Work Arrangement: Office-based Monday-Thursday | Work from Home on Friday
- Monday-Thursday: 12:00 PM - 9:00 PM IST
- Friday: Night shift starting at approximately 7:30 PM-8:00 PM IST | WFH
We are looking for an experienced Cyber Analyst to join an AI-driven Managed Extended Detection and Response (MXDR) environment.
This is not a traditional SOC role focused solely on alert triage. You will work at the intersection of cybersecurity operations and applied AI, reviewing AI-generated security investigations, validating detections, identifying false positives, and helping improve the underlying detection logic, knowledge base, and AI prompts.
Your analysis and feedback will directly contribute to improving the accuracy and reliability of the security platform.
Key Responsibilities
- Review and validate AI-generated security investigation reports and escalated cases.
- Classify security findings as False Positive, True Positive / Benign, or True Positive / Approved.
- Investigate security events across network, endpoint, cloud, and identity telemetry.
- Analyze raw logs and event payloads to validate AI-generated findings.
- Identify the root cause of false positives, including detection logic, client-specific conditions, payload/schema mapping, and asset-context issues.
- Review, correct, annotate, approve, or elevate security investigation reports as appropriate.
- Contribute to improvements in detection rules, security documentation, client context, and event normalization.
- Author and maintain knowledge-base documentation used to support AI-assisted investigations.
- Provide structured feedback to improve AI evaluation datasets and model accuracy.
- Identify recurring detection issues and recommend permanent upstream fixes.
- Contribute to weekly operational reporting and monthly client-outcome reporting.
Must-Haves
- 2-5 years of experience in a SOC, MDR/MXDR, Incident Response, or Detection Engineering environment, ideally at Tier 2 level or above.
- Strong knowledge of the MITRE ATT&CK framework, including mapping detections and adversary activity to relevant techniques.
- Hands-on investigation experience across at least two of the following: (SIEM, EDR, NDR, Cloud security telemetry, Identity/authentication logs)
- Strong ability to investigate alerts and distinguish true positives from false positives.
- Understanding of common security detection methods, including correlation rules, thresholds, and behavioral analytics.
- Experience reviewing raw security logs and payloads such as JSON, syslog, and cloud audit logs.
- Understanding of log normalization, parsing, and field mapping, including the ability to identify data-quality or mapping issues.
- Strong written communication skills with the ability to clearly document investigation findings and reasoning.
- Experience using case management or ticketing platforms such as TheHive, Jira, Linear, or similar.
- Comfortable working from the Bangalore office Monday-Thursday and the required Friday night shift from home.
Nice-to-Haves
- Experience with OCSF (Open Cybersecurity Schema Framework), ECS, CIM, or similar security normalization schemas.
- Exposure to AI/LLM-assisted cybersecurity workflows, including prompt writing, AI output evaluation, RAG systems, or AI-assisted triage.
- Detection engineering experience using Sigma, KQL, Jupyter notebooks, or vendor-specific detection languages.
- Experience creating or maintaining security runbooks, knowledge-base articles, or detection documentation.
- Markdown knowledge.
- Experience investigating security events in GCP or other cloud environments.
- Python scripting for log analysis, investigation, or security automation.
- Relevant certifications such as GCIA, GCIH, GCFA, BTL1/BTL2, or CySA+.