SOC Analyst for AI-Driven Security Investigations Job at SaidGig, United States

  • SaidGig
  • United States

Job Description

Role Overview

Help advance SOC automation and AI-driven investigation systems by applying real-world security operations expertise to validate alerts, assess investigation quality, and build reliable ground-truth cases across SIEM, endpoint, cloud, and identity environments.

Key Responsibilities

  • Review, monitor, and evaluate SOC alerts and investigation outputs against defined scenarios and criteria.
  • Validate evidence and alert context to distinguish true positives from false positives.
  • Conduct end-to-end investigations as needed, including log analysis, entity pivoting, timeline reconstruction, and evidence correlation.
  • Assess whether investigations produced through automated or human workflows are correct, complete, and high quality.
  • Apply consistent investigative judgment while recognizing that an alert may have more than one valid investigation path.
  • Make clear binary determinations, such as accept or pass, and produce detailed ground-truth investigations when required.
  • Use Splunk extensively to pivot across logs, entities, and timelines, including reading and reasoning about SPL queries.
  • Document investigative steps, assumptions, evidence, and conclusions clearly and accurately.
  • Collaborate with program leads and fellow expert annotators to maintain strong investigation and annotation standards.
  • Mentor or support other analysts when applicable, particularly in long-term or lead annotator assignments.

Qualifications

  • At least 3 years of hands-on experience as a SOC analyst in a production SOC environment. Tier 2 or higher experience is strongly preferred.
  • Strong knowledge of alert triage, incident investigation workflows, and evidence-based decision-making under time constraints.
  • Hands-on Splunk experience, including conducting investigations, reading and reasoning about SPL queries, and pivoting among logs, entities, and timelines.
  • Demonstrated ability to evaluate SOC investigations and determine whether conclusions are valid, incomplete, or incorrect.
  • Sound investigative judgment and confidence making decisive evaluations.
  • Fluent written and spoken English, with strong documentation and communication skills.

Preferred Qualifications

  • Experience with EDR tools such as CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOne.
  • Experience analyzing AWS CloudTrail and GuardDuty, Azure Activity Log and Defender for Cloud, or GCP Cloud Audit Logs.
  • Familiarity with identity and access management platforms such as Okta Identity Cloud or Microsoft Entra ID.
  • Experience with email security tools such as Proofpoint or Mimecast.
  • SOC leadership or mentoring experience.
  • Basic Python or similar scripting experience.
  • Optional security certifications, including GCIA, GCIH, GCED, Splunk certifications, Security+, CCNA, or cloud security certifications.

Work Terms

  • Remote hourly engagement.

Compensation

  • $70 to $95 per hour.

Opportunity

  • Contribute to high-impact investigative evaluations and security cases while collaborating with SOC practitioners, security engineers, and AI teams.
  • Apply practical SOC expertise to help shape how future security teams investigate and respond to threats.

Job Tags

Hourly pay

Similar Jobs

Hellosunshinetravels

Remote Travel Experience Specialist Job at Hellosunshinetravels

 ...inquiries, providing recommendations, maintaining client profiles, and ensuring a smooth travel experience. The position offers a flexible work-from-home schedule and opportunities for growth, making it ideal for those passionate about travel and client service.#J-18808-... 

MARTIN CONSTRUCTION, INC.

CDL Dump Truck Driver/Gravel Truck Driver Job at MARTIN CONSTRUCTION, INC.

 ...tractor-trailer combination driver, applying knowledge of commercial driving regulations, to operate as a belly-dump driver and/or water truck driver and/or transport driver. Knowledge, Skills & Abilities: Must have the ability to operate a tractor-trailer in a... 

MaziCTools

Remote Transcriptionist (Entry Level) - Flexible Hours Job at MaziCTools

 ...transcription jobs perfect for teens looking to begin their careers in the entertainment industry. This full-time role allows you to work from home, handling audio and video transcription tasks, ensuring utmost accuracy and adherence to guidelines set by Netflix.Candidates... 

Medical Delivery Services

Delivery Driver Charlottesville, VA Mon-Fri Job at Medical Delivery Services

 ...Medical Delivery Driver (Independent Contractor 1099) Medical Delivery Services is contracting Independent Drivers (1099) for medical delivery routes using your own vehicle. No delivery experience required. Fast onboarding and steady earnings. Compensation ~$7... 

viLogics

Security Operations Center (SOC) Analyst Job at viLogics

 ...Job Description Job Description Position Overview: As a SOC Analyst at viLogics, you are a front-line cyber defender operating...  ...Engineer TSO 365 Platform Architect Work Environment: Fully remote with optional travel to client locations or viLogics Data...