368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$25k – $64k per year (Estimated)
Location
In office
Seniority
Middle · 3+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
MoonPay is a cryptocurrency payments company headquartered in Miami, Florida, and founded in 2019. The company operates an on and off ramp that lets people buy and sell digital assets with cards and bank transfers, and supplies wallet, NFT checkout, and compliance infrastructure to other crypto businesses. It is integrated into hundreds of wallets and exchanges and holds money transmission and virtual asset licenses across the United States and Europe.

Locations Supported

  • India, Bengaluru

Relocation available: No

Work pattern:

  • This role will be in the office.

  • On-site 5 days per week.

  • Working hours: 12:00 to 9:00 PM IST

About the Opportunity

The Security Operations (SecOps) team at MoonPay is dedicated to ensuring the security and integrity of our systems and data in an increasingly complex digital landscape. Comprising a diverse group of professionals from various regions around the globe, our multicultural team brings together a wealth of expertise and perspectives to tackle security challenges effectively.

Our mission is to identify and mitigate vulnerabilities and threats while maintaining strict compliance with security policies and relevant regulations. By leveraging advanced security measures and proactive threat detection techniques, we work diligently to safeguard our infrastructure and protect our customers’ information.

In collaboration with the IT team and other departments, we foster a culture of security awareness, sharing best practices and ensuring that everyone at MoonPay understands their role in maintaining a secure environment.

Our key responsibilities include incident response, security monitoring, endpoint security, VPN, vulnerability management, data leak protection and third-party risk management (TPRM), all of which contribute to our overarching goal: to create a secure environment for our employees, clients and partners.

Join us in our commitment to security excellence and help us build a safer future in the blockchain and payments industry!

What You Will Do

We are looking for an Information Security Engineer, SaaS & Integration Security, to join our Information Security team, focused on securing our internal SaaS ecosystem, third-party integrations, APIs, and automation workflows. In this role, you will own the security review process for new SaaS applications and integrations end to end, build out threat modeling and secure design practices across the integration lifecycle, and contribute to incident response for SaaS and identity-related events. You are a hands-on individual contributor who is comfortable working across technical tooling, process development, and cross-functional collaboration.

  • SaaS and integration security

    • Set and maintain security standards for SaaS apps, integrations, APIs, plugins, and automation platforms.

    • Assess new applications and integrations before approval, reviewing architecture, data flows, and trust boundaries.

    • Evaluate OAuth scopes, tokens, service accounts, webhooks, extensions, and marketplace apps for excessive permissions, cross-tenant exposure, and unauthorized access.

    • Define approved security patterns for APIs, non-human identities, and automation workflows.

    • Assess AI assistants and third-party AI integrations accessing company systems.

    • Detects and reduces shadow IT and unsanctioned SaaS-to-SaaS connections.

  • Threat modeling and secure design

    • Facilitate risk-based threat modeling for SaaS apps, integrations, APIs, scripts, and internal tools.

    • Identify trust boundaries, abuse cases, and sensitive-data exposure; ensure risks have owners, mitigations, and timelines.

    • Provide secure design alternatives when proposed solutions create unacceptable risk.

    • Maintain reusable threat models and review checklists for common integration patterns.

  • Script and automation security

    • Review Python, JavaScript, shell, and low-code/no-code automations for secrets handling, injection risks, unsafe data processing, and excessive permissions.

    • Promote centralized secrets management, short-lived credentials, and least privilege.

    • Build automated checks for exposed secrets and insecure configurations.

    • Provide clear remediation guidance to engineers and automation owners.

  • Perform targeted testing of integrations, APIs, identity flows, and configurations.

  • Vendor / Third-Party Security

    • Conduct vendor and third-party security assessments, evaluating risk posture and reviewing security questionnaires.

    • Review vendor documentation (SOC 2 reports, pen test summaries) as part of the SaaS approval process.

    • Assess third-party access to company systems and data, including sub-processor risk.

    • Reassess vendor risk over time as scope or posture changes.

    • Partner with Legal and Privacy on contractual security requirements.

  • L2 Incident Response (Operational Role)

    • Monitor SaaS environments for suspicious activity, unauthorized integrations, and data-leakage risks

    • Actively participate in Security Operations activities as an L2 Incident Responder.

    • Lead incidents through all stages: identification, containment, eradication, recovery, and lessons learned.

    • Serve as the primary point of contact for the SOC regarding SIEM investigations, platform behavior, detection logic, and operational troubleshooting.

    • Support continuous improvement by translating incident learnings into better detections, dashboards, and playbooks.

About You

Describe the ideal candidate’s qualifications, skills, experience, and behaviours that show strong culture alignment.

You’re an Information Security Engineer who can both build and operate at scale. You have strong expertise in DLP and are equally comfortable with leading incident response.

You will be working primarily on the following stack: Apple systems, Google Workspace, Slack, Mimecast Code42, Okta, Crowdstrike, Cloudflare WARP, Tenable Nessus and Jamf Pro.

Must-have experience and skills

  • Experiences

    • 3+ years in SaaS security, application security, cloud security, or a related defensive security role

    • Experience conducting technical security reviews and risk-based threat modeling

    • Track record of assessing third-party integrations, APIs, and vendor risk before adoption

    • Experience validating security findings and driving remediation with engineering/business teams

  • Cybersecurity Principles

    • Strong grasp of least privilege, defense in depth, and trust boundary analysis

    • Solid understanding of identity and access concepts: OAuth, SAML, OIDC, SSO, MFA

    • Familiarity with common integration risks: excessive permissions, cross-tenant exposure, insecure data flows, injection, credential exposure, supply-chain compromise

    • Working knowledge of frameworks such as OWASP, MITRE ATT&CK, NIST, or CIS Controls

  • Technical Proficiency

    • Ability to read and review scripts in Python, JavaScript, or shell for security weaknesses

    • Understanding of secrets management, short-lived credentials, and secure API design

    • Hands-on experience securing identity and productivity platforms such as Okta, Google Workspace, and Google Cloud Platform

    • Experience assessing security and access controls in collaboration/SaaS tools such as Linear, Slack, Notion, Intercom, and Atlassian (Jira/Confluence)

    • Comfort building or using automated checks/tooling to detect exposed secrets, misconfigurations, or permission risks across a SaaS-first stack

  • Analytical Skills

    • Excellent analytical and problem-solving abilities.

  • Crisis Management

    • Ability to work effectively under pressure.

    • Capable of handling multiple incidents simultaneously.

  • Communication

    • Strong communication and interpersonal skills to collaborate with various teams.

Nice-to-have experience

  • Education

    • Bachelor's degree in Computer Science, Information Security, or a related field. Equivalent work experience will be considered.

  • Security Frameworks

    • Experience with frameworks such as ISO 27001, SOC 2, and PCI-DSS.

    • Responsible for defining and implementing key security controls.

  • Incident Response

    • Practical incident response experience including triage, investigation, containment, and communications.

  • Vulnerability Management

    • Identifying, prioritizing, and automating remediation of security vulnerabilities.

  • Vendor / Third-Party Security

    • Experience conducting vendor and third-party security assessments, including evaluating risk posture, reviewing security questionnaires, and ensuring third parties meet organizational security standards.

Bonus Points

Optional extras that would help a candidate stand out (keep this short).

  • Certifications

    • CompTIA Security+, CySA+, CCSP or equivalent certifications are a plus.

    • OSCP, GWAPT are a plus.

  • Technical Proficiency

    • Proven experience with tools such as:

      • Google Workspace / Cloud Platform

      • Okta

      • Slack

      • Intercom

      • Notion

      • Linear

      • Crowdstrike

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$39k – $84k per year (Estimated) • In office • Bachelor's Degree • Noida
JavaScript
C#
TypeScript
C#
.NET
AI/ML
AI Agents
Frontend
Angular
React.js
DevOps
AWS
GCP
Apply
$29k – $55k per year (Estimated) • Remote/Hybrid • Full-Time • Moscow
Management
Confluence
Jira
Apply
$19k – $28k per year (net) • Remote/Hybrid • Contractor • 2+ years exp • Samara
JavaScript
Python
SQL
Databases
Apache Kafka
MS SQL
PostgreSQL
AI/ML
Claude
Claude Code
Copilot
Cursor
Model Context Protocol
DevOps
Git
GitLab
Kibana
Design
Figma
Management
Confluence
Draw.io
Jira
Miro
QA
Postman
Swagger
Apply
$36k – $70k per year (Estimated) • In office • Full-Time • 5+ years exp • Moscow
ABAP
DevOps
Bitbucket
Management
Confluence
Jira
Apply
$28k per year (net) • Remote • Full-Time • 3+ years exp • Moscow
JavaScript
PHP
SQL
Databases
Apache Kafka
MySQL
Redis
Management
Confluence
Jira
Apply
$217k – $279k per year • Remote/Hybrid • Full-Time • London
AI/ML
Human-in-the-Loop
Apply
Senior SOC Analyst 5 days ago
$37k – $84k per year (Estimated) • In office • Bachelor's Degree • Bengaluru
DevOps
Cloudflare
IAM
Cybersecurity
Crowdstrike
Google SecOps
Okta
Apply
SOC Analyst 5 days ago
$23k – $58k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Bengaluru
DevOps
Cloudflare
IAM
Cybersecurity
Google SecOps
MITRE ATT&CK
Okta
Management
Jira
Linear
Apply
$141k – $309k per year (Estimated) • Remote/Hybrid • Full-Time • London
Databases
Google BigQuery
Google Bigtable
AI/ML
Vertex AI
DevOps
GCP
Kubernetes
Apply
Remote • Full-Time
DevOps
GitHub
Marketing
Google Ads
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.