Gruve
Gruve

Security Analyst I

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position summary:

Shift analyst owning end-to-end L1 triage across the security detection surface — cloud audit logs, Kubernetes/OpenShift, identity provider, WAF, container network-flow telemetry, infrastructure and PKI events — and L1 for PulseAI Managed Services: 24×7 monitoring of the PulseAI platform, OpenShift cluster and customer GPU infrastructure, acknowledgement within tier SLA, first-level diagnostics, and vendor case creation for confirmed hardware faults.

Key Roles & Responsibilities:

  • Triage and investigate SIEM detections; correlate across log sources and enrich with threat intelligence.
  • Execute approved containment steps (block requests, token disablement) under the L2/L3 authority matrix.
  • Maintain alert-quality feedback: false-positive tagging and tuning suggestions into the detection backlog.
  • Monitor PulseAI platform health — control plane, authentication/authorisation, tenancy and quota enforcement, admin interface/API, observability services — and OpenShift cluster health (nodes, operators, pods, storage) from the observability stack; acknowledge Severity 1–4 incidents within the customer's tier clocks (Sev 1 in 15–30 minutes).
  • Perform first-level diagnostics on PulseAI, OpenShift and GPU-node alerts: review platform, control-plane and workload logs and Grafana panels, distinguish platform faults from hardware, network, storage or customer-workload issues, and classify severity per the SLA definitions.
  • Detect and confirm hardware faults on GPU servers, control-plane/infrastructure nodes, supported switches and storage; open the vendor case (OEM, neocloud provider or storage vendor) within the tier window (60/30 minutes), record the case reference, and track status until closure.
  • Provide Severity 1/2 status updates at the SLA cadence; keep ITSM tickets audit-grade so SLA reports and availability calculations can be produced from them.
  • Author and refresh triage runbooks; coach trainee analysts on shift; coordinate with the NOC shift on cross-domain events.

Mandatory Qualifications:

  • BE/BTech (CS/IT/E&TC) or equivalent.
  • 2–4 years in a SOC/MSSP or 24×7 managed-operations environment with hands-on triage ownership.
  • Working experience on at least one enterprise SIEM platform; fast ramp to the engagement's AI-driven SIEM/SOAR stack expected.
  • MITRE ATT&CK-aligned investigation method; log fluency across firewall, identity, and cloud audit sources.
  • Monitor and first-triage Kubernetes/GKE security telemetry — kube-audit events and Cilium/Hubble flow alerts — distinguishing routine cluster activity from suspicious behaviour per runbooks.
  • Working Kubernetes/OpenShift operations basics — kubectl/oc for read-only investigation (pod and node status, events, logs, describe), namespaces, operators — and comfort reading Grafana dashboards and platform logs.
  • Understanding of GPU-server health basics (node inventory, GPU type/count detection, utilisation, memory, thermal) and of what constitutes a hardware fault versus a platform fault.
  • Disciplined ITSM/ticketing practice and written communication; ability to run a vendor support case end to end.

Preferred Qualifications:

  • SIEM query-language skills (SQL-style / vendor query languages).
  • Read-only kubectl fluency for alert validation; KCNA or CKA.
  • Red Hat OpenShift exposure (DO180-level or equivalent); GPU-node monitoring exposure (DCGM-class exporters, NVIDIA GPU Operator).
  • Exposure to switch telemetry (SNMP, syslog, streaming telemetry) and storage health monitoring.
  • Intermediate security certification (e.g., CySA+, CEH or equivalent); cloud audit logging / cloud security fundamentals.

Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Gruve is a software services startup that empowers enterprises to become AI-driven organizations. We provide specialized expertise in cybersecurity, customer experience, and cloud infrastructure, utilizing advanced technologies such as Large Language Models to enable smarter, data-informed decision-making for our clients.

Founded
Founded 2024
Employees
201-500 employees
Industry
information technology and services
Funding stage
Series A
Total raised
$88M raised
Last funding
Raised February 2026
View company profile