Security Consultant II

Gruve · Pune, Maharashtra, India

Spotted 5m ago
Job description

About this role

Employer-provided description, formatted for easier reading.

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions.

As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position summary

Security Consultant owning VAPT and Red Teaming engagements across infrastructure, network, web, mobile, API, thick-client, cloud and AI/LLM environments. The role involves identifying and exploiting security weaknesses, simulating real-world adversary techniques, developing proof-of-concept exploits, documenting findings and providing clear remediation guidance to technical and business stakeholders.

The consultant will also support purple-team activities, mentor junior resources and contribute to offensive security capability development.

Key responsibilities

  • Perform Vulnerability Assessment and Penetration Testing across infrastructure, network, web, mobile (Android/iOS), API, thick-client and cloud environments (AWS/Azure/GCP).
  • Identify, validate and document vulnerabilities using manual testing techniques and automated security tools; develop PoCs to demonstrate exploitability.
  • Conduct database security testing and configuration reviews across MySQL, Oracle and NoSQL platforms.
  • Plan, execute and document Red Team engagements simulating real-world threat actor TTPs mapped to MITRE ATT&CK.
  • Execute attack chains covering initial access, lateral movement, privilege escalation and data exfiltration.
  • Conduct Active Directory exploitation, phishing/social-engineering campaigns and endpoint security bypass exercises.
  • Use and adapt adversary-emulation tools and frameworks such as Cobalt Strike, Metasploit and Caldera.
  • Collaborate with Blue Teams during purple-team exercises to validate and improve detection and response capabilities.
  • Perform security testing of AI/ML and LLM-based applications, including prompt injection, jailbreak, model extraction and adversarial-input testing.
  • Apply relevant AI security frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS to identify AI-specific risks.
  • Prepare detailed technical reports covering assessment methodology, vulnerabilities, severity, evidence, PoCs and remediation recommendations.
  • Present security findings and risk implications clearly to technical teams, management and business stakeholders.
  • Stay current with emerging vulnerabilities, APT techniques, malware trends and offensive-security research and incorporate relevant techniques into assessments.
  • Mentor junior consultants on penetration-testing tools, techniques and methodologies and contribute to internal security capability building.

Mandatory Qualifications:

  • 3–6 years of hands-on experience in VAPT, Red Teaming and Application Security, including client-facing or security advisory exposure.
  • Strong understanding of OWASP Top 10, OSSTMM, NIST and CIS security frameworks.
  • Solid understanding of networking fundamentals, including OSI and TCP/IP, and network/infrastructure security.
  • Hands-on experience with penetration-testing and vulnerability-assessment tools such as Burp Suite Pro, Nessus, Nmap, Metasploit, Kali Linux, Nikto, ZAP and MobSF.
  • Ability to perform manual penetration testing beyond automated scanner capabilities.
  • Working experience with scripting and exploit development using Python, Bash or PowerShell.
  • Working knowledge of security assessment across AWS, Azure and/or GCP environments.
  • Strong analytical, technical documentation, report-writing and client communication skills.
  • BE/B.Tech/MCA or equivalent qualification.
  • Ability to communicate security risks and remediation requirements effectively with technical and business stakeholders.

Preferred Qualifications

  • OSCP, OSCE, CRTP, eWPTX, CREST-CRT or Security+ certification.
  • Hands-on exposure to AI/LLM security testing and frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Experience with advanced Red Teaming and adversary-emulation techniques.
  • Exposure to Active Directory exploitation, phishing/social engineering and endpoint bypass techniques.
  • Experience participating in purple-team engagements and working with Blue/SOC teams.

Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Interested in this role?Continue on Gruve's careers page.
Apply on Gruve