About the roleWe are sharing a specialised part-time consulting opportunity for experienced SOC analysts with strong expertise in alert triage, incident investigation, Splunk-based analysis, and evidence-driven security decision-making.This role supports current and upcoming remote consulting opportunities focused on structured security workflows, investigation review, technical evaluation, and high-quality project execution. Selected professionals will apply their SOC expertise to review and validate investigations, distinguish true positives from false positives, perform end-to-end security analysis when needed, follow technical instructions with precision, and contribute to high-quality technical deliverables. This opportunity is especially well-suited to professionals with strong investigative judgment, hands-on Splunk experience, and comfort working across structured security analysis workflows.Key ResponsibilitiesSOC Alert Review & Investigation EvaluationReview, monitor, and evaluate SOC alerts and investigation outputs based on predefined scenarios and criteriaDistinguish true positives from false positives by validating investigative evidence and alert contextAssess the correctness, completeness, and quality of SOC investigations produced through structured workflowsSecurity Investigation & AnalysisPerform end-to-end security investigations when required, including log analysis, entity pivoting, timeline reconstruction, and evidence correlationApply consistent investigative judgment while recognizing that multiple valid investigation paths may exist for the same alertMake clear determinations while also producing detailed ground-truth investigations when requiredSplunk-Based Investigation WorkflowsUse Splunk extensively to pivot across logs, entities, and timelinesRead, understand, and reason about SPL queriesSupport high-quality investigation workflows through structured evidence analysis and documentationDocumentation & CollaborationMaintain clear and accurate documentation of investigative steps, assumptions, evidence, and conclusionsCollaborate with program leads and other expert analysts to uphold high-quality investigation and review standardsMentor or support other analysts where applicable, particularly in long-term or lead analyst rolesIdeal ProfileStrong candidates may have:3+ years of hands-on experience as a SOC analyst in a production SOC environmentStrong understanding of alert triage, incident investigation workflows, and evidence-based decision-making under time constraintsMandatory hands-on experience with Splunk, including conducting investigations, reading and reasoning about SPL queries, and pivoting across logs, entities, and timelinesProven ability to evaluate SOC investigations and determine whether conclusions are valid, incomplete, or incorrectStrong investigative judgment and comfort making decisive evaluationsFluent English, written and spoken, with strong documentation and communication skillsPreferred QualificationsTier 2 or above SOC experienceExperience with Endpoint Detection and Response tools such as CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOneExperience analyzing cloud security logs and signals across AWS, Azure, or GCPFamiliarity with identity and access management platforms such as Okta Identity Cloud or Microsoft Entra IDExperience with email security tools such as Proofpoint or MimecastSOC leadership or mentoring experienceBasic scripting experience in Python or similar languagesSecurity certifications such as GCIA, GCIH, GCED, Splunk certifications, Security+, CCNA, or cloud security certificationsWhy This OpportunityApply real-world SOC expertise to high-impact security workContribute to investigation review, threat analysis, and technical evaluation workflowsTake ownership of meaningful investigative evaluations and security casesCollaborate with experienced security professionals across structured remote workflowsContract DetailsIndependent contractor roleFully remote with flexible schedulingTalent network opportunityWeekly payments via Stripe or WiseProjects may be extended, shortened, or concluded early depending on project needs and performanceWork will not involve access to confidential or proprietary information from any employer, client, or institutionPlease note: We are unable to support H1-B or STEM OPT candidates at this timeAbout the PlatformThis opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy:
https://www.24-mag.com/privacy-policy