What the work actually involves
You take an assigned workflow — pivot from a Suricata alert in Alerts to the related Zeek conn and http logs, pull the PCAP in Hunt, confirm or dismiss the detection — and complete it in your own Security Onion instance while recording your screen. Then you write it up: what you clicked, why you pivoted where you did, what would have changed your conclusion. From that recorded session you build a realistic prompt (the kind of question an analyst would genuinely put to an AI assistant) and a rubric detailed enough that a second reviewer, grading a model's answer, reaches the same score you would.
A second stream of work is evaluation: reading model outputs or other contributors' submissions and judging them against project guidelines. This is where most of the difficulty sits. A model answer about Security Onion can be fluent, well-structured, and quietly wrong — recommending a Kibana workflow that Security Onion 2.4 moved to SOC, confusing Suricata alert metadata with Zeek connection records, or inventing a `so-` command that does not exist. The job is catching that reliably and writing a reason a downstream reader can act on.
What the screen looks for
- Real instance access. Not coursework, not a screenshot deck. You should be able to describe your setup — standalone eval install, distributed deployment, what sensors feed it.
- Version literacy. Security Onion changed substantially between the 16.04/Elastic-era builds and 2.x with SOC, Cases, and the Detections interface. Vague answers that could apply to any SIEM read as secondhand knowledge.
- Explanatory clarity. Can you narrate an investigation in order, out loud, without skipping the reasoning between steps? The screen is conversational and will follow up on whatever you compress.
- Calibrated judgment. Whether you can distinguish an answer that is wrong from one that is merely different from how you would have done it.
Logistics
Fully remote contractor work, asynchronous, no fixed hours. Contributors typically pick up batches of workflows and deliver against a turnaround window rather than sitting in a shift. Volume fluctuates with customer demand — treat it as variable supplementary work, not a replacement for a full-time role. Observed rates for this listing run $90–175/hr, with placement in that band reflecting depth of hands-on Security Onion experience and prior evaluation work; the band is what has been posted, not a guarantee of any individual offer.