Cyber Analyst — AI-Assisted MXDR Operations

Outsourced

Bangalore Rural

On-site

INR 650,000 - 1,200,000

Full time

10 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Outsourced is seeking an experienced Cyber Analyst to join our MXDR environment in Bangalore. You will review AI-generated investigations, validate detections, and help improve detection logic and AI prompts. Shift pattern is office-based Mon-Thu with Friday night WFH.

You will classify findings, investigate across network, endpoint, cloud, and identity telemetry, and contribute to knowledge-base documentation and ongoing client reporting.

Qualifications

  • 2-5 years of experience in a SOC, MDR/MXDR, Incident Response, or Detection Engineering environment.
  • Strong knowledge of the MITRE ATT&CK framework and mapping detections to techniques.
  • Hands-on investigation across at least two: SIEM, EDR, NDR, Cloud security telemetry, or Identity/authentication logs.
  • Ability to distinguish true positives from false positives and document reasoning clearly.
  • Understanding of log normalization, parsing, and field mapping.
  • Excellent written communication to document findings and rationale.
  • Experience with case management tools such as TheHive, Jira, Linear, or similar.
  • Comfortable working from the Bangalore office Monday-Thursday and Friday night shift from home.

Responsibilities

  • Review and validate AI-generated security investigation reports and escalated cases.
  • Classify security findings as False Positive, True Positive / Benign, or True Positive / Approved.
  • Investigate security events across network, endpoint, cloud, and identity telemetry.
  • Analyze raw logs and event payloads to validate AI-generated findings.
  • Identify the root cause of false positives, including detection logic, client-specific conditions, payload/schema mapping, and asset-context issues.
  • Review, correct, annotate, approve, or elevate security investigation reports as appropriate.
  • Contribute to improvements in detection rules, security documentation, client context, and event normalization.
  • Author and maintain knowledge-base documentation used to support AI-assisted investigations.
  • Provide structured feedback to improve AI evaluation datasets and model accuracy.
  • Identify recurring detection issues and recommend permanent upstream fixes.
  • Contribute to weekly operational reporting and monthly client-outcome reporting.

Skills

MITRE ATT&CK
Threat investigation
Data analysis
Clear written communication
Security awareness

Tools

SIEM
EDR
NDR
Cloud telemetry
Identity logs

Job description

Work Arrangement: Office-based Monday-Thursday | Work from Home on Friday

  • Monday-Thursday: 12:00 PM - 9:00 PM IST
  • Friday: Night shift starting at approximately 7:30 PM-8:00 PM IST | WFH

We are looking for an experienced Cyber Analyst to join an AI-driven Managed Extended Detection and Response (MXDR) environment.

This is not a traditional SOC role focused solely on alert triage. You will work at the intersection of cybersecurity operations and applied AI, reviewing AI-generated security investigations, validating detections, identifying false positives, and helping improve the underlying detection logic, knowledge base, and AI prompts.

Your analysis and feedback will directly contribute to improving the accuracy and reliability of the security platform.

Key Responsibilities
  • Review and validate AI-generated security investigation reports and escalated cases.
  • Classify security findings as False Positive, True Positive / Benign, or True Positive / Approved.
  • Investigate security events across network, endpoint, cloud, and identity telemetry.
  • Analyze raw logs and event payloads to validate AI-generated findings.
  • Identify the root cause of false positives, including detection logic, client-specific conditions, payload/schema mapping, and asset-context issues.
  • Review, correct, annotate, approve, or elevate security investigation reports as appropriate.
  • Contribute to improvements in detection rules, security documentation, client context, and event normalization.
  • Author and maintain knowledge-base documentation used to support AI-assisted investigations.
  • Provide structured feedback to improve AI evaluation datasets and model accuracy.
  • Identify recurring detection issues and recommend permanent upstream fixes.
  • Contribute to weekly operational reporting and monthly client-outcome reporting.
Must-Haves
  • 2-5 years of experience in a SOC, MDR/MXDR, Incident Response, or Detection Engineering environment, ideally at Tier 2 level or above.
  • Strong knowledge of the MITRE ATT&CK framework, including mapping detections and adversary activity to relevant techniques.
  • Hands-on investigation experience across at least two of the following: (SIEM, EDR, NDR, Cloud security telemetry, Identity/authentication logs)
  • Strong ability to investigate alerts and distinguish true positives from false positives.
  • Understanding of common security detection methods, including correlation rules, thresholds, and behavioral analytics.
  • Experience reviewing raw security logs and payloads such as JSON, syslog, and cloud audit logs.
  • Understanding of log normalization, parsing, and field mapping, including the ability to identify data-quality or mapping issues.
  • Strong written communication skills with the ability to clearly document investigation findings and reasoning.
  • Experience using case management or ticketing platforms such as TheHive, Jira, Linear, or similar.
  • Comfortable working from the Bangalore office Monday-Thursday and the required Friday night shift from home.
Nice-to-Haves
  • Experience with OCSF (Open Cybersecurity Schema Framework), ECS, CIM, or similar security normalization schemas.
  • Exposure to AI/LLM-assisted cybersecurity workflows, including prompt writing, AI output evaluation, RAG systems, or AI-assisted triage.
  • Detection engineering experience using Sigma, KQL, Jupyter notebooks, or vendor-specific detection languages.
  • Experience creating or maintaining security runbooks, knowledge-base articles, or detection documentation.
  • Markdown knowledge.
  • Experience investigating security events in GCP or other cloud environments.
  • Python scripting for log analysis, investigation, or security automation.
  • Relevant certifications such as GCIA, GCIH, GCFA, BTL1/BTL2, or CySA+.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Managed Services Analyst, MXDR
Managed Services Analyst, MXDR

Check Point Software • Bengaluru

On-site
INR 800,000 - 1,400,000
Managed Services Analyst, MXDR
Managed Services Analyst, MXDR

Check Point Software • Bengaluru Urban

On-site
INR 1,200,000 - 1,500,000
Cyber Security Analyst
Cyber Security Analyst

Sunrise Biztech Systems • Hyderabad

On-site
INR 1,800,000 - 2,800,000
Managed Services Analyst, MXDR (Night Shift)
Managed Services Analyst, MXDR (Night Shift)

Check Point Software • Bengaluru

On-site
INR 900,000 - 1,500,000
Cyber Analyst.
Cyber Analyst.

Cortex Consultants LLC • Chennai

On-site
INR 1,500,000 - 2,500,000
Cyber Security Analyst
Cyber Security Analyst

Genpact • Dadri, Hyderabad, Bangalore Rural

Hybrid
INR 900,000 - 1,500,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Chief Analyst, Cyber Security Operations
Chief Analyst, Cyber Security Operations

SES S.A Brazil • Chennai District

On-site
INR 1,200,000 - 3,000,000
Senior Cyber Threat Engineer
Senior Cyber Threat Engineer

YO IT Consulting • Maharashtra

On-site
INR 1,200,000 - 2,000,000
AI Cybersecurity Analyst
AI Cybersecurity Analyst

Cyber MSI • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Health insurance
Laptop
Internet allowance
+5