Back to Gruve jobs
G

Security Operations Consultant

Gruve
|AI Compute
Pune
Managed Services

Job Description

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position summary:

Senior technical lead for the SOC and for the PulseAI platform layer. Runs major-incident response for security and PulseAI platform events, owns the detection-content and tuning program — including Kubernetes/OpenShift security telemetry — and is L3 for PulseAI platform operations: owns root cause analysis, works platform defects with the Gruve PulseAI engineering team, leads OpenShift cluster lifecycle operations and emergency remediation, acts as vendor engineering liaison for Red Hat, the NVIDIA software stack and third-party platform vendors, partners with the Network Operations Consultant on infrastructure-side events, and deputises for the Security Operation Manager.

Key responsibilities:

  • Lead technical response on Severity 1/2 security and PulseAI platform incidents until management command engages; own the SLA status cadence (hourly / every 30 minutes on Severity 1) to customer authorised contacts; hand infrastructure-side events (network fabric, GPU hardware, storage) to the Network Operations Consultant and stay engaged on cross-domain incidents.
  • Own root cause analysis for PulseAI platform and OpenShift cluster incidents; reproduce and characterise platform defects and route them to Gruve PulseAI product engineering; own the corrective-action backlog and problem management to eliminate recurring incidents.
  • Own the PulseAI platform operations practice: severity classification standards, diagnostic runbooks for the PulseAI and OpenShift layers (control plane, operators, authentication/SSO, RBAC, tenancy and quota enforcement, model-serving endpoints, observability), Grafana observability standards, alert thresholds for the SLA appendix, and the monitor / remediate / escalate matrix as applied per customer.
  • Lead OpenShift cluster lifecycle operations for PulseAI customers — y-stream upgrades on customer approval within the agreed window of the Red Hat release, operator and platform-component changes, emergency vulnerability remediation of the cluster and platform — enforcing the pre-change backup gate, and coordinating node-pool, GPU driver/firmware and fabric changes with the Network Operations Consultant.
  • Own Kubernetes/OpenShift security operations for the engagement: onboarding kube-audit and workload telemetry into the SIEM, detection content for container attack paths (MITRE ATT&CK for Containers), Cilium/Hubble and OVN-Kubernetes flow use cases, admission-control and image/runtime security posture, and RBAC / service-account hygiene reviews.
  • Act as vendor engineering liaison for the platform stack: Red Hat for OpenShift product defects, NVIDIA for GPU Operator / driver / NVIDIA AI Enterprise (NIM) software issues, and the third-party platform variant (Rafay, vCluster, vNode, NVIDIA Run:ai, Red Hat OpenShift AI) where restoration is best-effort with committed vendor escalation.
  • Lead customer onboarding technically for the platform layer: deploy and validate OpenShift and PulseAI within the 14-day Ready-for-Install window, configure identity provider federation and initial tenancy structure, onboard the platform to monitoring via the agreed connectivity pattern (outbound collector, site-to-site VPN or jump host with just-in-time elevation), and complete the platform sections of the countersigned environment validation checklist.
  • Own the detection-content backlog and tuning program; own log-pipeline integration health with escalation into engineering.
  • Approve and execute high-risk security and platform changes; cross-train the SOC L1/L2 bench on Kubernetes/OpenShift platform operations; drive shift-quality audits and post-incident reviews for the SOC pod.

-

Mandatory Qualifications:

  • 8–11 years with prior senior/lead experience in SOC or 24×7 platform operations and genuine security-to-platform cross-domain fluency.
  • Incident command capability; deep SIEM content and query skills.
  • Strong Kubernetes/GKE security operations depth — onboarding kube-audit and workload telemetry, building detection content for container attack paths (MITRE ATT&CK for Containers), and tuning Cilium/Hubble-based use cases.
  • Deep Red Hat OpenShift / Kubernetes operations experience in production — multi-node cluster administration, operators, y/z-stream upgrades, RBAC, storage and networking, observability stack (Grafana, metrics, logs, alerting), backup/restore of cluster and platform state — with a track record of platform diagnostics and RCA.
  • GPU-cluster platform operations experience: NVIDIA GPU Operator/driver lifecycle, NVIDIA AI Enterprise components (NIM), DCGM-class telemetry, node health and capacity management for AI inference workloads on RTX PRO 6000 / HGX B300-class servers or equivalent.
  • Experience operating against contractual SLAs (acknowledgement, restoration, availability, service credits) and running vendor engineering escalations through to fix.
  • Working network troubleshooting sufficient to scope cluster-networking versus fabric faults jointly with the NOC; automation mindset.

Preferred Qualifications:

  • Advanced incident-handling / intrusion-analysis certification (e.g., GCIH, GCIA, GCFA or equivalent).
  • CKS or equivalent; experience running K8s posture/runtime security tooling in production.
  • Red Hat certifications (EX280 / EX380 / RHCE); exposure to Rafay, vCluster, NVIDIA Run:ai or Red Hat OpenShift AI; MLOps or AI-platform operations (model-serving endpoints, GPU scheduling, quota governance).
  • Exposure to HashiCorp Vault, SAML 2.0 SSO federation, and CSI/NFS storage for model artefacts.
  • MSSP/managed-services background; AI-SOC tooling exposure.
  • Correlating GPU-platform performance anomalies (utilisation, thermal, fabric saturation) with security events to separate abuse, crypto-mining or misconfiguration from genuine workload load.

Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

About Gruve

First seen: August 31, 2026
Last updated: September 20, 2026