About Gruve
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic setting with strong customer and partner networks.
Position summary:
Security Consultant owning VAPT and Red Teaming engagements across infrastructure, network, web, mobile, API, thick-client, cloud and AI/LLM environments. The role involves identifying and exploiting security weaknesses, simulating real-world adversary techniques, developing proof-of-concept exploits, documenting findings and providing clear remediation guidance to technical and business stakeholders. The consultant will also support purple-team activities, mentor junior resources and contribute to offensive security capability development.
Key responsibilities:
- Perform Vulnerability Assessment and Penetration Testing across infrastructure, network, web, mobile (Android/iOS), API, thick-client and cloud environments (AWS/Azure/GCP).
- Identify, validate and document vulnerabilities using manual testing techniques and automated security tools; develop PoCs to demonstrate exploitability.
- Conduct database security testing and configuration reviews across MySQL, Oracle and NoSQL platforms.
- Plan, execute and document Red Team engagements simulating real-world threat actor TTPs mapped to MITRE ATT&CK.;
- Execute attack chains covering initial access, lateral movement, privilege escalation and data exfiltration.
- Conduct Active Directory exploitation, phishing/social-engineering campaigns and endpoint security bypass exercises.
- Use and adapt adversary-emulation tools and frameworks such as Cobalt Strike, Metasploit and Caldera.
- Collaborate with Blue Tea
📌 Security Consultant II (Pune)
🏢 Gruve
📍 Pune