SOC Security Consultant
Gruve
| Company | Gruve |
| Category | Consulting & Strategy |
| Location | Singapore |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 13 Apr 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
About Gruve
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks. Position summary:
We are seeking a skilled Security Consultant to join our Security Operations Center (SOC) team. The ideal candidate will have a strong background in SOC operations and will ensure the SOC team is performing its functions as required, including troubleshooting incidents and events. The ideal Security Consultant will also act as the technical subject matter expert (SME), handling critical SOC tasks, and guiding Level 1 and Level 2 customer communications.
Key Roles & Responsibilities:
Incident Response and Management
Lead the investigation of high-severity security incidents and breaches.
Provide expert analysis for complex incidents that L1 and L2 analysts cannot resolve.
Develop and execute incident response procedures, including containment, eradication, and recovery.
Ensure proper escalation processes are followed for incidents requiring higher expertise.
Communicate with stakeholders, such as management and IT teams, to ensure appropriate handling of incidents.
Threat Hunting and Analysis
Perform proactive threat hunting activities to identify potential vulnerabilities, threats, and attacks before they happen using Splunk / QRadar SIEM.
Use threat intelligence feeds to enrich SOC operations and identify emerging threats.
Analyze large volumes of security data to detect patterns and anomalies.
Security Tool Management
Oversee and optimize the usage of security monitoring tools such as Splunk/ QRadar SIEM (Security Information and Event Management), IDS/IPS (Intrusion Detection/Prevention Systems), and endpoint protection systems.
Configure, update, and fine-tune security tools to improve detection capabilities and reduce false positives.
Recommend new security tools and technologies to improve SOC operations.
Log and Event Analysis
Review logs from various sources (network, endpoints, servers, etc.) to identify security incidents.
Ensure accurate log data collection and retention practices are followed.
Provide in-depth analysis of security alerts and generate reports.
Vulnerability Management
Conduct vulnerability assessments and prioritize remediation activities for critical vulnerabilities.
Collaborate with the IT and development teams to address security flaws and implement patches.
Collaboration and Escalation
Serve as the point of escalation for L1 and L2 SOC analysts when complex issues arise.
Collaborate with other security teams, such as network security, application security, and IT operations, to ensure a comprehensive defense strategy.
Work with external partners, including Managed Security Service Providers (MSSPs), to coordinate incident management and threat intelligence sharing.
Security Policies and Best Practices
Review and recommend improvements to security policies, procedures, and best practices.
Ensure that the organization's security policies are being followed and advise on improvements.
Conduct regular security awareness training for SOC staff and the broader organization.
Reporting and Documentation
Generate detailed reports on incidents, security posture, and threats for senior management and relevant stakeholders.
Maintain incident logs and documentation to comply with regulatory and internal policies.
Ensure all incidents are well-documented with root cause analysis, remediation efforts, and lessons learned.
Continuous Improvement
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →