TechGeo 🔔 Track jobs on Gurify
TechGeo / Freelance Security Analyst

Freelance Security Analyst

Toloka Georgia
Posted Aug 06, 2026 5h ago

Job description

Company Intro At Toloka AI we create data that powers leading GenAI models and innovations. We work with frontier labs, big tech, renowned AI startups, enterprises and non-profit research organizations worldwide. We use a combination of Experts + Crowd + Tech Platform to teach AI models to reason and evaluate their efficacy and safety. We have experts in more than 50 different domains - from doctors and lawyers to physicists and engineers - and boast one of the most diverse global crowds, representing over 100 countries and speaking 40+ languages . We are a well-funded startup with an enviable portfolio of clients including Anthropic , Amazon , Microsoft , Poolside , Recraft , and Shopify . Recently, we secured strategic investment led by Bezos Expeditions and Nebius Group with participation from Mikhail Parakhin , CTO of Shopify and board advisor to leading GenAI companies, who now serves as our Chairman of the Board. Our remote-first team is globally distributed around the world: USA , UK , the Netherlands , Serbia , and more. We're looking for a Freelance Security Analyst to join our Security team and help protect the infrastructure behind one of the world's leading AI data companies. You'll investigate security incidents, analyze cloud and SaaS logs, improve detection capabilities, and work with modern AI-powered investigation workflows. This role is ideal for someone who enjoys analytical problem-solving, likes working with data, and wants to build a career in cloud security while working on cutting-edge AI infrastructure. What this role is about Toloka runs entirely on cloud and SaaS. They all produce audit logs, and that's where security work lives: something looks unusual, and someone has to work out whether it's an attack, a misconfiguration, or an engineer doing their job in an unexpected way. Working that out is the job. You'll join a globally distributed security team and grow into a security analyst with us. We don't expect you to know our stack - Azure, Sentinel, KQL, Terraform: we'll teach it. What we can't teach is the ability to reason through a messy problem with incomplete data. What we do expect up front: you already work with coding agents. Most of our work is agent-driven research - an investigation or an audit is a harness we build and run, not a query we type by hand. You should understand how a modern agent stack fits together (tools/MCP, context, subagents, evals) and how to spot an agent that is confidently wrong. In security a fabricated finding is worse than no finding. What you'll actually do - Triage security alerts daily - read the evidence, reach a verdict, escalate what's real, document it. With a mentor at first, on your own within a few months. - Investigate: phishing against our staff and our expert community, suspicious logins, files leaving the company, leaked credentials. Build the timeline, name the affected accounts, and recommend the fix. - Work through agents: point a harness at the logs, then verify what it claims against the raw data before you sign off. Extend our investigation skills and eval cases as you learn where the agent gets things wrong. - Write and tune detections. Our rules are code in Git - you'll ship them as pull requests. - Answer the company's security questions in Slack: access requests, "is this app safe", "I got a strange email" - with a reason, not just a verdict. - Run recurring hygiene work: access reviews, service-account audits, phishing simulations, and keeping the runbooks honest. - Later, if it suits you: build log connectors in Python, or grow towards the engineering side - infrastructure as code, cloud configuration, data-access controls. Key Priorities for the First 6 Months The team runs a security duty rotation - whoever is on duty is the company's first line for anything security-related that week: the alert queue, incoming requests from any team, and whatever turns out to be on fire. Getting you onto that rotation is the point of your first six months. - Weeks 1-2 - get oriented in the estate and the tooling; you're triaging alongside your mentor from the second day. - Month 1 - handle the recurring alert types yourself, with review. Shadow a full duty week. - Month 2 - own the daily alert queue unsupervised; first detection rules shipped as pull requests. - Month 3 - take your first duty shifts with someone backing you up; ship your first improvement to our investigation agent skills. - Month 4 - run a recurring process (an access review or a service-account audit) end to end. - Months 5-6 - a full member of the duty rotation: real incidents from first alert to written post-mortem without a fallback, plus ownership of an area - a group of detections, a log source, or a recurring audit. We move fast and expect you to. Six months in, you should be someone the rest of the company comes to directly. Core tech stack Broad, and deliberately so. We're a cloud-native company with no legacy: identity, code, data and infrastructure each live in a different cloud, alongside a couple of dozen SaaS systems - and every one of them is a log source you'll learn to read. Nobody here knows all of it. The actual skill is getting oriented in a system you first opened this morning. Three things you'll touch every day: Claude Code and our agent harnesses , the layer we expect you to arrive already fluent in; Microsoft Sentinel and KQL - a SQL -like query language for logs - which quickly become your hands; and Git , because our detections and access rules are code that ships through pull requests, not settings clicked in a console. Around that: Python , Terraform , Kubernetes , MITRE ATT&CK , and whatever the next system we onboard turns out to require. What we evaluate - Analytical ability, demonstrated. Reason from messy, incomplete data to a conclusion and explain how you got there. Tested with a case exercise - no security knowledge needed to solve it. - Real fluency with coding agents. Not "I've used ChatGPT": agentic tools are your normal way of building things, and you understand the machinery - tools/MCP, context, subagents, evals. Expect to walk us through a harness you've built and why you designed it that way. - Skepticism towards model output. Tell us about a time an agent was confidently wrong and what you now do to catch it. - Comfort with data and basic Python - SQL, pandas or spreadsheets on real datasets; enough Python to call an API and process the response. You don't need to be a developer. - Clear written English and genuine curiosity about how systems work - plus the willingness to say "I don't know yet, here's how I'll find out." Nice to have, none required Something non-trivial you've shipped with agents (an MCP server, a custom skill, an eval suite); any security exposure (SOC internship, CTFs, home lab, Security+ / SC-200); experience reading logs; cloud, Linux or networking basics. This role suits people moving into security from data analysis, antifraud, IT support or engineering, or strong recent graduates. What we can offer Freelance collaboration via the Ontop freelance platform ( B2B contract is available ). Flexible, fully remote schedule ( 40 hours per week ). You’ll have the opportunity to work on highly innovative projects at the leading edge of AI development, together with a genuinely dedicated and dynamic team of experts. You’ll also be working on projects with customers that are AI industry leaders and well-known household names. Friendly community.