TSS Information Security Engineer, SaaS & Integrations at MoonPay – Full-Time Job in Bengaluru
MoonPay is hiring a TSS Information Security Engineer, SaaS & Integrations to join its security team in Bengaluru, India. This is a full-time opportunity for an experienced cybersecurity professional with expertise in SaaS security, application security, cloud security, threat modeling, integrations, APIs, data loss prevention, and incident response.
The role is particularly suitable for information security professionals who enjoy working at the intersection of technology, security operations, SaaS applications, identity management, automation, and emerging technologies such as artificial intelligence.
Applicants must be located in Bengaluru, India.
About MoonPay
MoonPay is a global financial technology company focused on infrastructure for digital assets and value movement.
The company describes its platform as an operating system for value movement, supporting crypto, stablecoins, tokenized assets, and payments. MoonPay's infrastructure serves more than 30 million customers and over 500 partners.
🎓 Invest in Your Future
Master in-demand skills with expert-led courses on Programming, AI, Data Science, Business, Finance, Marketing, Design and thousands more.
🚀 Explore Udemy Courses✔ Learn at your own pace | ✔ Lifetime access | ✔ Certificates of completion
As a company operating across the digital-asset and financial technology ecosystem, MoonPay places significant emphasis on security, compliance, privacy, and risk management.
The Information Security Engineer will therefore have the opportunity to work on security challenges involving SaaS applications, APIs, integrations, identity systems, automation platforms, and AI-enabled tools.
About the Information Security Engineer Role
The TSS Information Security Engineer, SaaS & Integrations will focus on protecting MoonPay's technology environment from security risks associated with third-party applications, SaaS platforms, APIs, integrations, automation tools, and identity systems.
The successful candidate will help determine whether new applications and integrations can safely be introduced into the company's environment.
This involves performing security reviews, assessing potential threats, defining security requirements, investigating incidents, and helping develop processes that reduce security risks.
The role combines hands-on cybersecurity work with security governance and cross-functional collaboration.
Key Responsibilities
Security Reviews for SaaS and Integrations
One of the main responsibilities will be managing security reviews and approval processes for new SaaS applications, integrations, APIs, plugins, and automation platforms.
The engineer will assess whether proposed technologies introduce unacceptable security risks before they are approved for use.
This requires the ability to understand how applications communicate, what information they access, and what permissions they require.
Develop Security Standards
The successful candidate will help define and maintain security standards, approved patterns, and threat models for integrations and automation workflows.
The objective is to create repeatable security practices that engineering and business teams can follow when introducing new technologies.
This can help MoonPay move quickly while maintaining appropriate security controls.
Assess Identity and Permissions
The role involves evaluating security risks associated with technologies such as:
- OAuth scopes
- Access tokens
- Webhooks
- Service accounts
- Marketplace applications
- API integrations
- AI integrations
- Automation platforms
The engineer will look for excessive permissions, inappropriate access, exposed credentials, and other weaknesses that could potentially be exploited by attackers.
Threat Modeling
Threat modeling will also be an important part of the position.
The engineer will identify trust boundaries, potential abuse cases, attack paths, and other security risks associated with integrations.
Once risks are identified, the engineer will ensure that appropriate risk owners and mitigation strategies are assigned.
This requires strong analytical skills and the ability to think like both a security engineer and a potential attacker.
Review Automation and Scripts
MoonPay uses various automation technologies, and the Information Security Engineer will review scripts and workflows written in technologies such as:
- Python
- JavaScript
- Shell
- Low-code automation platforms
The engineer will assess these scripts for problems such as poor secrets handling, injection vulnerabilities, unsafe data processing, and other security weaknesses.
The role will also promote the use of centralized secrets-management solutions.
Incident Response
The successful candidate will also serve as an L2 Incident Responder for SaaS and identity-related security incidents.
This means monitoring security events, investigating suspicious activity, helping contain incidents, and determining how security controls can be improved.
After incidents are resolved, the engineer will help translate lessons learned into improved detections, procedures, and incident-response playbooks.
Requirements
MoonPay is looking for an information security professional with at least three years of experience in areas such as:
- SaaS security
- Application security
- Cloud security
- Defensive security
- Information security engineering
🎓 Invest in Your Future
Master in-demand skills with expert-led courses on Programming, AI, Data Science, Business, Finance, Marketing, Design and thousands more.
🚀 Explore Udemy Courses✔ Learn at your own pace | ✔ Lifetime access | ✔ Certificates of completion
Candidates should have practical experience conducting technical security reviews and risk-based threat modeling for integrations and APIs.
Strong expertise in Data Loss Prevention (DLP) is required, along with hands-on incident-response experience.
The successful candidate should also be comfortable working across technical security tools, developing security processes, and collaborating with teams outside of security.
Skills That Can Help Candidates Stand Out
Candidates may strengthen their applications by demonstrating experience with:
- SaaS security architecture
- API security
- OAuth
- Identity and access management
- Threat modeling
- Incident response
- DLP
- Security automation
- Cloud security
- Third-party risk management
- AI security
- Secrets management
- Application security
Experience reviewing automation workflows and integrations can also be highly valuable.
Technology Stack
The position involves a broad collection of security and enterprise technology tools.
The listed stack includes:
Apple systems, Google Workspace, Slack, Mimecast, Code42, Okta, CrowdStrike, Cloudflare WARP, Tenable Nessus, and Jamf Pro.
Candidates who have worked with several of these technologies may have an advantage, particularly where they can demonstrate practical security experience rather than simply familiarity with the tools.
Who Should Apply?
This opportunity may be suitable for professionals working as:
- Information Security Engineers
- Cybersecurity Engineers
- SaaS Security Engineers
- Cloud Security Engineers
- Application Security Engineers
- Security Operations Engineers
- Security Analysts
- Incident Response Engineers
- Defensive Security Engineers
- Security Risk Engineers
It may also appeal to cybersecurity professionals who want to move into a role combining technical security operations with security governance and technology risk management.
How to Prepare Your Application
Candidates should tailor their CV to the specific requirements of the position.
Rather than simply listing cybersecurity tools, applicants should demonstrate what they have achieved with them.
For example, highlight experience where you:
- Conducted security reviews
- Identified and mitigated API vulnerabilities
- Performed threat modeling
- Investigated security incidents
- Managed DLP controls
- Reviewed OAuth permissions
- Secured SaaS applications
- Improved identity-security processes
- Built security automation
- Developed incident-response procedures
Quantifiable achievements can make an application stronger.
Location and Work Arrangement
This is a full-time position based in Bengaluru, India.
Applicants should therefore be prepared to meet the company's location requirement.
Professionals already living in Bengaluru and surrounding areas with the required cybersecurity experience are particularly encouraged to consider the opportunity.
🎓 Invest in Your Future
Master in-demand skills with expert-led courses on Programming, AI, Data Science, Business, Finance, Marketing, Design and thousands more.
🚀 Explore Udemy Courses✔ Learn at your own pace | ✔ Lifetime access | ✔ Certificates of completion
How to Apply
Interested candidates can review the vacancy and application details through the job listing below.
📩 Apply:
Before applying, candidates should review the latest job description and confirm that they meet MoonPay's experience and Bengaluru location requirements.
Final Thoughts
The TSS Information Security Engineer, SaaS & Integrations position at MoonPay is an attractive opportunity for experienced cybersecurity professionals who want to work on security challenges within the digital-asset and financial technology industry.
The role goes beyond traditional security monitoring. It combines SaaS security, API and integration security, identity protection, threat modeling, automation security, DLP, and incident response.
For cybersecurity professionals in Bengaluru, India, this could be an opportunity to work with a global technology company while developing experience in a rapidly evolving digital-asset environment.
Candidates who can demonstrate strong technical security knowledge, excellent analytical skills, practical incident-response experience, and the ability to collaborate across teams should consider applying.
Comments
Post a Comment