SOC Analyst - Splunk Expert - Full-Time REMOTE
Worldwide
OVERVIEW We are looking for an experienced SOC Analyst with strong hands-on Splunk experience to support a client’s security operations needs. This role is specifically for someone who has worked directly inside Splunk in a SOC environment and can investigate alerts, write and modify searches, analyze security events, and explain their Splunk experience in depth. Please only apply if you are truly comfortable working hands-on with Splunk. The interview process will include detailed technical questions about Splunk, SOC workflows, alert investigation, search queries, dashboards, correlation, and real-world detection/response scenarios. WHAT YOU'LL DO - Monitor, triage, and investigate security alerts in a SOC environment - Use Splunk hands-on to search, analyze, and correlate security events - Review logs and alerts from endpoints, network devices, identity systems, cloud platforms, and security tools - Write, modify, and explain SPL queries used for investigation and analysis - Investigate suspicious activity and escalate incidents when needed - Support incident response workflows, including evidence gathering and timeline analysis - Tune alerts, reduce false positives, and improve detection quality where appropriate - Document investigations, findings, and recommended next steps clearly - Work with internal security, infrastructure, and IT teams to support remediation and follow-up WHAT WE'RE LOOKING FOR - Strong hands-on experience using Splunk in a SOC or security operations environment - Ability to write and explain SPL searches for real investigation scenarios - Experience investigating alerts, suspicious logins, malware activity, endpoint events, network anomalies, phishing-related events, or cloud security alerts - Understanding of SOC processes, including triage, escalation, incident handling, and documentation - Ability to interpret logs from Windows, Linux, firewalls, EDR tools, identity platforms, and other security sources - Strong analytical skills and attention to detail - Clear communication skills and ability to explain investigation steps and findings - Ability to perform well in a technical interview focused heavily on Splunk and SOC scenarios SPLUNK EXPERIENCE REQUIRED - You should be comfortable navigating Splunk and using it for daily SOC investigations - You should understand SPL syntax and be able to build practical searches - You should be able to explain how you investigate alerts in Splunk from initial detection through validation and escalation - You should understand fields, indexes, sourcetypes, lookups, dashboards, alerts, and correlation searches at a practical working level - You should be prepared to discuss real examples of Splunk investigations you have performed NICE TO HAVE - Experience in financial services industry. HOW TO APPLY - Briefly describe your SOC analyst and Splunk experience. - Send a loom or equivalent video introduction - Send a copy of your resume
- More than 30 hrs/weekHourly
- 6+ monthsDuration
- IntermediateExperience Level
- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Last viewed by client:yesterday
- Interviewing:19
- Invites sent:0
- Unanswered invites:0
About the client
- United States11:36 PM
- $20K total spent35 hires, 8 active
- 985 hours
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by