Specialist, Information Security and Privacy
The Opportunity
We are scaling our Information Security and Privacy team in Pune to ensure our enterprise-grade trust is measurable and continuously improving. You will own external security ratings, bug bounty triage, and vulnerability validation through self-proof-of-concepts, partnering directly with Engineering and GTM to maintain an accurate security posture. If you want a role where your technical depth directly secures a market-leading revenue platform from day one, this is it
What You'll Drive
Manage Mindtickle's standing on external security rating platforms like SecurityScorecard and UpGuard by tracking scores, analyzing flagged issues, and updating the GTM Score Deck.
Validate incoming vulnerability findings across bug bounties, third-party pentests, and customer reports by reproducing issues via self-PoC and assessing real-world impact.
Run the bug bounty program end-to-end, coordinating researcher communications, reward decisions, and cross-functional payouts.
Perform security reviews of products, pull requests, and infrastructure-as-code to catch vulnerabilities early in development.
Review AWS account configurations, network architecture, and core protocols to uncover misconfigurations and mitigate real-world risks.
Partner with Engineering and DevOps to strengthen automated security checks like SAST, DAST, and container scanning within CI/CD pipelines.
Translate validated findings into actionable Jira tickets with clear exploitation paths and remediation options for development teams.
Track open security issues through to final resolution and validate fixes post-sign-off.
How You'll Work with AI
Use AI-powered tools (e.g. Cursor, Claude Code) to support security reviews and analyze codebases more efficiently
Leverage AI assistants to parse complex vulnerability scan outputs and accelerate preliminary triage workflows.
Prompt-engineer AI workflows to automate repetitive security checks and streamline internal tracking documentation
What You Bring
Practical experience in application security, vulnerability management, security operations, or a security-adjacent technical role.
Proven capability to independently validate and triage vulnerability findings using tools like Burp Suite, OWASP ZAP, sqlmap, or Nmap.
Strong, hands-on command of the OWASP Top 10, with deep depth in XSS, SQL injection, broken authentication, and access control flaws.
Solid grasp of networking fundamentals, core protocols (TLS/SSL, OAuth 2.0, SAML), and AWS cloud security configurations.
Hands-on familiarity with CI/CD tooling, infrastructure-as-code like Terraform, and container security.
Strong written communication skills to articulate technical security risks clearly to both engineers and external stakeholders
Nice to Have
Prior experience running or supporting a bug bounty program or handling reward processes would be an advantage.
Professional security certifications such as OSCP, CEH, CISA, CISSP, or AWS Certified Security (Specialty) are a plus.
•Exposure to CSPM tooling or Google Cloud Platform is nice to have
What We Offer
Competitive compensation
Flexible hybrid work - we care about output
Unlimited paid time off, plus company holidays and all statutory leave entitlements
Comprehensive health coverage for you and your family
Wellness support - physical and mental health programmes
Learning & development access, including Mindtickle's own platform.
Equity participation
If based in our India offices (Pune / Bangalore):
Fresh meals from our live kitchen - breakfast, lunch, and dinner covered
Unlimited tea, coffee, snacks, and beverages throughout the day
Spaces to focus, collaborate, or decompress between sessions
We mark the moments that matter - birthdays, work anniversaries, and the wins worth celebrating
Our Culture & Values
We hire builders, people who move fast, learn from failure, and use AI as a default part of how they work. Our values, Delight Your Customers, Act as a Founder, and Better Together, aren't wall decor. They're how decisions get made here.
Growth at Mindtickle looks like owning more, not just doing more. Your scope will outgrow your job title if you want it to. You'll work alongside people who've scaled revenue tech globally, get direct feedback from leaders invested in your development, and take on challenges before you feel ready because that's how the best growth happens.
Our team spans 5+ countries, backgrounds, and perspectives. We believe the best products are built by people who bring different ways of seeing the same problem - and everyone has a seat at that table.
Learn more: Culture • Product • Customers • Recognition
Follow us: LinkedIn • Twitter / X • YouTube
We believe the best products are built by teams with different backgrounds, experiences, and ways of seeing the world. We welcome every unique identity, and we mean that.
Equal Opportunity Statement
Mindtickle is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, national origin, disability, protected veteran status, or any other characteristic protected by law.
Your Right to Work: In compliance with applicable laws, all persons hired will be required to verify identity and eligibility to work in the respective work locations and to complete the required employment eligibility verification document form upon hire.
Job Details
Experience
Mid