About the role
MoonPay is the operating system for moving value across crypto, stablecoins, tokenized assets, and beyond. We serve 30 million customers and 500+ ecosystem partners with four core offerings: fund, tokenize, trade, and spend. The company is regulated across the U.S., UK, EU, Canada, and Australia, and has been recognized by Forbes as one of America's Best Startup Employers for 2026 and ranked second in Crypto Services on Fortune's inaugural Crypto 100 list.
This is a high-velocity, high-accountability environment where outcomes matter more than process. The organization runs on AI as a default operating mode—it's embedded in how people work daily. You'll join a team that values hard problems, real ownership, and teammates who love building together.
You'll work in the Bengaluru office on the Technology & Security Services team, joining the Information Security group focused on data protection and insider risk. This is a hands-on role where you'll own the Data Loss Prevention program end to end, build out insider risk and UEBA capabilities, and contribute to incident response. You'll work across technical tooling, policy development, and collaboration with other departments to create a secure environment.
What you'll do
- Deploy, configure, optimize, and maintain Mimecast Code42, Slack, and Google Workspace to prevent data exfiltration. Design and roll out technical controls across email, browsers, and messaging to block data leakage from endpoints.
- Implement and manage Google Workspace Data Loss Prevention policies and Labels, applying GRC frameworks and data classification principles to inform strategy.
- Build familiarity with UEBA concepts and correlate signals from SaaS platforms, endpoints, and email security tools to identify risky user behavior.
- Develop and manage a pre-hire insider risk process with Talent Acquisition to catch risk signals early in hiring, and build a program to address deepfake threats including detection and incident response procedures.
- Actively participate as an L2 Incident Responder in Security Operations, leading incidents through identification, containment, eradication, recovery, and lessons learned.
- Serve as the primary point of contact for the SOC on SIEM investigations, platform behavior, detection logic, and operational troubleshooting. Translate incident learnings into better detections, dashboards, and playbooks.
What you'll bring
- 3–5 years in information security with focus on data protection, DLP, or insider threat management.
- Strong expertise in DLP and hands-on capability in incident response at scale.
- Deep knowledge of the stack: Apple systems, Google Workspace, Slack, Mimecast Code42, Okta, Crowdstrike, Cloudflare WARP, Tenable Nessus, and Jamf Pro.
- Understanding of GRC frameworks, data management principles, and data classification schemes.
- Ability to move between technical tooling, process development, and cross-functional collaboration without friction.
The role is full-time, in-office in Bengaluru, with working hours from 6:30 PM to 3:30 AM IST. Relocation is not available for this position.
Pay, location & hours
Salary not listed. Based in Bengaluru, Karnataka.
About Moonpay

31 open roles in this building · Company page → · See it on the map
Ripple · Sydney