Specialist, Information Security & Privacy
Mindtickle · Information Security & Privacy
Apply ↗Skills
["Burp Suite""OWASP ZAP""sqlmap""Nmap""OWASP Top 10""AWS security""Terraform""CI/CD""SAST""DAST"]Technology stack
{"cloud": ["AWS"]"infrastructure": ["Terraform""CI/CD"]"other_tools": ["Burp Suite""OWASP ZAP""sqlmap""Nmap"]}Description
About Mindtickle Mindtickle is the leading AI-powered revenue enablement platform, helping sales teams learn faster, practice smarter, and perform at their best. We bring together onboarding, training, coaching, content, digital sales rooms, conversation intelligence, and AI role plays into one platform so revenue teams have everything they need to build winning sellers. Global companies, like Fortune 500 organizations, trust Mindtickle to support their revenue teams. We've also been recognized by customers and industry analysts. G2 has ranked us the #1 Sales Training & Onboarding platform for 28 consecutive quarters, and Forrester has recognized Mindtickle as a Leader in revenue enablement. Mindtickle was also recognized as AI-Based Sales Solution of the Year by the 2025 AI Breakthrough Awards and has received Stevie Awards for Technology Innovation and Customer Support Excellence. At Mindtickle, we're helping companies create high-performing revenue teams, and we're looking for people who want to help shape what's next. The Opportunity We are scaling our Information Security and Privacy team in Pune to ensure our enterprise-grade trust is measurable and continuously improving. You will own external security ratings, bug bounty triage, and vulnerability validation through self-proof-of-concepts, partnering directly with Engineering and GTM to maintain an accurate security posture. If you want a role where your technical depth directly secures a market-leading revenue platform from day one, this is i
Requirements
["Practical experience in application security, vulnerability management, security operations, or a security-adjacent technical role.\n\n Proven capability to independently validate and triage vulnerability findings using tools like Burp Suite, OWASP ZAP, sqlmap, or Nmap.\n\n Strong, hands-on command of the OWASP Top 10, with deep depth in XSS, SQL injection, broken authentication, and access control flaws.\n\n Solid grasp of networking fundamentals, core protocols (TLS/SSL, OAuth 2.0, SAML), and AWS cloud security configurations.\n\n Hands-on familiarity with CI/CD tooling, infrastructure-as-code like Terraform, and container security.\n\n Strong written communication skills to articulate technical security risks clearly to both engineers and external stakeholders"]
Roles & responsibilities
["Manage Mindtickle's standing on external security rating platforms like SecurityScorecard and UpGuard by tracking scores, analyzing flagged issues, and updating the GTM Score Deck.\n\n Validate incoming vulnerability findings across bug bounties, third-party pentests, and customer reports by reproducing issues via self-PoC and assessing real-world impact.\n\nRun the bug bounty program end-to-end, coordinating researcher communications, reward decisions, and cross-functional payouts.\n\n Perform security reviews of products, pull requests, and infrastructure-as-code to catch vulnerabilities early in development.\n\n Review AWS account configurations, network architecture, and core protocols to uncover misconfigurations and mitigate real-world risks.\n\n Partner with Engineering and DevOps to strengthen automated security checks like SAST, DAST, and container scanning within CI/CD pipelines.\n\nTranslate validated findings into actionable Jira tickets with clear exploitation paths and remediation options for development teams.\n\nTrack open security issues through to final resolution and validate fixes post-sign-off."]
About