← Back to jobs

Specialist, Information Security and Privacy

Mindtickle · Information Security & Privacy

Apply ↗
Location
Pune, Maharashtra, India
Employment type
Full-time
Work mode
Onsite
Experience
3-5 years
Posted
2026-09-10

Skills

["SOC 2""ISO 27001""NIST""GDPR""HIPAA""Third-party risk"]

Technology stack

{"other_tools": ["Google Workspace"]}

Description

Mindtickle is hiring a Specialist, Information Security and Privacy to join our Information Security and Privacy team in Pune. This role sits at the intersection of compliance, technical security, third-party risk management, and customer trust. You will be responsible for various functions related to the security, privacy, and protection of Mindtickle's growing cloud platform. Your role will involve handling enterprise customer and prospect security RFP requests, managing third-party risk, and owning the operational backbone of our compliance program across SOC 2 Type II, ISO (27001, 22301, 27701, 27017, 27018 & 42001), 21 CFR Part 11,  HIPAA, and DR testing. You will coordinate with customers, vendors, and internal teams to ensure Mindtickle adheres to the highest data security standards. A proactive and pragmatic approach to data security and privacy is essential as you help build systems that make compliance self-evident. This role reports to the Senior Manager, Information Security and Privacy.

Requirements

["Experience and Background\n\n3-5 years of experience in information security and compliance, with exposure to cloud software platforms (AWS/GCP).\n\nExtensive experience in handling customer security queries, including RFPs, questionnaires, security architecture reviews, and data protection evaluations.\n\nExperience in managing third-party risk evaluation and management processes.\n\nStrong understanding of cloud governance and technology security controls covered in SOC 2, ISO Standards, NIST, GDPR, HIPAA, CSA STAR, CIS, etc.\n\nTooling and Workflow\n\nProficient in Google Workspace - comfortable using Sheets for control tracking, Drive and Docs for policy and evidence management, Gmail for formal communications, and Calendar for scheduling.\n\nUtilize existing RFP management tools to maintain the knowledge base in line with changing customer needs, global standards, product releases, and updates.\n\nExperience using Jira for cross-functional issue tracking and Slack for team collaboration.\n\nSoft Skills and Working Style\n\nExcellent communication, interpersonal, project management, and issue-resolution skills.\n\nStrong written communication skills - able to draft clear policy documents, corrective action notices, and executive summaries.\n\nStrong analytical and organizational skills, with the ability to work effectively as part of a team.\n\nProactive, pragmatic, and self-driven - able to learn quickly, take initiative, identify gaps, propose solutions, and drive complex projects in a fast-paced SaaS environment."]

Roles & responsibilities

["Serve as the main point of contact for sales and customer teams regarding security, privacy, and compliance topics, communicating with customers and prospects through RFPs, emails, or calls.\n\nReview customer/prospect questionnaires and security addendums, providing and building necessary information, collaterals, and resources.\n\nMaintain information security reports, RFP knowledgebase, and security assets for the security due diligence process utilizing existing RFP management tools.\n\nWork flexibly across all teams in the organization, driving security RFP and third-party risk management projects, including sales, customer success, product, and engineering.\n\nOwn the third-party risk management process, including planning, scoping, needs analysis, ongoing project management, and communication with stakeholders.\n\nConduct security due diligence on new third parties and perform periodic risk reviews of existing third parties.\n\nOwn and manage controls across SOC 2 Type II, ISO standards, 21 CFR Part 11, and HIPAA frameworks, maintaining an up-to-date control landscape and evidence inventory.\n\nCoordinate and support external audits end-to-end - from audit scoping and evidence preparation to auditor walkthroughs and post-audit remediation tracking.\n\nManage compliance tracking across Google Workspace (Sheets, Drive, Docs, Gmail) - maintaining structured control registers, evidence repositories, and policy documentation.\n\nSend and track corrective action communications to control owners, following up through resolution and maintaining a clear audit trail.\n\nConduct periodic internal compliance reviews and produce structured reports for leadership.\n\nCollaborate closely with privacy, internal governance, audit, Engineering, DevOps, Legal, and HR teams to gather necessary information related to compliance and ensure controls are implemented.\n\nWork with engineering, business applications, legal, and other teams as required to fulfill customer, prospect, or third-party compliance requirements.\n\nMaintain and periodically review information security policies, procedures, and standards in Google Docs, ensuring they remain current and aligned with framework controls.\n\nCoordinate access reviews, vendor security assessments, and third-party risk evaluations as part of the ongoing compliance calendar.\n\nUndertake any other reasonable and related tasks associated with the role."]

About

All jobs →