What the work is
About the work
What we will talk about
- How your work actually happens: the tools you live in, what lands in your queue, where judgment matters and where it does not.
- How your team measures whether a triage, investigation, containment, hunt, detection rule or patch was done well.
- Where AI assistance helps you today, where it gets in the way, and what would make a benchmark of AI on this work credible to you.
- Our draft task taxonomy: what is missing, what is mislabeled, what you would weight differently.
Who gets hired
Who we are looking for
Current or recent hands-on practitioners in enterprise security, for example:
- SOC analysts and SOC leads (tier 2 and above)
- Incident responders and digital forensics investigators
- Detection engineers and threat hunters
- Application security or product security engineers who find and fix vulnerabilities in production code
- Security engineers who have run or been on the receiving end of a red team engagement
Experience with an EDR and SIEM stack (CrowdStrike Falcon, Microsoft Defender and Sentinel, Splunk, SentinelOne, Elastic or similar) is a plus. Security leaders are welcome if you are still close to the work.
Pay and time
- Paid hourly for interview time as a spot bonus. Sessions are one hour; no prep is expected.
- Two to three sessions in total. Nothing to build, label or submit.
- Remote, US-based.
Confidentiality
We will ask you to describe patterns, not specific incidents, and to leave out anything confidential about current or former employers or customers. Your input is used only to design the benchmark and is never attributed to you or your employer.
Pay
$125–175/hr, fully remote.