Job Description
As a Cyber Analyst (CA), you sit at the human-in-the-loop (HITL) checkpoint of our SitRep generation pipeline. You will review AI-generated SitReps — both those flagged by our automated confidence gate and those in routine QA sampling — determine whether the underlying detection is a true or false positive, diagnose why the pipeline got it right or wrong, and drive permanent fixes into the system's knowledge base and agent prompts.
You are the mechanism by which a mistake happens once instead of a thousand times
Job Title: Cyber Analyst — AI-Assisted MXDR Operations
Required Experience: 2-5 years
Educational Qualification: B.E./B.Tech, M.E./M.Tech, BCA, or MCA in Computer Science, Information Technology, Cyber Security, Information Security, or a related field
Location: Pune/Ahmedabad
Key Responsibilities:
SitRep Triage & Investigation
Review AI-generated SitReps in our case management queue (TheHive), including escalations from low-confidence scoring, judge-model failures, and recurring-case matches
-
Classify SitReps as False Positive, True Positive / Benign, or True Positive / Approved, using client context, detection logic, raw telemetry, and asset data
-
Investigate underlying security events across network, endpoint, cloud, and identity telemetry to validate or refute the AI's findings
-
Approve high-quality SitReps for client delivery; correct, annotate, or escalate the rest
Root-Cause Analysis of AI Output For every false positive or benign finding, determine the failure category and drive the fix:
Client condition issues — the detection is technically correct but expected/authorized in this client's environment contribute changes to Client Notes documentation and the client-context agent prompt
-
Detection logic issues — the rule itself is flawed or over-broad contribute changes to Detection documentation and the detection agent prompt
-
Payload / OCSF issues — event normalization, schema mapping, or pipeline parsing errors contribute changes to OCSF/payload/pipeline documentation
-
Asset alignment issues — asset inventory, vulnerability, or hardening context is wrong or stale contribute changes to asset/vulnerability documentation
Knowledge Base & Prompt Engineering Contributions
Author and edit the versioned Markdown knowledge corpus (detections, OCSF mappings, asset context, client notes) that grounds every SitRep the platform generates
-
Propose, test, and sign off on changes to agent prompts before they go to production — your edits are permanent improvements, subject to testing and signoff, not one-off overrides
-
Provide structured feedback (analyst edits, verdict rationale) that feeds our evaluation datasets and judge-model calibration
Reporting & Continuous Improvement
Contribute to weekly triage-outcome reports used by CA Managers to identify systemic detection and content issues
-
Support monthly client-outcome reporting alongside Customer Success
-
Identify recurring failure patterns and propose upstream fixes rather than repeatedly triaging the same class of error
2–5 years in a SOC, MDR/MXDR, incident response, or detection engineering role (Tier 2 equivalent or above)
-
Strong working knowledge of the MITRE ATT&CK framework and the ability to map detections and adversary behavior to techniques
-
Hands-on experience investigating alerts across at least two of: SIEM, EDR, NDR, cloud security telemetry, identity/authentication logs
-
Demonstrated ability to distinguish true positives from false positives and articulate the reasoning in writing — clear, precise written communication is core to this job
-
Familiarity with log formats and event normalization; ability to read raw payloads (JSON, syslog, cloud audit logs) and spot parsing or field-mapping errors
-
Understanding of common detection logic (correlation rules, thresholds, behavioral analytics) and where each tends to generate noise
-
Comfort working in ticketing/case management systems (TheHive, Jira, Linear or similar)
Experience with OCSF (Open Cybersecurity Schema Framework) or other normalization schemas (ECS, CIM)
-
Exposure to LLM-based tooling in security workflows — prompt writing, output evaluation, RAG systems, or AI-assisted triage — or strong curiosity and aptitude to learn it fast
-
Detection engineering experience: writing or tuning rules in Sigma, KQL, Jupyter notebooks, or vendor-native languages
-
Experience writing runbooks, knowledge-base articles, or detection documentation (Markdown fluency a plus)
-
Familiarity with GCP or other cloud environments from an investigation standpoint
-
Scripting ability (Python) for log analysis and triage automation
-
Certifications such as GCIA, GCIH, GCFA, BTL1/BTL2, or CySA+ (valued, not required)
What Makes a Great Fit
Skeptical by default, curious by nature. You don't rubber-stamp AI output, and you don't dismiss it either — you verify, then diagnose
-
Root-cause oriented. Closing a ticket isn't the goal; making the same ticket never appear again is
-
A strong writer. Your notes, corrections, and documentation become the ground truth an AI system reasons from — precision matters
-
Comfortable with feedback loops. You'll see your own triage decisions scored, sampled, and used to improve the system, and you'll help improve the process itself
-
Client-empathetic. Every SitRep lands in front of a customer; you understand that clarity and accuracy are the product
Why This Role Is Different
Most analyst jobs burn people out on repetitive alert triage. Here, repetition is a bug you're empowered to fix. When you identify why a false positive occurred, your correction is tested, signed off, and permanently versioned into the platform — improving output for every client, on every future case. You'll build genuine expertise at the intersection of security operations and applied AI, one of the fastest-growing skill sets in the industry.