Security Consultant II

gruveΒ· Solution Delivery
Apply Now β†—
πŸ“ Pune, Maharashtra, India

About this role

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position summary:

Security Consultant owning VAPT and Red Teaming engagements across infrastructure, network, web, mobile, API, thick-client, cloud and AI/LLM environments. The role involves identifying and exploiting security weaknesses, simulating real-world adversary techniques, developing proof-of-concept exploits, documenting findings and providing clear remediation guidance to technical and business stakeholders. The consultant will also support purple-team activities, mentor junior resources and contribute to offensive security capability development.

Key responsibilities:

  • Perform Vulnerability Assessment and Penetration Testing across infrastructure, network, web, mobile (Android/iOS), API, thick-client and cloud environments (AWS/Azure/GCP).
  • Identify, validate and document vulnerabilities using manual testing techniques and automated security tools; develop PoCs to demonstrate exploitability.
  • Conduct database security testing and configuration reviews across MySQL, Oracle and NoSQL platforms.
  • Plan, execute and document Red Team engagements simulating real-world threat actor TTPs mapped to MITRE ATT&CK.
  • Execute attack chains covering initial access, lateral movement, privilege escalation and data exfiltration.
  • Conduct Active Directory exploitation, phishing/social-engineering campaigns and endpoint security bypass exercises.
  • Use and adapt adversary-emulation tools and frameworks such as Cobalt Strike, Metasploit and Caldera.
  • Collaborate with Blue Teams during purple-team exercises to validate and improve detection and response capabilities.
  • Perform security testing of AI/ML and LLM-based applications, including prompt injection, jailbreak, model extraction and adversarial-input testing.
  • Apply relevant AI security frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS to identify AI-specific risks.
  • Prepare detailed technical reports covering assessment methodology, vulnerabilities, severity, evidence, PoCs and remediation recommendations.
  • Present security findings and risk implications clearly to technical teams, management and business stakeholders.
  • Stay current with emerging vulnerabilities, APT techniques, malware trends and offensive-security research and incorporate relevant techniques into assessments.
  • Mentor junior consultants on penetration-testing tools, techniques and methodologies and contribute to internal security capability building.

Mandatory Qualifications:

  • 3–6 years of hands-on experience in VAPT, Red Teaming and Application Security, including client-facing or security advisory exposure.
  • Strong understanding of OWASP Top 10, OSSTMM, NIST and CIS security frameworks.
  • Solid understanding of networking fundamentals, including OSI and TCP/IP, and network/infrastructure security.
  • Hands-on experience with penetration-testing and vulnerability-assessment tools such as Burp Suite Pro, Nessus, Nmap, Metasploit, Kali Linux, Nikto, ZAP and MobSF.
  • Ability to perform manual penetration testing beyond automated scanner capabilities.
  • Working experience with scripting and exploit development using Python, Bash or PowerShell.
  • Working knowledge of security assessment across AWS, Azure and/or GCP environments.
  • Strong analytical, technical documentation, report-writing and client communication skills.
  • BE/B.Tech/MCA or equivalent qualification.
  • Ability to communicate security risks and remediation requirements effectively with technical and business stakeholders.

Preferred Qualifications:

  • OSCP, OSCE, CRTP, eWPTX, CREST-CRT or Security+ certification.
  • Hands-on exposure to AI/LLM security testing and frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Experience with advanced Red Teaming and adversary-emulation techniques.
  • Exposure to Active Directory exploitation, phishing/social engineering and endpoint bypass techniques.
  • Experience participating in purple-team engagements and working with Blue/SOC teams.

Β 

Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Frequently Asked Questions

Is the salary disclosed for the Security Consultant II position at gruve?
The salary for this Security Consultant II role at gruve is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Security Consultant II position at gruve located?
This Security Consultant II role at gruve is based in Pune, Maharashtra, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Which team or department does the Security Consultant II at gruve belong to?
This Security Consultant II position is part of the Solution Delivery department at gruve. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Security Consultant II position at gruve?
Click the "Apply Now" button on this page. You will be redirected to gruve's official application portal hosted on greenhouse where you can submit your application directly.
When was the Security Consultant II job at gruve posted?
This Security Consultant II position at gruve was posted on Sep 17, 2026. Apply as soon as possible β€” early applications are often reviewed first.
Security Consultant II
gruve
Apply for this role β†—

You'll be redirected to gruve's official application page on Greenhouse.