Cutshort logo
For Employers
Mercor logo
SOC Investigation Specialist Talent Network
SOC Investigation Specialist Talent Network

SOC Investigation Specialist Talent Network at Mercor · Remote only · 3 - 7 years · ₹10L - ₹20L / yr · Remote only · Posted 16 Apr 2026

Halogion's logo

SOC Investigation Specialist Talent Network

Agency job
3 - 7 yrs
₹10L - ₹20L / yr
Remote only
Skills
SOC
Splunk
CrowdStrike Falcon
Microsoft Defender
SentinelOne
skill iconAmazon Web Services (AWS)
CloudTrail
GuardDuty
Azure
Google Cloud Platform (GCP)
Okta Identity Cloud
Microsoft Entra ID
Mimecast
GCIA
GCIH
GCED
Cisco Certified Network Associate (CCNA)

Hiring SOC Investigation Specialist on behalf of high-growth technology and enterprise partners building next-generation SOC automation and AI-driven investigation systems. This role is ideal for experienced SOC analysts who can apply real-world investigative judgment to review, validate, and construct high-quality security investigations across SIEM, endpoint, cloud, and identity environments.

Responsibilities

  • Review, monitor, and evaluate SOC alerts and investigation outputs based on predefined scenarios and criteria.
  • Distinguish true positives from false positives by validating investigative evidence and alert context.
  • Perform end-to-end security investigations when required, including log analysis, entity pivoting, timeline reconstruction, and evidence correlation.
  • Assess the correctness, completeness, and quality of SOC investigations produced by automated or human workflows.
  • Apply consistent investigative judgment while recognizing that multiple valid investigation paths may exist for the same alert.
  • Make clear binary determinations (e.g., ACCEPT / PASS) while also producing detailed ground-truth investigations when required.
  • Use Splunk extensively to pivot across logs, entities, and timelines, including reading and reasoning about SPL queries.
  • Maintain clear and accurate documentation of investigative steps, assumptions, evidence, and conclusions.
  • Collaborate with program leads and other expert annotators to uphold high-quality investigation and annotation standards.
  • Mentor or support other analysts where applicable, particularly in long-term or lead annotator roles.

Requirements

  • 3+ years of hands-on experience as a SOC analyst in a production SOC environment (Tier 2 or above strongly preferred).
  • Strong understanding of alert triage, incident investigation workflows, and evidence-based decision-making under time constraints.
  • Mandatory hands-on experience with Splunk, including:
  • Conducting investigations using Splunk
  • Reading, understanding, and reasoning about SPL queries
  • Pivoting between logs, entities, and timelines
  • Proven ability to evaluate SOC investigations and determine whether conclusions are valid, incomplete, or incorrect.
  • Strong investigative judgment and comfort making decisive evaluations.
  • Fluent English (written and spoken) with strong documentation and communication skills.

Nice to Have

  • Experience with Endpoint Detection & Response (EDR) tools such as CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOne.
  • Experience analyzing cloud security logs and signals:
  • AWS (CloudTrail, GuardDuty)
  • Azure (Activity Log, Defender for Cloud)
  • GCP (Cloud Audit Logs)
  • Familiarity with Identity & Access Management platforms such as Okta Identity Cloud or Microsoft Entra ID (Azure AD).
  • Experience with email security tools like Proofpoint or Mimecast.
  • SOC leadership or mentoring experience.
  • Basic scripting experience (Python or similar).
  • Security certifications (optional): GCIA, GCIH, GCED, Splunk certifications, Security+, CCNA, or cloud security certifications.
Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

About Mercor

Founded
Type
Size
Stage

About

N/A

Company social profiles

N/A

Similar jobs (2)

Service Based Company
Service Based Company
Agency job
via by Chandra M
Chennai
6 - 9 yrs
₹8L - ₹15L / yr
SOC analyst
Incident Response
SIEM
Firewall
endpoints
+2 more

This role will be permanent with NAM info and deploy to client location Chennai.


Work Mode: WORK FROM OFFICE

Offer salary can offer on a decent hike


Role Descriptions:

Exp Range: 6-10 years

Primary Competency : Terraform, Hashi Sentinel (IaC/PaC), Kubernetes (GKE/EKS)

City Locations: Bengaluru or Chennai

Key Responsibilities*

Experience Required: 6-10



Role Descriptions:

Security Monitoring & Incident Response


Investigate and analyze security alerts escalated by L1 SOC analysts.

Perform triage, containment, eradication, and recovery activities for security incidents.


1. Perform in-depth analysis of security alerts escalated from L1

2. Investigate suspicious activities using SIEM, EDR, and threat intelligence tools

3. Correlate events across multiple log sources (firewalls, endpoints, IAM, cloud logs)

4. Validate true positives and recommend reducing false positives

5. Lead triage and response for medium to high severity incidents

6. Coordinate with IT, network, and application teams during incidents and support deep investigations when required

7. Conduct proactive threat hunting based on TTPs (e.g., MITRE ATT&CK)

8. Fine-tuning and optimize SIEM use cases to reduce false positives

9. Develop new correlation rules and detection logic

10. Document incidents, findings, and response actions

11. Prepare weekly , monthly reports for SOC leadership and stakeholders


Desire candidate

  • Candidate should have valid PF.
Read more
Remote only
0 - 3 yrs
₹10000 - ₹15000 / mo
Cyber Security
Security Information and Event Management (SIEM)
Network Security
Linux/Unix
Security operations

Cyber Toddler is inviting applications for its 6-week Cybersecurity Operations, SOC & Threat Intelligence Internship — a weekend-only practical program designed for students, fresh graduates and early-career cybersecurity professionals.


The internship focuses on the skills used across modern security operations, including SOC monitoring, SIEM and log analysis, threat intelligence, incident response, threat hunting and security detection.

Rather than focusing only on theoretical learning, selected interns will work through simulated security incidents, investigate logs and indicators, analyze threats, document findings and complete a final cybersecurity investigation project.


What you will work on:

  • SOC operations and security monitoring
  • SIEM concepts and log analysis
  • Security alert triage
  • Threat intelligence and IOC investigation
  • Phishing and suspicious activity analysis
  • Incident response
  • MITRE ATT&CK
  • Threat hunting
  • Detection engineering fundamentals
  • Security investigation and reporting
  • Cybersecurity documentation
  • End-to-end SOC investigation


Duration: 6 weeks

Mode: Remote

Schedule: Weekends

Commitment: Approximately 4–5 hours per week

Cohort: Limited seats

Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos