Security Analyst II
Summary
The Security Analyst II performs L1 triage and investigation of security events across cloud, identity, and network infrastructure. The role involves maintaining alert quality, managing incident tickets, and collaborating with L2/L3 teams using SIEM tools and threat intelligence.
About Gruve
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.
Position summary:
Shift analyst owning end-to-end L1 triage across the engagement's detection surface — cloud audit (GCP/GKE), identity (Okta), WAF (Cloudflare), network flow (Cilium/Hubble), infrastructure and PKI events — with quality escalations into L2.
Key Roles & Responsibilities:
- Triage and investigate Exaforce detections; correlate across log sources and enrich with threat intelligence.
- Execute approved containment steps (block requests, token disablement) under L2/L3 authority matrix.
- Maintain alert-quality feedback: false-positive tagging and tuning suggestions into the detection backlog.
- Meet MTTA/MTTD SLAs; keep Linear tickets audit-grade. • Author and refresh triage runbooks; coach trainee analysts on shift.
- Coordinate with the NOC shift on cross-domain events (network anomaly vs security incident).
Mandatory Qualifications:
- BE/BTech (CS/IT/E&TC) or equivalent.
- 2–4 years in a SOC/MSSP environment with hands-on triage ownership.
- Working experience on at least one enterprise SIEM (e.g., Cortex XSIAM, Chronicle, Splunk, Sentinel); fast ramp to Exaforce expected.
- MITRE ATT&CK-aligned investigation method; log fluency across firewall, identity, and cloud audit sources.
- Disciplined ITSM/ticketing practice and written communication.
Preferred Qualifications:
- Kubernetes/container security exposure; query skills (KQL/SPL/SQL-style).
- Security+, CySA+, or CEH.
- GCP logging / cloud security fundamentals.
Why Gruve
At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.
Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
- Preferred First Name optional
- This role requires to work in 24*7 rotational shift (Including Night Shifts), Are you comfortable for this? choose one
- Are you willing to relocate to Pune or comfortable for working from Baner, Pune? choose one
- LinkedIn Profile optional
- What is your current notice period?
- What is your current CTC?
- What are your salary expectations for this role?
- What is your current address?
- I acknowledge my right to refrain from disclosing any confidential or proprietary information during the interview and understand that the company will not solicit such information, in accordance with the Non-Disclosure Agreement choose one
- I consent to the use of AI-powered note-taking tools during the interview process and acknowledge that the interview may be recorded and stored for evaluation purposes. choose one
- I hereby provide my consent to share my professional referees with Gruve and authorize Gruve, or its designated third-party representative, to contact them for the purpose of conducting business reference checks as part of the hiring process. choose one