--- title: 'OT SOC Analyst L2 at Gruve' canonical: 'https://feeny.ai/job/ot-soc-analyst-l2-gruve-pune-8hxjkv61f70k' type: 'job' last_seen: '2026-09-16' --- # OT SOC Analyst L2 at Gruve - **Company:** Gruve - **Location:** Pune, India - **Posted:** 2026-07-17 - **Last confirmed live:** 2026-09-16 - **Apply:** https://gruve.ai/careers/?gh_jid=5362442008 ## Job description ## About Gruve Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks. Position summary: We are seeking a skilled OT SOC Analyst L2 to join our OT Security Operations Center. The ideal candidate will have 3 - 6 years of experience in OT/ICS cybersecurity monitoring and incident investigation, with hands-on exposure to industrial environments such as ICS, SCADA, PLC, RTU, and HMI ecosystems. The analyst will act as the primary escalation point from L1, perform advanced monitoring and triage, support Nozomi and SIEM operations, assist integrations and deployments, and deliver high-quality customer support and reporting while safeguarding safety-critical industrial operations. Key Roles & Responsibilities: 1. Security Monitoring and Incident Triage Monitor OT and IT security alerts across SIEM and OT visibility platforms such as Splunk, QRadar, Sentinel, FortiSIEM, Elastic, and Nozomi Guardian. Validate suspicious activities, correlate security events, monitor industrial communications, and track abnormal asset behavior in ICS/SCADA environments. Escalate confirmed incidents with complete evidence, business impact, and recommended next actions. 1. Incident Investigation and Analysis Investigate OT security alerts, malware indicators, unauthorized changes, policy violations, and suspicious network behavior affecting PLCs, RTUs, HMIs, historians, and engineering workstations. Perform packet analysis using Wireshark, validate indicators of compromise, identify lateral movement, and support containment and recovery activities under defined runbooks. 3.SIEM, Nozomi, and Detection Administration Support SIEM administration activities including log source validation, parser verification, dashboard usage, alert tuning, and false-positive reduction. Assist in the administration and health monitoring of OT security monitoring platforms such as Nozomi Guardian and related collectors/sensors. Contribute to the creation and maintenance of detection rules and OT use cases aligned to industrial threats and operational realities. 4.Deployment and Integration Support Assist OT solution deployments by validating sensor connectivity, syslog forwarding, collector health, API integrations, use-case testing, and user acceptance activities. Support integration of OT monitoring platforms with SIEM, SOAR, ticketing systems, and reporting workflows. 1. OT Log, Asset, and Protocol Analysis Review logs, alarms, and network telemetry from OT and IT sources to identify anomalies and confirm incident context. Demonstrate working knowledge of industrial protocols including Modbus, DNP3, OPC UA, IEC 60870-5-104, PROFINET, and related industrial Ethernet communications. Support OT asset inventory validation, communication baseline analysis, and visibility improvement activities. 1. Customer Support and Troubleshooting Provide remote troubleshooting, incident bridge support, health checks, upgrade support, and ticket resolution for customer OT security environments. Communicate effectively with customers, internal stakeholders, and project teams while maintaining SLA commitments. 1. Reporting and Documentation Prepare daily SOC reports, weekly incident summaries, asset visibility reports, security posture updates, and SLA-driven ticketing updates. Maintain accurate incident records, SOPs, runbooks, troubleshooting notes, and knowledge-base documentation. 1. Collaboration and Escalation Work closely with L1 analysts, L3 engineers, implementation teams, customer stakeholders, and cross-functional security teams to resolve operational issues. Escalate complex OT incidents, persistent integration issues, and monitoring gaps to the appropriate engineering or management teams. 9.Compliance and Best Practices Follow established OT security procedures, change controls, and documentation standards while supporting compliance and audit requirements. Operate with awareness of plant safety, production availability, maintenance windows, and the sensitivity of safety-critical environments. 1. Continuous Improvement Recommend improvements to alert quality, reporting accuracy, use cases, SOPs, dashboarding, and OT monitoring coverage. Stay updated on OT cyber threats, industrial attack techniques, and evolving defensive controls relevant to manufacturing, utilities, energy, and other industrial sectors. 1. Report deviations and concerns to the SOC Manager Basic Qualifications: - Bachelor’s degree in computer science, Information Technology, Cybersecurity, Electronics, Instrumentation, or a related field. - 3–6 years of experience in cybersecurity operations, OT SOC, ICS/SCADA monitoring, incident investigation, or industrial network security. - Hands-on exposure to SIEM platforms such as Splunk, QRadar, Sentinel, FortiSIEM, or Elastic, and familiarity with Nozomi Guardian or similar OT monitoring tools. - Working knowledge of OT/ICS environments including ICS, SCADA, PLC, RTU, HMI, historians, industrial switches, and engineering workstations. - Understanding of industrial protocols such as Modbus, DNP3, OPC UA, IEC 60870-5-104, PROFINET, and related traffic analysis concepts. - Experience with Wireshark, Syslog, Linux, Windows, Excel, and PowerShell for troubleshooting, analysis, and reporting. - Strong analytical thinking, documentation discipline, customer interaction skills, time management, and team collaboration. - Ability to work in rotational shifts, manage ticket queues, and operate effectively in high-availability industrial environments. Preferred Qualifications: - Certifications such as Security+, Microsoft SC-200, Splunk Power User, QRadar Analyst, Nozomi Fundamentals, GICSP (foundation level exposure), or equivalent. - Exposure to SOAR workflows, API-based integrations, threat intelligence enrichment, and OT vulnerability management processes. - Knowledge of Purdue Model, network segmentation, jump hosts, remote access controls, firewall policy validation, and OT asset inventory concepts. - Experience supporting industrial customers in sectors such as manufacturing, energy, utilities, oil and gas, pharma, or critical infrastructure. - Strong interest in building deeper expertise across OT detection engineering, incident response, industrial protocols, and customer-facing delivery. ## Why Gruve At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you. Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted. ## About Gruve ## Company Overview - **One-liner**: Gruve provides AI-native cybersecurity, infrastructure, and data services that help enterprises deploy and secure AI at scale. - **Entity Type**: Private (Series A, Seed stage) - **Headquarters**: Redwood City, California, United States - **Founded**: 2024 - **Founders**: Tarun Raisoni (CEO, Co-Founder) ## Core Business - **Industry**: IT Services and IT Consulting; AI Security & Infrastructure - **Target Customers**: Large enterprises (B2B), including those in regulated industries requiring private AI deployment and advanced security operations. - **Mission / Purpose**: Enable scalable, secure, and measurable AI execution in production by delivering an AI-native approach to enterprise services. ## Products & Services - **PulseAI**: A private AI infrastructure platform that enables enterprises to deploy generative AI on-premises, in the cloud, or in hybrid environments – production-ready in under two weeks. (SaaS/infrastructure) - **AI SOC**: An AI-driven Security Operations Center that combines AI detection, automated investigation, and intelligent response to improve security team efficiency and reduce risk. (Managed service/SaaS) - **Digital Forensics & Incident Response**: Structured methodologies for preserving evidence, investigating incidents, and accelerating recovery. (Service) - **Enterprise AI Transformation Services**: Consulting and implementation services including data science, Kubernetes SRE, forward deployment engineering, and AI solution architecture. (Professional services) ## Market Standing - **Valuation**: Not disclosed - **Total Funding**: USD $57.5 million (across Seed and Series A rounds) - **Key Investors**: Mayfield Fund (lead in Series A), Xora Innovation (lead in prior round) - **Notable Acquisitions**: SecurView (July 2024), NetServ (September 2024), Lumos (October 2024) - **Growth Signals**: 120.3% YoY employee growth (from ~134 to 413 employees); operations across 9 countries; featured in Cybersecurity Insiders on AI agent governance. ## Competitive Advantages - **AI-Native Architecture**: Unlike legacy stacks built for static software, Gruve designs for dynamic AI workloads (probabilistic decisions, context retrieval, autonomous actions). - **Speed to Scale**: Claims 500MW+ of distributed edge AI inference capacity and a 30% cost advantage over alternatives. - **Integrated Security & AI**: Combines private AI infrastructure (PulseAI) with an AI-powered SOC, covering the entire lifecycle from deployment to defense. - **Talent & Expertise**: Team draws from top firms (Cisco, IBM, Infosys) and includes deep Kubernetes, data science, and cybersecurity specialists. ## Strategic Focus - **Private AI Deployment**: Helping enterprises keep AI workloads on their own infrastructure to maintain data ownership, governance, and security. - **AI Security Governance**: Developing solutions to govern AI agents as a new attack surface, as highlighted in their recent thought leadership. - **Global Expansion**: Operating in 9 countries (US, India, South Korea, UAE, Singapore, Japan, Saudi Arabia, Germany, Canada) with plans to scale further. - **Partner Ecosystem**: Working closely with hyperscalers (noted VP of Hyperscaler Solutions) and achieving Red Hat advanced tier partner status. ## Why Work Here - **High Growth Environment**: Headcount more than doubled in the past year, offering rapid career progression and the chance to shape a young company. - **Culture of Trust**: Core values include giving trust from day one, constructive feedback, and a championship mindset. - **Global & Remote-Friendly**: Offices in 4 countries (US, India, Singapore, UAE) and remote roles posted; a distributed team with cultural diversity. - **Learning & Impact**: Mentorship programs, opportunities to lead innovative projects in AI and security, and the ability to work on cutting-edge infrastructure. - **Notable Perks**: Focus on career development, knowledge sharing, and a "people-first" approach. ## Sources 1. [gruve.ai – Company homepage](https://gruve.ai/) 2. [gruve.ai – About Us](https://gruve.ai/about-us/) 3. [gruve.ai – Life at Gruve](https://gruve.ai/life-at-gruve/) 4. [linkedin.com/company/gruveai – LinkedIn Company Page](https://www.linkedin.com/company/gruveai) 5. [job-boards.greenhouse.io/gruve – Careers Page](https://job-boards.greenhouse.io/gruve) ## Other roles at Gruve - [Senior Security Consultant (Cisco ISE/Ansible/AWS)](https://feeny.ai/job/senior-security-consultant-cisco-ise-ansible-aws-gruve-pune-nzpy01b3jxhf) — Pune, India - [Senior Security Consultant – Cisco ISE with AWS Cloud Architecture](https://feeny.ai/job/senior-security-consultant-cisco-ise-with-aws-cloud-architecture-gruve-pune-r2y0mn11bv7j) — Pune, India - [Director Cisco Security Data Center and AI Services Sales](https://feeny.ai/job/director-cisco-security-data-center-and-ai-services-sales-gruve-united-states-w9x1cfe6j1jc) — United States - [Technical Account Manager](https://feeny.ai/job/technical-account-manager-gruve-mumbai-s7hqtbj9yy5h) — Mumbai, India - [Network & Security Engineer](https://feeny.ai/job/network-security-engineer-gruve-dubai-xyfzv4rzh1yf) — Dubai, United Arab Emirates - [Network & Systems Engineer (Vulnerability Management)](https://feeny.ai/job/network-systems-engineer-vulnerability-management-gruve-dubai-4c97f1fw5n7d) — Dubai, United Arab Emirates - [Network & Systems Engineer (Vulnerability Management)](https://feeny.ai/job/network-systems-engineer-vulnerability-management-gruve-dubai-7p605zapm8fj) — Dubai, United Arab Emirates - [Network Consultant I](https://feeny.ai/job/network-consultant-i-gruve-pune-znz1kevp3qqc) — Pune, India - [Security Operations Consultant](https://feeny.ai/job/security-operations-consultant-gruve-pune-08z3vj5pvdre) — Pune, India - [Network Consultant II](https://feeny.ai/job/network-consultant-ii-gruve-pune-0qzpajanq6re) — Pune, India