Cyber Analyst (India)

Cyber Analyst (India)

29 Aug
|
Outsourced
|
India

29 Aug

Outsourced

India

Company Overview Outsourced is a leading ISO certified global offshore outsourcing company that provides dedicated remote staff to some of the world's leading international companies. Outsourced is recognized as one of the Best Places to Work and has achieved Great Place to Work Certification.

We are committed to providing a positive and supportive work environment where all staff can thrive. As an Outsourced staff member, you will enjoy a fun and friendly working workplace, competitive salaries, opportunities for growth and development, work-life balance, and the chance to share your passion with a team of over 1000 talented professionals.

Position Title: Cyber Analyst

Work Arrangement: Remote - India

About The Role As a Cyber Analyst (CA), you sit at the human-in-the-loop (HITL) checkpoint of our SitRep generation pipeline. You will review AI-generated SitReps — both those flagged by our automated confidence gate and those in routine QA sampling — determine whether the underlying detection is a true or false positive, diagnose why the pipeline got it right or wrong, and drive permanent fixes into the system's knowledge base and agent prompts.

You are the mechanism by which a mistake happens once instead of a thousand times.

Key Responsibilities SitRep Triage & Investigation

- Review AI-generated SitReps in our case management queue (TheHive), including escalations from low-confidence scoring, judge-model failures, and recurring-case matches
- Classify SitReps as False Positive, True Positive / Benign, or True Positive / Approved, using client context, detection logic, raw telemetry, and asset data
- Investigate underlying security events across network, endpoint, cloud, and identity telemetry to validate or refute the AI's findings
- Approve high-quality SitReps for client delivery; correct, annotate, or escalate the rest

Root-Cause Analysis of AI Output For every false positive or benign finding, determine the failure category and drive the fix:





- Client condition issues — the detection is technically correct but expected/authorized in this client's environment → contribute changes to Client Notes documentation and the client-context agent prompt
- Detection logic issues — the rule itself is flawed or over-broad → contribute changes to Detection documentation and the detection agent prompt
- Payload / OCSF issues — event normalization, schema mapping, or pipeline parsing errors → contribute changes to OCSF/payload/pipeline documentation
- Asset alignment issues — asset inventory, vulnerability, or hardening context is wrong or stale → contribute changes to asset/vulnerability documentation

Knowledge Base & Prompt Engineering Contributions

- Author and edit the versioned Markdown knowledge corpus (detections, OCSF mappings, asset context, client notes) that grounds every SitRep the platform generates
- Propose, test, and sign off on changes to agent prompts before they go to production — your edits are permanent improvements, subject to testing and signoff, not one-off overrides
- Provide structured feedback (analyst edits, verdict rationale) that feeds our evaluation datasets and judge-model calibration

Reporting & Continuous Improvement

- Contribute to weekly triage-outcome reports used by CA Managers to identify systemic detection and content issues
- Support monthly client-outcome reporting alongside Customer Success
- Identify recurring failure patterns and propose upstream fixes rather than repeatedly triaging the same class of error.

Preferred Qualification-

- Experience with OCSF (Open Cybersecurity Schema Framework) or other normalization schemas (ECS, CIM)
- Exposure to LLM-based tooling in security workflows — prompt writing, output evaluation, RAG systems,



or AI-assisted triage — or strong curiosity and aptitude to learn it fast
- Detection engineering experience: writing or tuning rules in Sigma, KQL, Jupyter notebooks, or vendor-native languages
- Experience writing runbooks, knowledge-base articles, or detection documentation (Markdown fluency a plus)
- Familiarity with GCP or other cloud environments from an investigation standpoint
- Scripting ability (Python) for log analysis and triage automation
- Certifications such as GCIA, GCIH, GCFA, BTL1/BTL2, or CySA+ (valued, not required)

The Ideal Candidate Will Possess:

- Skeptical by default, curious by nature. You don't rubber-stamp AI output, and you don't dismiss it either — you verify, then diagnose
- Root-cause oriented. Closing a ticket isn't the goal; making the same ticket never appear again is
- A strong writer. Your notes, corrections, and documentation become the ground truth an AI system reasons from — precision matters
- Comfortable with feedback loops. You'll see your own triage decisions scored, sampled, and used to improve the system, and you'll help improve the process itself
- Client-empathetic. Every SitRep lands in front of a customer; you understand that clarity and accuracy are the product

What we Offer

- Health Insurance: We provide medical coverage up to 20 lakh per annum, which covers you, your spouse, and a set of parents. This is available after one month of successful engagement.
- Professional Development: You'll have access to a monthly upskill allowance of ₹5000 for continued education and certifications to support your career growth.
- Leave Policy: Vacation Leave (VL): 10 days per year, available after probation. You can carry over or encash up to 5 unused days.
- Casual Leave (CL): 8 days per year for personal needs or emergencies, available from day one.
- Sick Leave: 12 days per year, available after probation.
- Flexible Work Hours or Remote Work Opportunities - Depending on the role and project.
- Outsourced Benefits such as Paternity Leave, Maternity Leave, etc.

📌 Cyber Analyst (India)
🏢 Outsourced
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber analyst (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: cyber analyst (india) / india