SlipstreamJobsFresh Startup & VC-Backed Jobs

Information Security Engineer, DLP & Insider Risk

Decent.xyz - Bengaluru, Karnataka, India - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

MoonPay is a high-velocity fintech company building the operating system for value movement across crypto, stablecoins, tokenized assets, and payments. The company serves 30M+ customers and 500+ ecosystem partners, with regulatory licenses across the US, UK, EU, Canada, and Australia. The Security Operations (SecOps) team is seeking an Information Security Engineer focused on Data Loss Prevention (DLP) and Insider Risk. This is a hands-on individual contributor role reporting to the Information Security team, responsible for protecting sensitive data and reducing insider risk across the organization. Key Responsibilities: Data Loss Prevention: Deploy, configure, optimize, and maintain DLP tools including Mimecast, Code42, Slack, and Google Workspace to prevent data exfiltration. Design and implement technical controls across endpoints, email, browsers, and messaging applications. Implement and manage Google Workspace DLP policies and Labels. Apply GRC frameworks, data management principles, and data classification schemes to inform DLP strategy. Insider Risk & UEBA: Develop familiarity with User and Entity Behavior Analytics (UEBA) concepts and correlate signals from SaaS platforms, endpoints, and email security tools to identify risky user behavior. Build a pre-hire insider risk process in partnership with Talent Acquisition. Develop a defensive program addressing deepfake threats, including detection capabilities and incident response procedures. Collaborate with Security Awareness on data-sharing best practices. L2 Incident Response: Actively participate as an L2 Incident Responder in Security Operations. Lead incidents through identification, containment, eradication, recovery, and lessons learned phases. Serve as primary point of contact for the SOC regarding SIEM investigations, platform behavior, detection logic, and operational troubleshooting. Translate incident learnings into improved detections, dashboards, and playbooks. The role operates on a 6:30 PM to 3:30 AM IST schedule, in-office in Bengaluru. MoonPay emphasizes outcomes over process, impact over titles, and expects daily use of AI tools. The company culture values hard problems, real ownership, and collaborative winning. Requirements: Must-Have Experience: - 3–5 years in information security with focus on data protection, DLP, or insider threat - Experience building and operationalizing DLP programs: policy development, detection rule tuning, alert management, response runbook documentation for data exfiltration - Working knowledge of GRC principles, data classification frameworks, and regulatory requirements (GDPR, CCPA, HIPAA) - Familiarity with security frameworks: NIST, ISO 27001, SOC 2 - Google Workspace experience (minimum 1 year) in areas of responsibility - Exposure to SSPM tooling and CIS hardening standards for SaaS and endpoint environments - Proficiency with SIEM tools such as Google SecOps for security operations and investigation workflows - Familiarity with email security gateway solutions for threat prevention, filtering, and analysis - Hands-on experience with Okta for identity and access management in security context - Experience with YARA rules or similar pattern-matching detection methods - Excellent analytical and problem-solving abilities - Ability to work effectively under pressure and handle multiple incidents simultaneously - Strong communication and interpersonal skills for cross-functional collaboration Nice-to-Have: - Bachelor's degree in Computer Science, Information Security, or related field (equivalent work experience considered) - Experience with ISO 27001, SOC 2, PCI-DSS frameworks and defining/implementing key security controls - Practical incident response experience: triage, investigation, containment, communications - Vulnerability management: identifying, prioritizing, automating remediation - Vendor/third-party security assessment experience - Certifications: CompTIA Security+, CySA+, CCSP, GCIH, GCFA - Proven experience with Mimecast, Code42, Slack, Crowdstrike, Cloudflare Zero Trust, Tenable Nessus

Similar roles