What the work involves

You receive alerts and the investigations attached to them — some produced by automated systems, some by other analysts — and decide whether the reasoning is sound. That means checking whether the evidence cited actually supports the verdict, whether obvious pivots were skipped, and whether a true positive was written off as noise (or the reverse). On other tasks you build the reference investigation yourself: the full triage path, the SPL you'd run, the entities you'd pivot through, the timeline, and the conclusion with its supporting evidence.

Most decisions resolve to a binary (ACCEPT / PASS), but the value is in the written rationale underneath. Reviewers want to see which specific log line or missing correlation drove your call. A recurring difficulty is that two analysts can take different valid routes to the same correct conclusion — you're judging whether an investigation is defensible, not whether it matches your personal habits.

What the platform screens for

  • Real production SOC time. 3+ years hands-on, Tier 2 or above strongly preferred. Expect follow-ups on shift structure, escalation paths, and cases you personally closed.
  • Splunk depth, not familiarity. You should be able to read SPL you didn't write, explain what a search is actually returning, and describe how you'd pivot from a single indicator to a full entity picture.
  • Decisiveness with a stated basis. Screens penalize hedging; they also penalize confident calls with no evidentiary reasoning behind them.
  • Written clarity. Documentation quality is the deliverable as much as the verdict.

Strengthening signals include EDR work (CrowdStrike, Defender for Endpoint, SentinelOne), cloud log analysis (CloudTrail, GuardDuty, Azure Activity Log, GCP Audit Logs), IAM platforms like Okta or Entra ID, email security tooling, and certifications such as GCIA, GCIH, or Splunk credentials. None are hard gates.

Logistics and pay

Fully remote and largely asynchronous, with task batches pulled from a queue rather than assigned shifts. Observed rates for this listing run $70–95/hr, typically varying with tier level, Splunk depth, and whether you take a lead-annotator or mentoring track — not guaranteed, and set per engagement. Commitments are usually part-time and flexible (often 10–20 hours weekly), with longer-running program work available to analysts who hold quality consistently. Occasional synchronous calibration sessions with program leads are common on active projects.