Security Consultant II
Pune, India · On-site · Full-time
- Posted 3w ago
- From Gruve’s careers page
- Location
- Pune, India
- Work mode
- On-site
- Type
- Full-time
- Level
- Senior
- Experience
- 3+ years
- Department
- Information Technology
Opens the listing on gruve.ai
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Position summary:
Security Consultant owning VAPT and Red Teaming engagements across infrastructure, network, web, mobile, API, thick-client, cloud and AI/LLM environments. The role involves identifying and exploiting security weaknesses, simulating real-world adversary techniques, developing proof-of-concept exploits, documenting findings and providing clear remediation guidance to technical and business stakeholders. The consultant will also support purple-team activities, mentor junior resources and contribute to offensive security capability development.
Key responsibilities:
- Perform Vulnerability Assessment and Penetration Testing across infrastructure, network, web, mobile (Android/iOS), API, thick-client and cloud environments (AWS/Azure/GCP).
- Identify, validate and document vulnerabilities using manual testing techniques and automated security tools; develop PoCs to demonstrate exploitability.
- Conduct database security testing and configuration reviews across MySQL, Oracle and NoSQL platforms.
- Plan, execute and document Red Team engagements simulating real-world threat actor TTPs mapped to MITRE ATT&CK.
- Execute attack chains covering initial access, lateral movement, privilege escalation and data exfiltration.
- Conduct Active Directory exploitation, phishing/social-engineering campaigns and endpoint security bypass exercises.
- Use and adapt adversary-emulation tools and frameworks such as Cobalt Strike, Metasploit and Caldera.
- Collaborate with Blue Teams during purple-team exercises to validate and improve detection and response capabilities.
- Perform security testing of AI/ML and LLM-based applications, including prompt injection, jailbreak, model extraction and adversarial-input testing.
- Apply relevant AI security frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS to identify AI-specific risks.
- Prepare detailed technical reports covering assessment methodology, vulnerabilities, severity, evidence, PoCs and remediation recommendations.
- Present security findings and risk implications clearly to technical teams, management and business stakeholders.
- Stay current with emerging vulnerabilities, APT techniques, malware trends and offensive-security research and incorporate relevant techniques into assessments.
- Mentor junior consultants on penetration-testing tools, techniques and methodologies and contribute to internal security capability building.
Mandatory Qualifications:
- 3–6 years of hands-on experience in VAPT, Red Teaming and Application Security, including client-facing or security advisory exposure.
- Strong understanding of OWASP Top 10, OSSTMM, NIST and CIS security frameworks.
- Solid understanding of networking fundamentals, including OSI and TCP/IP, and network/infrastructure security.
- Hands-on experience with penetration-testing and vulnerability-assessment tools such as Burp Suite Pro, Nessus, Nmap, Metasploit, Kali Linux, Nikto, ZAP and MobSF.
- Ability to perform manual penetration testing beyond automated scanner capabilities.
- Working experience with scripting and exploit development using Python, Bash or PowerShell.
- Working knowledge of security assessment across AWS, Azure and/or GCP environments.
- Strong analytical, technical documentation, report-writing and client communication skills.
- BE/B.Tech/MCA or equivalent qualification.
- Ability to communicate security risks and remediation requirements effectively with technical and business stakeholders.
Preferred Qualifications:
- OSCP, OSCE, CRTP, eWPTX, CREST-CRT or Security+ certification.
- Hands-on exposure to AI/LLM security testing and frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS.
- Experience with advanced Red Teaming and adversary-emulation techniques.
- Exposure to Active Directory exploitation, phishing/social engineering and endpoint bypass techniques.
- Experience participating in purple-team engagements and working with Blue/SOC teams.
Skills they ask for
Pick one to see other roles that ask for it.
About Gruve
AI infrastructure and security servicesGruve provides enterprise AI infrastructure and cybersecurity services, including private AI infrastructure and managed security operations.
See all 14 roles at GruveMore roles at Gruve
See all 14- Senior Business Analyst – Digital Transformation & AIIndia · Senior · RemoteBusiness Operations · Senior · RemoteIndia2d
- L3 Server Infrastructure Lead (Unix/Linux)India · Senior · RemoteInformation Technology · Senior · RemoteIndia4d
- Manager – Partner & AlliancesBengaluru · Senior · On-siteBusiness Development · Senior · On-siteBengaluru, India5d
- Marketing Operations & Event SpecialistPune · HybridMarketing · HybridPune, India5d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.