×
Register Here to Apply for Jobs or Post Jobs. X

Remote AI-Driven SOC Investigator

Remote / Online - Candidates ideally in
Sacramento, Sacramento County, California, 94203, USA
Listing for: Mercor
Remote/Work from Home position
Listed on 2026-07-26
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 80000 - 120000 USD Yearly USD 80000.00 120000.00 YEAR
Job Description & How to Apply Below
  • Mercor is hiring SOC Investigation Specialist on behalf of high-growth technology and enterprise partners building next-generation SOC automation and AI-driven investigation systems. This role is ideal for experienced SOC analysts who can apply real-world investigative judgment to review, validate, and construct high-quality security investigations across SIEM, endpoint, cloud, and identity environments. * * * ### Responsibilities
    - Review, monitor, and evaluate SOC alerts and investigation outputs based on predefined scenarios and criteria.

    - Distinguish true positives from false positives by validating investigative evidence and alert context.

    - Perform end-to-end security investigations when required, including log analysis, entity pivoting, timeline reconstruction, and evidence correlation.

    - Assess the correctness, completeness, and quality of SOC investigations produced by automated or human workflows.

    - Apply consistent investigative judgment while recognizing that multiple valid investigation paths may exist for the same alert.

    - Make clear binary determinations (e.g., ACCEPT / PASS) while also producing detailed ground-truth investigations when required.

    - Use Splunk extensively to pivot across logs, entities, and timelines, including reading and reasoning about SPL queries.

    - Maintain clear and accurate documentation of investigative steps, assumptions, evidence, and conclusions.

    - Collaborate with program leads and other expert annotators to uphold high-quality investigation and annotation standards.

    - Mentor or support other analysts where applicable, particularly in long-term or lead annotator roles. * * * ### Requirements - 3+ years of hands-on experience as a SOC analyst in a production SOC environment (Tier 2 or above strongly preferred).

    - Strong understanding of alert triage, incident investigation workflows, and evidence-based decision-making under time constraints.

    - Mandatory hands-on experience with Splunk , including :

    - Conducting investigations using Splunk
    - Reading, understanding, and reasoning about SPL queries
    - Pivoting between logs, entities, and timelines
    - Proven ability to evaluate SOC investigations and determine whether conclusions are valid, incomplete, or incorrect.

    - Strong investigative judgment and comfort making decisive evaluations.

    - Fluent English (written and spoken) with strong documentation and communication skills. * * * ### Nice to Have

    - Experience with Endpoint Detection & Response (EDR) tools such as Crowd Strike Falcon, Microsoft Defender for Endpoint, or Sentinel One.

    - Experience analyzing cloud security logs and signals :

    - AWS (Cloud Trail, Guard Duty) - Azure (Activity Log, Defender for Cloud) - GCP (Cloud Audit Logs) - Familiarity with Identity & Access Management platforms such as Okta Identity Cloud or Microsoft Entra  (Azure AD).

    - Experience with email security tools like Proofpoint or Mimecast.

    - SOC leadership or mentoring experience.

    - Basic scripting experience (Python or similar).

    - Security certifications (optional) : GCIA, GCIH, GCED, Splunk certifications, Security+, CCNA, or cloud security certifications. * * * ### Why Join
    - Work on cutting-edge SOC automation and AI-driven investigation systems.

    - Apply real-world SOC expertise to shape how future security teams investigate and respond to threats.

    - Take ownership of high-impact investigative evaluations and ground-truth security cases.

    - Collaborate with experienced SOC practitioners, security engineers, and AI teams.

    - Join Mercor’s global network of vetted security professionals.
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary