Incident Response Analyst - Fully Remote
Kiryas Joel, Orange County, New York, USA
Listed on 2026-10-02
-
IT/Tech
Cybersecurity
About the work
Mercor is designing a benchmark that measures how well AI agents do real enterprise cyber defense work. Before we build it, we want to hear from people who do that work every day.
This is a short paid research engagement, not a task or data project. You will join two to three one-hour video conversations with the Mercor team over roughly four weeks, scheduled around your availability.
What we will talk about- How your work actually happens: the tools you live in, what lands in your queue, where judgment matters and where it does not.
- How your team measures whether a triage, investigation, containment, hunt, detection rule or patch was done well.
- Where AI assistance helps you today, where it gets in the way, and what would make a benchmark of AI on this work credible to you.
- Our draft task taxonomy: what is missing, what is mislabeled, what you would weight differently.
Current or recent hands-on practitioners in enterprise security, for example:
- SOC analysts and SOC leads (tier 2 and above)
- Incident responders and digital forensics investigators
- Detection engineers and threat hunters
- Application security or product security engineers who find and fix vulnerabilities in production code
- Security engineers who have run or been on the receiving end of a red team engagement
Experience with an EDR and SIEM stack (Crowd Strike Falcon, Microsoft Defender and Sentinel, Splunk, Sentinel One, Elastic or similar) is a plus. Security leaders are welcome if you are still close to the work.
Pay and time- Paid hourly for interview time as a spot bonus. Sessions are one hour; no prep is expected.
- Two to three sessions in total. Nothing to build, label or submit.
- Remote, US-based.
We will ask you to describe patterns, not specific incidents, and to leave out anything confidential about current or former employers or customers. Your input is used only to design the benchmark and is never attributed to you or your employer.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).