$70–95/hr · Mercor · Part time
Senior SOC analyst evaluating and improving how AI systems investigate security alerts and produce incident analysis.
What you would do
- Review and evaluate AI-generated security investigations and SOC alerts for correctness, completeness, and investigative soundness
- Perform complex end-to-end security investigations using Splunk to analyze logs, pivot across entities and timelines, and reconstruct events
- Distinguish true positives from false positives through careful evaluation of investigative evidence and alert context from SIEM, endpoint, and cloud sources
- Create ground-truth investigations that define high-quality security analysis for AI model training and evaluation
- Document investigative reasoning, assumptions, evidence connections, and conclusions with clarity for researcher review and model improvement
Who they want
- 3+ years of hands-on SOC analyst experience in production environments, Tier 2 or above positions strongly preferred
- Deep Splunk expertise including conducting investigations, reading SPL queries, and pivoting across logs, entities, and timelines
- Strong understanding of alert triage approaches, incident response methodologies, and rapid analytical judgment under operational pressure
- Proven ability to evaluate whether security investigations are valid, incomplete, or incorrect with sound investigative judgment
- Fluent written and spoken English with strong documentation skills and comfort providing structured feedback to research teams
Main skills
What the interview asks about
1.False positive versus true positive determination
Correctly identifying whether alerts represent genuine threats is foundational; AI systems must learn when alerts are spurious despite appearing suspicious.
For example: “You see a Splunk alert for 50 failed login attempts from an external IP to administrative accounts over 2 hours. What investigation steps would you perform to determine if this is an attack or legitimate activity?”
2.Evidence correlation and timeline reconstruction
Complete investigations connect multiple data sources and reconstruct accurate timelines; spotting gaps and missing evidence connections is critical.
For example: “An AI investigation concludes a user account was compromised based on unusual 3am login from new IP. What additional evidence would you examine before accepting this conclusion?”
3.Splunk query reasoning and interpretation
AI systems must correctly interpret security queries and understand what data they return; evaluators assess whether AI grasps SPL logic and query validity.
For example: “Review this SPL query designed to find lateral movement. Explain what it searches for, whether it would catch the intended behavior, and what edge cases it might miss.”
4.Investigation completeness judgment
Some investigations are correct but incomplete; distinguishing thorough analysis from shallow conclusions requires expertise in investigation methodology.
For example: “An AI generates an investigation concluding an alert is a true positive. Is it sufficient, or what additional investigation steps would a SOC analyst normally perform?”
5.Endpoint and cloud investigation integration
Modern investigations span multiple environments; AI systems must correlate evidence from SIEM, EDR, and cloud logs, which requires understanding each platform.
For example: “You need to investigate suspicious AWS CloudTrail activity that correlates with endpoint detection alerts. How would you tie these together and determine scope?”
A task you may get
Investigate a SIEM and endpoint alert using Splunk to determine if threat is real, reconstruct timeline, identify impact, and document investigation reasoning.
How to prepare
- Review recent real-world security incidents and post-incident reports to understand how thorough investigations actually unfold and identify common investigative gaps
- Practice writing and interpreting Splunk queries across different log sources including authentication, network, process execution, and file activity data
- Study examples where AI systems made SOC analysis mistakes, noting common pitfalls like overweighting single evidence types or missing alternative explanations
- Refresh understanding of threat behaviors across SIEM, EDR tools, cloud environments, and identity platforms
The facts
- Pay
- $70–95/hr
- Hours
- Part time
- Where
- Remote
- Open to
- IND, DNK, EST, FIN, ISL, IRL, LVA, LTU, NOR, SWE, AUT, BEL, FRA, DEU, LIE, LUX, MCO, NLD, CHE, GBR, ALB, BIH, HRV, GRC, ITA, XKX, MLT, MKD, PRT, SMR, SRB, SVN, ESP, BGR, CZE, HUN, MDA, POL, ROU, SVK, IND, DNK, EST, FIN, ISL, IRL, LVA, LTU, NOR, SWE, AUT, BEL, FRA, DEU, LIE, LUX, MCO, NLD, CHE, GBR, ALB, BIH, HRV, GRC, ITA, XKX, MLT, MKD, PRT, SMR, SRB, SVN, ESP, BGR, CZE, HUN, MDA, POL, ROU, SVK
- Field
- Data Analysis
- Role type
- Talent network
- Posted
- 1/18/2026
We wrote this page from the public Mercor listing. It may be out of date, so read the full posting before you apply.