SlipstreamJobsFresh Startup & VC-Backed Jobs

TSS Information Security Engineer, SaaS & Integrations

MoonPay - Bengaluru, India - In-office - posted 2026-08-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

MoonPay is seeking an Information Security Engineer to join the Security Operations team, focusing on securing the internal SaaS ecosystem, third-party integrations, APIs, and automation workflows. This is a hands-on individual contributor role with end-to-end ownership of the security review process for new SaaS applications and integrations. Key responsibilities include: **SaaS and Integration Security**: Set and maintain security standards for SaaS apps, integrations, APIs, plugins, and automation platforms. Assess new applications and integrations before approval, reviewing architecture, data flows, and trust boundaries. Evaluate OAuth scopes, tokens, service accounts, webhooks, extensions, and marketplace apps for excessive permissions and unauthorized access. Define approved security patterns for APIs, non-human identities, and automation workflows. Assess AI assistants and third-party AI integrations accessing company systems. Detect and reduce shadow IT and unsanctioned SaaS-to-SaaS connections. **Threat Modeling and Secure Design**: Facilitate risk-based threat modeling for SaaS apps, integrations, APIs, scripts, and internal tools. Identify trust boundaries, abuse cases, and sensitive-data exposure; ensure risks have owners, mitigations, and timelines. Provide secure design alternatives when proposed solutions create unacceptable risk. Maintain reusable threat models and review checklists for common integration patterns. **Script and Automation Security**: Review Python, JavaScript, shell, and low-code/no-code automations for secrets handling, injection risks, unsafe data processing, and excessive permissions. Promote centralized secrets management, short-lived credentials, and least privilege. Build automated checks for exposed secrets and insecure configurations. Provide clear remediation guidance to engineers and automation owners. Perform targeted testing of integrations, APIs, identity flows, and configurations. **Vendor and Third-Party Security**: Conduct vendor and third-party security assessments, evaluating risk posture and reviewing security questionnaires. Review vendor documentation (SOC 2 reports, pen test summaries) as part of the SaaS approval process. Assess third-party access to company systems and data, including sub-processor risk. Reassess vendor risk over time as scope or posture changes. Partner with Legal and Privacy on contractual security requirements. **L2 Incident Response**: Monitor SaaS environments for suspicious activity and unauthorized integrations. MoonPay is a high-velocity, high-accountability company building the operating system for value movement in crypto, stablecoins, and tokenized assets. The company serves 30M+ customers and 500+ ecosystem partners, and is licensed and regulated across the U.S., UK, EU, Canada, and Australia. The role is based in Bengaluru with on-site work 5 days per week, 12:00 PM to 9:00 PM IST.

Similar roles