forensics, or a related technical field is helpful
  • Equivalent professional experience in SOC analysis, incident response, threat detection, or security investigation work is also highly relevant

Nice to Have

  • Experience with Endpoint Detection & Response tools such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or comparable platforms
  • Experience analyzing cloud security logs and signals, including AWS CloudTrail, GuardDuty, Azure Activity Log, Microsoft Defender for Cloud, or GCP Cloud Audit Logs
  • Familiarity with Identity & Access Management platforms such as Okta Identity Cloud or Microsoft Entra ID
  • Experience with email security tools such as Proofpoint, Mimecast, or similar platforms
  • SOC leadership, mentoring, or lead analyst experience
  • Basic scripting experience with Python or comparable languages
  • Security certifications such as GCIA, GCIH, GCED, Splunk certifications, Security+, CCNA, or cloud security certifications

Why This Opportunity

  • Flexible, remote consulting work aligned with your SOC investigation and security analysis expertise
  • Opportunity to contribute to high-impact security investigation evaluation and ground-truth case review
  • Suitable for experienced SOC professionals who enjoy evidence-based investigation, structured review, and technical decision-making
  • Project-based work that can align with part-time availability and remote schedules

Contract Details

  • Independent contractor engagement
  • Fully remote and flexible scheduling
  • Part-time, project-based availability
  • Expected commitment may vary by project, with many opportunities ranging from approximately 15–30 hours per week
  • Competitive hourly compensation in the range of $50–$70/hour, depending on project scope, experience, and fit
  • Payments are made weekly via Stripe or Wise based on services rendered
  • Projects may be extended, shortened, adjusted, or concluded based on project needs and performance
  • Eligible locations include Albania, Austria, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, India, Ireland, Italy, Kosovo, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, and the United Kingdom
  • Candidates requiring H1-B or STEM OPT sponsorship support are not eligible at this time
  • Work must not involve sharing confidential or proprietary information from any employer, client, or institution

About the Platform

This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.

By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...

Other Jobs To Apply

Principal IT Technical Program Manager, Infrastructure

Account Manager

Specialist, Platform Product

Merchandise Planner

Business Development Director - Google Cloud Platform

REMOTE DISNEY VACATION SPECIALIST

Program Manager III- PGM Basecamp

Update Business Information for Ebay, Walmart, Amazon.

Delta Airlines Careers Remote( Customer service ) – Work From Home – Part Time

Data Engineer (Fully Remote)

(Remote) Amazon Data Entry Jobs from Home - No Experience - Apply Now

Remote Senior QA Automation Architect

Account Manager - X (Formerly Twitter)

Remote Retention Marketing Manager, DTC eCommerce

Data Entry Specialist (Entry Level, Remote) – Earn $70K–$80K/Year - Part Time

Remote Telemedicine Veterinarian

Sr. Manager, Merchandising

VP, GTM, UCANZ

Software Engineer (Frontend/Vue) - HENNGE Email DLP

Software Engineer (Data Analytics), AI & Data Platforms (AiDP)

Talent Coach

AI/ML Engineer for an AI-Driven E-Commerce Platform

Brand & Product Marketing Growth Leader

QA Tester - BaseCamp (Remote)

TESTING SPECIALIST/TESTER

Customer Engineer/Buffer - Flexforce - Customer Engineer

Sr. Software Engineer (AI Orchestration Zone, Backend Leaning)

Senior Manager, IT

Sr Developer - Kubernetes, GitOps / GitHub, service meshes

Principal – GitHub & Azure DevOps Platform Engineering

Senior Software Engineer,Billing

Post Task Github Project Contributor Remotely

Business Development Representative

Renewals Manager - West

Staff Product Manager, RevOps & Finance Systems

Intermediate Support Engineer (SHIFT)

Fullstack Engineer (TypeScript), AI Engineering: Duo Client SDK

Data Analyst for Ecom brand – Need deep research on Shopify analytics

E-Commerce, PLG Commercial (SaaS + Shopify)

UI/UX Designer (Shopify & Ecommerce) for a USA Client - Remote

Shopify & Etsy Customer Service Agent – Remote

Shopify Expert (Remote)

Remote Veterinary Care Representative - Pharmacy Order Management

[Remote] Rust backend architect Engineer – Twitter/X Style Infrastructure

Seasonal: Guest Advocate (Cashier), General Merchandise, Inbound (Stocking) (T3273)

Target Entry Level Remote Jobs ($21/Hr WFH Jobs) -

Measure Tech – Part-Time

Territory Associate Relations Manager (Houston & Dallas)

Online Experience Analyst - The Company Store

YouTube Operations Associate Manager- Contract