MoonPay
Information Security Engineer, DLP & Insider Risk
Bengaluru, Karnataka
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.6M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Mid level
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 19 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About MoonPay
MoonPay is for builders with something to prove.
This isn't a "work on cool crypto stuff" company. It's a high-standards, high-velocity, high-accountability company building the operating system for value movement. If the internet moves information, we move value: crypto, stablecoins, tokenized assets, and whatever comes next. Four offerings make that real: fund, tokenize, trade, and spend. 30M+ customers and 500+ ecosystem partners run on us. Licensed in the U.S. Regulated across the UK, EU, Canada, and Australia.
AI is the default operating mode here. It's woven into every role, and we expect you to use it daily. It handles the manual work so you can deliver on what actually matters.
You'll thrive here if outcomes excite you more than process, if impact motivates you more than titles, and if you want hard problems, real ownership, and teammates who love winning, building, and doing it together.
The bar is high. The pace is real. We're building for what's next, for humans and agents.
Recent recognition:
- Forbes' America's Best Startup Employers 2026 .
- 2nd in Crypto Services on Fortune's inaugural Crypto 100
- The Sunday Times Best Places to Work two years running
Research has shown that women are less likely than men to apply for this role if they do not have experience in 100% of these areas. Please know that this list is indicative, and that we would still love to hear from you even if you feel that you are only a 75% match. Skills can be learned, diversity cannot.
Locations Supported 🌍
India, Bengaluru
Relocation available: No
Work pattern:
This role will be in the office.
Working hours: 6:30 PM to 3:30 AM IST
About the Opportunity
The Security Operations (SecOps) team at MoonPay is dedicated to ensuring the security and integrity of our systems and data in an increasingly complex digital landscape. Comprising a diverse group of professionals from various regions around the globe, our multicultural team brings together a wealth of expertise and perspectives to tackle security challenges effectively.
Our mission is to identify and mitigate vulnerabilities and threats while maintaining strict compliance with security policies and relevant regulations. By leveraging advanced security measures and proactive threat detection techniques, we work diligently to safeguard our infrastructure and protect our customers’ information.
In collaboration with the IT team and other departments, we foster a culture of security awareness, sharing best practices and ensuring that everyone at MoonPay understands their role in maintaining a secure environment.
Our key responsibilities include incident response, security monitoring, endpoint security, VPN, vulnerability management, data leak protection and third-party risk management (TPRM), all of which contribute to our overarching goal: to create a secure environment for our employees, clients and partners.
Join us in our commitment to security excellence and help us build a safer future in the blockchain and payments industry!
What You Will Do
We are looking for an Information Security Engineer, DLP & Insider Risk, to join our Information Security team, focused on protecting sensitive data and reducing insider risk across the organization. In this role, you will own our Data Loss Prevention program end to end, build out our Insider Risk and UEBA capabilities, and contribute to incident response. You are a hands-on individual contributor who is comfortable working across technical tooling, process development, and cross-functional collaboration.
Data Loss Prevention
Deploy, configure, optimize, and maintain Mimecast Code42, Slack, Google Workspace to protect against data exfiltration.
Design and roll out technical controls to prevent data leakage from endpoints across email, browsers, and messaging applications.
Implement and manage Google Workspace Data Loss Prevention policies and Labels.
Apply a solid understanding of GRC frameworks, data management principles, and data classification schemes to inform DLP strategy and policy.
Insider Risk & UEBA
Familiarity with UEBA concepts and the ability to correlate signals from SaaS platforms, endpoints, and email security tools to identify and investigate risky user behavior.
Develop and manage a pre-hire insider risk process in partnership with Talent Acquisition to identify risk signals early in the hiring pipeline.
Build and maintain a defensive program to address deepfake threats, including detection capabilities, incident response procedures, and employee awareness.
Collaborate with the Security Awareness team to promote healthy data-sharing practices across the organization.
L2 Incident Response (Operational Role)
Actively participate in Security Operations activities as an L2 Incident Responder.
Lead incidents through all stages: identification, containment, eradication, recovery, and lessons learned.
Serve as the primary point of contact for the SOC regarding SIEM investigations, platform behavior, detection logic, and operational troubleshooting.
Support continuous improvement by translating incident learnings into better detections, dashboards, and playbooks.
About You
👉 Describe the ideal candidate’s qualifications, skills, experience, and behaviours that show strong culture alignment.
You’re an Information Security Engineer who can both build and operate at scale. You have strong expertise in DLP and are equally comfortable with leading incident response.
You will be working primarily on the following stack: Apple systems, Google Workspace, Slack, Mimecast Code42, Okta, Crowdstrike, Cloudflare WARP, Tenable Nessus and Jamf Pro.
Must-have experience and skills
Experiences
3–5 years of experience in information security, with a focus on data protection, DLP, or insider threat.
Experience building and operationalizing DLP programs, including policy development, tuning detection rules, managing alerts, and documenting response runbooks for data exfiltration scenarios.
Cybersecurity Principles
Working knowledge of GRC principles, data classification frameworks, and regulatory requirements.
Experience with data classification standards and the ability to translate policies into technical controls.
Familiarity with security frameworks such as NIST, ISO 27001, or SOC 2.
Understanding of relevant regulatory requirements such as GDPR, CCPA, or HIPAA.
Technical Proficiency
Google Workspace experience in the areas of responsibility for at least 1 year.
Exposure to SSPM tooling and CIS hardening standards for SaaS and endpoint environments.
Proficiency with SIEM such as Google SecOps for security operations and investigation workflows.
Familiarity with email security gateway solutions for threat prevention, filtering, and analysis.
Hands-on experience with Okta for identity and access management in a security context.
Experience with YARA rules or similar pattern-matching detection methods.
Analytical Skills
Excellent analytical and problem-solving abilities.
Crisis Management
Ability to work effectively under pressure.
Capable of handling multiple incidents simultaneously.
Communication
Strong communication and interpersonal skills to collaborate with various teams.
Nice-to-have experience
Education
Bachelor's degree in Computer Science, Information Security, or a related field. Equivalent work experience will be considered.
Security Frameworks
Experience with frameworks such as ISO 27001, SOC 2, and PCI-DSS.
Responsible for defining and implementing key security controls.
Incident Response
Practical incident response experience including triage, investigation, containment, and communications.
Vulnerability Management
Identifying, prioritizing, and automating remediation of security vulnerabilities.
Vendor / Third-Party Security
Experience conducting vendor and third-party security assessments, including evaluating risk posture, reviewing security questionnaires, and ensuring third p
Similar jobs
- Application Security EngineerAutodesk · Bengaluru, INDFirst seen yesterday
- Security EngineerWehrtyou · MumbaiFirst seen today
- Associate Network Security EngineerCDK Global · IndiaFirst seen today
- Lead Security Engineer - Threat modelling, Cloud SecurityJPMorgan Chase · Bengaluru, Karnataka, IndiaFirst seen yesterday
- Associate Network Security EngineerCdk · Hyderabad, TG, INDFirst seen 2d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job