Security Analyst II

Summary

The Security Analyst II performs L1 triage and investigation of security events across cloud, identity, and network infrastructure. The role involves maintaining alert quality, managing incident tickets, and collaborating with L2/L3 teams using SIEM tools and threat intelligence.

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position summary:

Shift analyst owning end-to-end L1 triage across the engagement's detection surface — cloud audit (GCP/GKE), identity (Okta), WAF (Cloudflare), network flow (Cilium/Hubble), infrastructure and PKI events — with quality escalations into L2.

Key Roles & Responsibilities:

  • Triage and investigate Exaforce detections; correlate across log sources and enrich with threat intelligence.
  • Execute approved containment steps (block requests, token disablement) under L2/L3 authority matrix.
  • Maintain alert-quality feedback: false-positive tagging and tuning suggestions into the detection backlog.
  • Meet MTTA/MTTD SLAs; keep Linear tickets audit-grade. • Author and refresh triage runbooks; coach trainee analysts on shift.
  • Coordinate with the NOC shift on cross-domain events (network anomaly vs security incident).

Mandatory Qualifications:

  • BE/BTech (CS/IT/E&TC) or equivalent.
  • 2–4 years in a SOC/MSSP environment with hands-on triage ownership.
  • Working experience on at least one enterprise SIEM (e.g., Cortex XSIAM, Chronicle, Splunk, Sentinel); fast ramp to Exaforce expected.
  • MITRE ATT&CK-aligned investigation method; log fluency across firewall, identity, and cloud audit sources.
  • Disciplined ITSM/ticketing practice and written communication.

Preferred Qualifications:

  • Kubernetes/container security exposure; query skills (KQL/SPL/SQL-style).
  • Security+, CySA+, or CEH.
  • GCP logging / cloud security fundamentals.

Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available