The work
AfterQuery contracts security practitioners to build the evaluation material AI labs use to test whether a model's security advice would survive contact with a real environment. A typical task starts with you authoring a scenario grounded in something you've actually worked: a suspicious EDR detection on a finance workstation, a burst of failed Okta logins followed by one success, a Nessus finding on an internet-facing appliance nobody owns. You write the alert data or log excerpts the model sees, then a reference answer that spells out the investigative path — which pivot you'd make first, what evidence would change your hypothesis, when you'd contain versus keep watching.
The second half is grading. You read model output against your reference and score it for technical accuracy and operational soundness. The interesting failures are rarely factual errors; they're answers that cite the right framework and recommend something that would destroy volatile evidence, tip off an attacker, break production, or close a ticket that should have been escalated. Flagging plausible-but-harmful guidance is the core skill the platform is buying.
What the screen looks for
- Verifiable operational history — which SIEM, which EDR, what your queue actually looked like, what you escalated and to whom
- Genuine depth in at least one lane (detection engineering, threat hunting, vuln management, GRC) rather than shallow coverage of all of them
- Written reasoning that a reviewer can follow without you in the room, since everything is async
- Calibration: whether you can distinguish a wrong answer from a merely different-but-defensible one
Logistics
Fully remote, fully asynchronous — no shifts, no live calls with labs. You set hours each week against a 10-hour floor, and work is paid weekly via Stripe. Rates within the $90–135 band are as observed on the platform and typically reflect specialization depth and grading track record; they are not guaranteed. Work is ongoing rather than a fixed engagement, with volume varying by scenario batch.