About the Role
What if your hard-won experience in SOC operations could directly strengthen how organizations detect, respond to, and contain cyber threats? We're looking for a seasoned Incident Response Lead to evaluate real-world security operations — scrutinizing detection workflows, response playbooks, and triage logic to identify what's working, what isn't, and what needs to change.
This is a fully remote, flexible contract role built for experienced security professionals who think in timelines, escalation trees, and containment logic.
- Type: Hourly Contract
- Location: Remote
- Commitment: Flexible, based on project scope
What You'll Do
- Review detection alerts, triage workflows, and escalation pathways for quality and consistency
- Evaluate the completeness and effectiveness of incident response actions across real-world scenarios
- Identify gaps in logging coverage, detection logic, and containment strategies
- Summarize incident patterns, operational bottlenecks, and systemic weaknesses
- Validate response playbooks for clarity, accuracy, and practical feasibility under pressure
- Support recurring assessments of SOC maturity and operational readiness
- Produce structured, analytical documentation that drives meaningful operational improvements
Who You Are
Must-Have:
- Hands-on experience in SOC operations, incident response leadership, or cybersecurity operations
- Strong command of detection engineering, response workflows, and incident timeline analysis
- Ability to critically assess triage quality, escalation logic, and containment decisions
- Clear, structured analytical writing skills — you can translate complex findings into actionable documentation
Nice to Have:
- Familiarity with SIEM platforms (Splunk, Microsoft Sentinel, Chronicle, etc.)
- Experience with EDR tools and cloud-native detection systems
- Background in red team / blue team exercises or SOC maturity assessments
- Relevant certifications such as GCIH, GCFA, CISSP, or equivalent
Why Join Us
- Apply deep domain expertise to real, consequential security assessments
- Fully remote and flexible — work when and where it suits you
- Freelance autonomy with the structure of meaningful, project-based work
- Make a direct impact on how organizations prepare for and respond to cyber threats
- Potential for ongoing engagements and contract extension as new projects launch