SOC Investigation Evidence Reviewer
Work you will do
- Analyze alert and event evidence using the appropriate SIEM and investigative workflow.
- Assess triage, escalation, detection and response reasoning, identifying unsupported conclusions or missed signals.
- Document findings and reference decisions clearly; leadership-focused assignments also evaluate process quality, coordination and operational effectiveness.
Required background and routes
- At least three years as a hands-on analyst in a production SOC. Splunk investigation is mandatory, including SPL interpretation and movement between logs, entities and timelines.
- Evaluate whether an investigation's conclusion follows from its evidence; understand alert triage, incident workflows and time-constrained judgment. Fluent spoken and written English is required.
Preferred background
- Tier 2 or higher responsibility, mentoring, Python scripting or SOC leadership.
- CrowdStrike Falcon, SentinelOne or Defender for Endpoint; CloudTrail/GuardDuty, Azure or GCP logs; Okta/Entra ID; Proofpoint/Mimecast; GCIA, GCIH, GCED, Splunk, Security+, CCNA or cloud-security certifications.
Deliverables
Submit the completed technical artifact or assessment with its supporting evidence, explicit assumptions, reproducible checks where applicable, and concise reasons for each material judgment. Address review findings within the agreed scope.
Location and schedule
Regional eligibility: India, Denmark, Estonia, Finland, Iceland, Ireland, Latvia, Lithuania, Norway, Sweden, Austria, Belgium, France, Germany, Liechtenstein, Luxembourg, Monaco, Netherlands, Switzerland, United Kingdom, Albania, Bosnia and Herzegovina, Croatia, Greece, Italy, Kosovo, Malta, North Macedonia, Portugal, San Marino, Serbia, Slovenia, Spain, Bulgaria, Czechia, Hungary, Moldova, Poland, Romania, Slovakia. Remote assignments are scheduled by agreement, with no guaranteed weekly volume. IXO confirms the applicable timing before work.
Pay and working terms
$75 $100/hr USD. The agreed hourly rate, scope, schedule and acceptance criteria are confirmed before work starts. Applying does not guarantee an assignment. Use public, licensed or otherwise authorized material only; do not submit confidential employer information, personal data or restricted research.
#J-18808-Ljbffr