NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Cybersecurity Consultant in India
3 days ago
Apply with autofill
Apply with autofill
Gruve·3 days ago
3 days ago

Security Consultant II

Pune, IndiaContractMid · 3-6 yearsCybersecurity Consultant

Sign up free to see how well your resume matches this role.

Boost your chances at gruve

How you compare FREE

?
Your scoreYour score: not yet known
→
58
Top 10%Top 10%: 58 out of 100

Top 10% of NextRaise users matched against Cybersecurity Consultant roles in India.

Must-have skills for this role

  • vapt
  • red teaming
  • penetration testing
  • application security

PDF or DOCX · no account needed

Apply faster with autofill FREEgruve uses Greenhouse - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Perform Vulnerability Assessment and Penetration Testing across infrastructure, network, web, mobile (Android/iOS), API, thick-client and cloud environments (AWS/Azure/GCP).
  • Identify, validate and document vulnerabilities using manual testing techniques and automated security tools; develop PoCs to demonstrate exploitability.
  • Conduct database security testing and configuration reviews across MySQL, Oracle and NoSQL platforms.
  • Plan, execute and document Red Team engagements simulating real-world threat actor TTPs mapped to MITRE ATT&CK.
  • Execute attack chains covering initial access, lateral movement, privilege escalation and data exfiltration.
  • Conduct Active Directory exploitation, phishing/social-engineering campaigns and endpoint security bypass exercises.
  • Use and adapt adversary-emulation tools and frameworks such as Cobalt Strike, Metasploit and Caldera.
  • Collaborate with Blue Teams during purple-team exercises to validate and improve detection and response capabilities.
  • Perform security testing of AI/ML and LLM-based applications, including prompt injection, jailbreak, model extraction and adversarial-input testing.
  • Apply relevant AI security frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS to identify AI-specific risks.
  • Prepare detailed technical reports covering assessment methodology, vulnerabilities, severity, evidence, PoCs and remediation recommendations.
  • Present security findings and risk implications clearly to technical teams, management and business stakeholders.

What they're looking for

  • 3–6 years of hands-on experience in VAPT, Red Teaming and Application Security, including client-facing or security advisory exposure.
  • Strong understanding of OWASP Top 10, OSSTMM, NIST and CIS security frameworks.
  • Solid understanding of networking fundamentals, including OSI and TCP/IP, and network/infrastructure security.
  • Hands-on experience with penetration-testing and vulnerability-assessment tools such as Burp Suite Pro, Nessus, Nmap, Metasploit, Kali Linux, Nikto, ZAP and MobSF.
  • Ability to perform manual penetration testing beyond automated scanner capabilities.
  • Working experience with scripting and exploit development using Python, Bash or PowerShell.
  • Working knowledge of security assessment across AWS, Azure and/or GCP environments.
  • Strong analytical, technical documentation, report-writing and client communication skills.
  • BE/B.Tech/MCA or equivalent qualification.
  • Ability to communicate security risks and remediation requirements effectively with technical and business stakeholders.

Nice to have

  • OSCP, OSCE, CRTP, eWPTX, CREST-CRT or Security+ certification.
  • Hands-on exposure to AI/LLM security testing and frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Experience with advanced Red Teaming and adversary-emulation techniques.
  • Exposure to Active Directory exploitation, phishing/social engineering and endpoint bypass techniques.
  • Experience participating in purple-team engagements and working with Blue/SOC teams.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position summary:

Security Consultant owning VAPT and Red Teaming engagements across infrastructure, network, web, mobile, API, thick-client, cloud and AI/LLM environments. The role involves identifying and exploiting security weaknesses, simulating real-world adversary techniques, developing proof-of-concept exploits, documenting findings and providing clear remediation guidance to technical and business stakeholders. The consultant will also support purple-team activities, mentor junior resources and contribute to offensive security capability development.

Key responsibilities:

  • Perform Vulnerability Assessment and Penetration Testing across infrastructure, network, web, mobile (Android/iOS), API, thick-client and cloud environments (AWS/Azure/GCP).
  • Identify, validate and document vulnerabilities using manual testing techniques and automated security tools; develop PoCs to demonstrate exploitability.
  • Conduct database security testing and configuration reviews across MySQL, Oracle and NoSQL platforms.
  • Plan, execute and document Red Team engagements simulating real-world threat actor TTPs mapped to MITRE ATT&CK.
  • Execute attack chains covering initial access, lateral movement, privilege escalation and data exfiltration.
  • Conduct Active Directory exploitation, phishing/social-engineering campaigns and endpoint security bypass exercises.
  • Use and adapt adversary-emulation tools and frameworks such as Cobalt Strike, Metasploit and Caldera.
  • Collaborate with Blue Teams during purple-team exercises to validate and improve detection and response capabilities.
  • Perform security testing of AI/ML and LLM-based applications, including prompt injection, jailbreak, model extraction and adversarial-input testing.
  • Apply relevant AI security frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS to identify AI-specific risks.
  • Prepare detailed technical reports covering assessment methodology, vulnerabilities, severity, evidence, PoCs and remediation recommendations.
  • Present security findings and risk implications clearly to technical teams, management and business stakeholders.
  • Stay current with emerging vulnerabilities, APT techniques, malware trends and offensive-security research and incorporate relevant techniques into assessments.
  • Mentor junior consultants on penetration-testing tools, techniques and methodologies and contribute to internal security capability building.

Mandatory Qualifications:

  • 3–6 years of hands-on experience in VAPT, Red Teaming and Application Security, including client-facing or security advisory exposure.
  • Strong understanding of OWASP Top 10, OSSTMM, NIST and CIS security frameworks.
  • Solid understanding of networking fundamentals, including OSI and TCP/IP, and network/infrastructure security.
  • Hands-on experience with penetration-testing and vulnerability-assessment tools such as Burp Suite Pro, Nessus, Nmap, Metasploit, Kali Linux, Nikto, ZAP and MobSF.
  • Ability to perform manual penetration testing beyond automated scanner capabilities.
  • Working experience with scripting and exploit development using Python, Bash or PowerShell.
  • Working knowledge of security assessment across AWS, Azure and/or GCP environments.
  • Strong analytical, technical documentation, report-writing and client communication skills.
  • BE/B.Tech/MCA or equivalent qualification.
  • Ability to communicate security risks and remediation requirements effectively with technical and business stakeholders.

Preferred Qualifications:

  • OSCP, OSCE, CRTP, eWPTX, CREST-CRT or Security+ certification.
  • Hands-on exposure to AI/LLM security testing and frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Experience with advanced Red Teaming and adversary-emulation techniques.
  • Exposure to Active Directory exploitation, phishing/social engineering and endpoint bypass techniques.
  • Experience participating in purple-team engagements and working with Blue/SOC teams.

 

Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Company

Gruve
Pune, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Gruve's careers site·first seen 17 Sept 2026·last verified 17 Sept 2026·How we source jobs

Similar jobs

  • Sr Manager, Integrated Security Operations at AdobeDelhi NCR, India–match not yet calculated
  • Security Specialist at roquetteGokak, India–match not yet calculated
  • Manager - IT, Security, and Cloud at idreamDelhi NCR, India–match not yet calculated
  • Chief Information Security Officer (CISO) at Weekday AIDelhi NCR, India–match not yet calculated
  • Sr Analyst - CISO Office Enterprise Security & Privacy at mgpruMumbai, India–match not yet calculated

Browse more jobs

  • Cybersecurity Consultant jobs in India
  • Business Analyst jobs in India
  • ERP / Enterprise Systems Consultant jobs in India
  • IT Consultant jobs in India
  • Cybersecurity Consultant jobs in United States
  • Cybersecurity Consultant jobs in Germany