Jobs · Legal

SOC Investigation Specialist | Remote

CodeGeniusRecruit · United States · 1 wk ago
RemoteRemoteLegalContract

Type: Contract
Location: Remote
Commitment: 10-40 hrs/week

Responsibilities

  • Review, monitor, and evaluate SOC alerts and investigation outputs based on predefined scenarios and criteria.
  • Distinguish true positives from false positives by validating investigative evidence and alert context.
  • Perform end-to-end security investigations, including log analysis, entity pivoting, timeline reconstruction, and evidence correlation.
  • Assess the correctness, completeness, and quality of SOC investigations produced by automated or human workflows.
  • Use Splunk extensively to pivot across logs, entities, and timelines, including reading and reasoning about SPL queries.
  • Maintain clear and accurate documentation of investigative steps, assumptions, evidence, and conclusions.

Requirements

  • Have strong relevant experience as a SOC analyst in a production SOC environment.
  • Strong understanding of alert triage, incident investigation workflows, and evidence-based decision-making.
  • Mandatory hands-on experience with Splunk, including conducting investigations and reasoning about SPL queries.
  • Proven ability to evaluate SOC investigations and determine whether conclusions are valid, incomplete, or incorrect.
  • Fluent English with strong documentation and communication skills.

Similar jobs