Security Analyst I

gruve

Pune District

On-site

INR 600,000 - 900,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Gruve is seeking a Shift Analyst to own end-to-end L1 triage across cloud audit, identity, WAF, and network events, with escalation into L2. The role requires hands-on triage in a SOC/MSSP setting and familiarity with enterprise SIEMs, MITRE ATT&CK methodologies, and ITSM practices.

You will coordinate with NOC for cross-domain events and contribute to runbooks. The ideal candidate has BE/BTech and 2–4 years of SOC experience, strong log fluency across security sources, and a proactive approach

Qualifications

  • BE/BTech (CS/IT/ETC) or equivalent.
  • 2–4 years in a SOC/MSSP environment with hands-on triage ownership.
  • Experience with at least one enterprise SIEM (e.g., Cortex XSIAM, Chronicle, Splunk, Sentinel).
  • MITRE ATT&CK-aligned investigation method; log fluency across firewall, identity, and cloud audit sources.

Responsibilities

  • Triage and investigate detections; correlate across log sources.
  • Execute approved containment steps under authority matrix.
  • Maintain alert-quality feedback and tune detection backlog.
  • Meet MTTA/MTTD SLAs and refresh triage runbooks; coach trainees.
  • Coordinate with NOC on cross-domain events (network vs security incident).

Skills

SOC/MSSP experience
SIEM experience
MITRE ATT&CK
ITSM / ticketing
Written communication

Education

BE/BTech (CS/IT/ETC) or equivalent

Tools

Cortex XSIAM
Chronicle
Splunk
Sentinel

Job description

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position summary:

Shift analyst owning end-to-end L1 triage across the engagement's detection surface - cloud audit (GCP/GKE), identity (Okta), WAF (Cloudflare), network flow (Cilium/Hubble), infrastructure and PKI events - with quality escalations into L2.

Key Roles & Responsibilities:
  • Triage and investigate Exaforce detections; correlate across log sources and enrich with threat intelligence.
  • Execute approved containment steps (block requests, token disablement) under L2/L3 authority matrix.
  • Maintain alert-quality feedback: false-positive tagging and tuning suggestions into the detection backlog.
  • Meet MTTA/MTTD SLAs; keep Linear tickets audit-grade. - Author and refresh triage runbooks; coach trainee analysts on shift.
  • Coordinate with the NOC shift on cross-domain events (network anomaly vs security incident).
Mandatory Qualifications:
  • BE/BTech (CS/IT/E&TC) or equivalent.
  • 2-4 years in a SOC/MSSP environment with hands‑on triage ownership.
  • Working experience on at least one enterprise SIEM (e.g., Cortex XSIAM, Chronicle, Splunk, Sentinel); fast ramp to Exaforce expected.
  • MITRE ATT&CK-aligned investigation method; log fluency across firewall, identity, and cloud audit sources.
  • Disciplined ITSM/ticketing practice and written communication.
Preferred Qualifications:
  • Kubernetes/container security exposure; query skills (KQL/SPL/SQL-style).
  • Monitor and first‑triage Kubernetes/GKE security telemetry - kube‑audit events and Cilium/Hubble flow alerts - distinguishing routine cluster activity from suspicious behaviour per runbooks.
  • Read‑only kubectl fluency for alert validation; KCNA or CKA.
  • Security+, CySA+, or CEH.
  • GCP logging / cloud security fundamentals.
Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you're passionate about technology and eager to make an impact, we'd love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst (Trainee)
SOC Analyst (Trainee)

Gruve • Pune District

On-site
INR 350,000 - 520,000
Threat Hunter Analyst
Threat Hunter Analyst

Gruve • Pune District

On-site
INR 1,000,000 - 1,500,000
Dynamic work environment
Commitment to diversity and inclusion
Senior Security Consultant (Red Hat)
Senior Security Consultant (Red Hat)

Gruve • Maharashtra

Hybrid
INR 4,000,000 - 6,400,000
Senior Pre-Sales Consultant - CyberSecurity
Senior Pre-Sales Consultant - CyberSecurity

Gruve • Mumbai

On-site
INR 1,500,000 - 2,500,000
Dynamic work environment
Inclusive workplace culture
Continuous learning opportunities
Security Consultant
Security Consultant

Gruve • Mumbai City

On-site
INR 800,000 - 1,200,000
Network Consultant - L2
Network Consultant - L2

Gruve • Pune District

On-site
INR 1,200,000 - 1,800,000
OT SOC Analyst L2
OT SOC Analyst L2

Gruve • Maharashtra

On-site
INR 1,200,000 - 2,400,000
Network Consultant II
Network Consultant II

gruve • Pune District

On-site
INR 600,000 - 1,200,000
Senior Security Consultant
Senior Security Consultant

Gruve • Pune District

On-site
INR 1,800,000 - 3,200,000
Network Consultant II
Network Consultant II

Gruve • Maharashtra

On-site
INR 1,800,000 - 3,000,000