SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Mindtickle is seeking a Specialist, Information Security and Privacy to join its Information Security and Privacy team in Pune. This role sits at the intersection of compliance, technical security, third-party risk management, and customer trust, responsible for protecting Mindtickle's growing cloud platform.
You will serve as the main point of contact for sales and customer teams on security, privacy, and compliance matters, handling enterprise customer and prospect security RFP requests, questionnaires, and security addendums. You will manage third-party risk evaluation and conduct security due diligence on new vendors and periodic risk reviews of existing third parties.
Key responsibilities include owning the operational backbone of the compliance program across SOC 2 Type II, ISO (27001, 22301, 27701, 27017, 27018, 42001), 21 CFR Part 11, HIPAA, and disaster recovery testing. You will maintain information security reports, RFP knowledgebase, and security assets using existing RFP management tools. You will own and manage controls across multiple frameworks, maintaining an up-to-date control landscape and evidence inventory.
You will coordinate and support external audits end-to-end—from scoping and evidence preparation to auditor walkthroughs and post-audit remediation tracking. You will manage compliance tracking across Google Workspace (Sheets, Drive, Docs, Gmail), maintaining structured control registers, evidence repositories, and policy documentation. You will send and track corrective action communications to control owners, conduct periodic internal compliance reviews, and produce structured reports for leadership.
You will work flexibly across all teams—sales, customer success, product, and engineering—driving security RFP and third-party risk management projects. You will collaborate closely with privacy, internal governance, audit, engineering, DevOps, legal, and HR teams to gather necessary information and ensure controls are implemented. You will maintain and periodically review information security policies, procedures, and standards, ensuring they remain current and aligned with framework controls.
This role reports to the Senior Manager, Information Security and Privacy.
**Requirements:**
**Experience and Background:**
- 3–5 years of experience in information security and compliance, with exposure to cloud software platforms (AWS/GCP)
- Extensive experience handling customer security queries, including RFPs, questionnaires, security architecture reviews, and data protection evaluations
- Experience managing third-party risk evaluation and management processes
- Strong understanding of cloud governance and technology security controls covered in SOC 2, ISO Standards, NIST, GDPR, HIPAA, CSA STAR, CIS, etc.
**Tooling and Workflow:**
- Proficient in Google Workspace—comfortable using Sheets for control tracking, Drive and Docs for policy and evidence management, Gmail for formal communications, and Calendar for scheduling
- Experience utilizing existing RFP management tools to maintain knowledge bases
- Experience using Jira for cross-functional issue tracking and Slack for team collaboration
**Soft Skills and Working Style:**
- Excellent communication, interpersonal, project management, and issue-resolution skills
- Strong written communication skills—able to draft clear policy documents, corrective action notices, and executive summaries
- Strong analytical and organizational skills, with the ability to work effectively as part of a team
- Proactive, pragmatic, and self-driven—able to learn quickly, take initiative, identify gaps, propose solutions, and drive complex projects in a fast-paced SaaS environment
**Good to Have:**
- Certifications: CISSP, CISM, CISA, CRISC, CCSP, ISO 27001, ISO 42001, ISO 22301, CompTIA Security+, etc.
- Understanding of data privacy principles under GDPR and HIPAA, including data classification, retention policies, and subject rights processes