Skip to content
Labeling Jobs

Security Onion Specialist

Pay
$90 – $175 / Hour
Open to
Worldwide
Apply

We earn a commission if you sign up through the links on this page. It costs you nothing and does not affect which jobs we list. How this works.

Skills
  • security onion
  • threat detection
  • incident response
  • log analysis
  • network monitoring
  • rubric writing

What you'll do

You do SOC analyst work inside Security Onion, the open-source platform for network security monitoring and log management, and record it. Assigned workflows cover network monitoring, alert investigation, log analysis, threat detection and incident response: you analyse alerts, traffic and logs and show every step on screen.

From each completed workflow you write a realistic prompt that would ask an agent to perform it and a detailed rubric for judging the result. You document the steps and explain which tools, features and investigation techniques you used, and you review task outputs against the project guidelines.

The payoff for the customer is data showing how an experienced analyst actually moves through the platform, which is exactly what a security agent would need to imitate.

Who fits

  • Strong hands-on Security Onion experience for monitoring, detection or incident investigation
  • Previous human-data work (annotation, labelling, RLHF, response or model evaluation) is preferred
  • Your own access to Security Onion and the ability to run it independently
  • Comfortable recording and sharing your screen
  • Able to explain a technical workflow clearly in writing

No AI experience is required.

What it pays

$90–175/hour, micro1's published figure. The ad does not say whether pay is hourly or per task, or what places you in the band.

Security Onion is a niche tool, and the rate reflects that: it matches micro1's GitHub Specialist listing, which uses the same template, and sits well above typical SOC analyst contract rates.

Before you start

You need your own Security Onion environment, which in practice means a lab install on hardware or a VM that meets its resource requirements. Do not record workflows against a production environment you manage for an employer; real alerts and logs contain data you should not share.

Worth knowing

Good:

  • A rare, well-paid use for a specialist blue-team skill
  • Previous annotation or RLHF work gives you an edge
  • 40 openings on a newly posted listing
  • No AI experience needed

Less good:

  • You provide your own Security Onion access
  • Screen recording means careful control over what data appears
  • Pay structure and placement criteria not stated
  • No hours, duration or start date published
  • Contractor engagement: no benefits, your own tax to manage

About this listing

Posted by micro1 on its own jobs portal and read on 24 September 2026, a day after it went up. Location is Remote with no country list. It shares its template and $90–175 band with micro1's GitHub Specialist listing. See micro1.

More roles at micro1

See all 380

Similar roles at other platforms

Guides about micro1

See all 81

Browse similar roles

Not the right fit?

See every open role, or get new ones on Telegram or Discord as they are added.