Cyber Analyst (CA)

Zymr Systems

Ahmedabad District

On-site

INR 750,000 - 1,200,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Zymr Systems is seeking a Cyber Analyst - AI-Assisted MXDR Operations to join our security operations team in Pune/Ahmedabad. You will review AI-generated SitReps, determine true/false positives, and drive fixes into our knowledge base and prompts.

In this role you triage and investigate SitReps from TheHive, classify findings, and validate detections across network, endpoint, cloud, and identity telemetry. You will author structured feedback and contribute to process improvements.

Qualifications

  • 2–5 years in a SOC/MDR/MXDR, incident response, or detection engineering.
  • Strong knowledge of MITRE ATT&CK and mapping detections to techniques.
  • Hands-on experience investigating alerts across at least two of: SIEM, EDR, NDR, cloud security telemetry, identity logs.
  • Ability to distinguish true positives from false positives and articulate the reasoning in writing.
  • Familiarity with log formats and event normalization; read JSON/syslog/cloud logs.
  • Understanding of detection logic: correlations, thresholds, behavioral analytics.
  • Experience with ticketing systems like TheHive, Jira, or Linear.

Responsibilities

  • SitRep triage and investigation in case management queue.
  • Classify SitReps as FP, TP/Benign, or TP/Approved.
  • Investigate security events across network, endpoint, cloud, and identity telemetry.
  • Approve high-quality SitReps for client delivery and annotate others.

Skills

SOC/MDR/MXDR experience
MITRE ATT&CK
Investigating alerts across multiple🔥(
True/False positive reasoning
Log formats & normalization
Detection logic understanding
Ticketing systems (TheHive/Jira/Linear

Tools

TheHive
Jira
Linear

Job description

As a Cyber Analyst (CA), you sit at the human-in-the-loop (HITL) checkpoint of our SitRep generation pipeline. You will review AI-generated SitReps - both those flagged by our automated confidence gate and those in routine QA sampling - determine whether the underlying detection is a true or false positive, diagnose why the pipeline got it right or wrong, and drive permanent fixes into the systems knowledge base and agent prompts.

You are the mechanism by which a mistake happens once instead of a thousand times

Job Title: Cyber Analyst - AI-Assisted MXDR Operations

Location: Pune/Ahmedabad

Key Responsibilities
  • SitRep Triage & Investigation - Review AI-generated SitReps in our case management queue (TheHive), including escalations from low-confidence scoring, judge-model failures, and recurring-case matches
  • Classify SitReps as False Positive, True Positive / Benign, or True Positive / Approved, using client context, detection logic, raw telemetry, and asset data
  • Investigate underlying security events across network, endpoint, cloud, and identity telemetry to validate or refute the AI's findings
  • Approve high-quality SitReps for client delivery; correct, annotate, or elevate the rest
Root-Cause Analysis of AI Output

For every false positive or benign finding, determine the failure category and drive the fix:

  • Client condition issues - the detection is technically correct but expected/authorized in this clients environment contribute changes to Client Notes documentation and the client-context agent prompt
  • Detection logic issues - the rule itself is flawed or over-broad contribute changes to Detection documentation and the detection agent prompt
  • Payload / OCSF issues - event normalization, schema mapping, or pipeline parsing errors contribute changes to OCSF/payload/pipeline documentation
  • Asset alignment issues - asset inventory, vulnerability, or hardening context is wrong or stale contribute changes to asset/vulnerability documentation
Knowledge Base & Prompt Engineering Contributions
  • Author and edit the versioned Markdown knowledge corpus (detections, OCSF mappings, asset context, client notes) that grounds every SitRep the platform generates
  • Propose, test, and sign off on changes to agent prompts before they go to production - your edits are permanent improvements, subject to testing and signoff, not one-off overrides
  • Provide structured feedback (analyst edits, verdict rationale) that feeds our evaluation datasets and judge-model calibration
Reporting & Continuous Improvement
  • Contribute to weekly triage-outcome reports used by CA Managers to identify systemic detection and content issues
  • Support monthly client-outcome reporting alongside Customer Success
  • Identify recurring failure patterns and propose upstream fixes rather than repeatedly triaging the same class of error

Required Qualifications

  • 2-5 years in a SOC, MDR/MXDR, incident response, or detection engineering role (Tier 2 equivalent or above)
  • Strong working knowledge of the MITRE ATT&CK framework and the ability to map detections and adversary behavior to techniques
  • Hands‑on experience investigating alerts across at least two of: SIEM, EDR, NDR, cloud security telemetry, identity/authentication logs
  • Demonstrated ability to distinguish true positives from false positives and articulate the reasoning in writing - clear, precise written communication is core to this job
  • Familiarity with log formats and event normalization; ability to read raw payloads (JSON, syslog, cloud audit logs) and spot parsing or field-mapping errors
  • Understanding of common detection logic (correlation rules, thresholds, behavioral analytics) and where each tends to generate noise
  • Comfort working in ticketing/case management systems (TheHive, Jira, Linear or similar)
Preferred Qualifications
  • Experience with OCSF (Open Cybersecurity Schema Framework) or other normalization schemas (ECS, CIM)
  • Exposure to LLM-based tooling in security workflows - prompt writing, output evaluation, RAG systems, or AI-assisted triage - or strong curiosity and aptitude to learn it fast
  • Detection engineering experience: writing or tuning rules in Sigma, KQL, Jupyter notebooks, or vendor-native languages
  • Experience writing runbooks, knowledge-base articles, or detection documentation (Markdown fluency a plus)
  • Familiarity with GCP or other cloud environments from an investigation standpoint
  • Scripting ability (Python) for log analysis and triage automation
  • Certifications such as GCIA, GCIH, GCFA, BTL1/BTL2, or CySA+ (valued, not required)
What Makes a Great Fit
  • Skeptical by default, curious by nature. You dont rubber-stamp AI output, and you dont dismiss it either - you verify, then diagnose
  • Root‑cause oriented. Closing a ticket isnt the goal

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Analyst (CA)
Cyber Analyst (CA)

Zymr Systems • Pune District

On-site
INR 900,000 - 1,500,000
Cyber Analyst (Bangalore)
Cyber Analyst (Bangalore)

Zymr Systems • Bangalore Rural

On-site
INR 1,200,000 - 2,000,000
Cyber Analyst — AI-Assisted MXDR Operations
Cyber Analyst — AI-Assisted MXDR Operations

Outsourced • Bangalore Rural

On-site
INR 650,000 - 1,200,000
Managed Services Analyst, MXDR
Managed Services Analyst, MXDR

Check Point Software • Bengaluru

On-site
INR 800,000 - 1,400,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
AI Detection Engineer - SOC Analyst IV
AI Detection Engineer - SOC Analyst IV

Ten Eleven Ventures • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Security Engineer
Security Engineer

AppViewX • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Managed Services Analyst, MXDR
Managed Services Analyst, MXDR

Check Point Software • Bengaluru Urban

On-site
INR 1,200,000 - 1,500,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work