The Role
As a Cyber Analyst (CA), you sit at the human-in-the-loop (HITL) checkpoint of our SitRep generation pipeline. You will review AI-generated SitReps both those flagged by our automated confidence gate and those in routine QA sampling determine whether the underlying detection is a true or false positive, diagnose why the pipeline got it right or wrong, and drive permanent fixes into the system's knowledge base and agent prompts.
You are the mechanism by which a mistake happens once instead of a thousand times.
What You'll Do
SitRep Triage & Investigation
- Review AI-generated SitReps in our case management queue (TheHive), including escalations from low-confidence scoring, judge-model failures, and recurring-case matches
- Classify SitReps as False Positive, True Positive / Benign, or True Positive / Approved, using client context, detection logic, raw telemetry, and asset data
- Investigate underlying security events across network, endpoint, cloud, and identity telemetry to validate or refute the AI's findings
- Approve high-quality SitReps for client delivery; correct,
annotate, or escalate the rest
Root-Cause Analysis of AI Output For every false positive or benign finding, determine the failure category and drive the fix:
- Client condition issues the detection is technically correct but expected/authorized in this client's workplace contribute changes to Client Notes documentation and the client-context agent prompt
- Detection logic issues — the rule itself is flawed or over-broad contribute changes to Detection documentation and the detection agent prompt
- Payload / OCSF issues — event normalization, schema mapping, or pipeline parsing errors contribute changes to OCSF/payload/pipeline documentation
- Asset alignment issues — asset inventory, vulnerability, or hardening context is wrong or stale contribute changes to asset/vulnerability documentation
Knowledge Base & Prompt Engineering Contributions
- Author and edit the versioned Markdown kno