--- title: 'Information Security Engineer at MoonPay' canonical: 'https://feeny.ai/job/information-security-engineer-moonpay-india-3k9wsf50d35f' type: 'job' last_seen: '2026-09-07' --- # Information Security Engineer at MoonPay - **Company:** MoonPay - **Location:** India - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-08-11 - **Last confirmed live:** 2026-09-07 - **Apply:** https://jobs.lever.co/moonpay/202dec29-039f-4211-8d8e-4ce8e36511ab ## Job description ## About MoonPay MoonPay is for builders with something to prove. This isn't a "work on cool crypto stuff" company. It's a high-standards, high-velocity, high-accountability company building the operating system for value movement. If the internet moves information, we move value: crypto, stablecoins, tokenized assets, and whatever comes next. Four offerings make that real: fund, tokenize, trade, and spend. 30M+ customers and 500+ ecosystem partners run on us. Licensed in the U.S. Regulated across the UK, EU, Canada, and Australia. AI is the default operating mode here. It's woven into every role, and we expect you to use it daily. It handles the manual work so you can deliver on what actually matters. You'll thrive here if outcomes excite you more than process, if impact motivates you more than titles, and if you want hard problems, real ownership, and teammates who love winning, building, and doing it together. The bar is high. The pace is real. We're building for what's next, for humans and agents. Recent recognition: Forbes' America's Best Startup Employers 2026 . 2nd in Crypto Services on Fortune's inaugural Crypto 100 The Sunday Times Best Places to Work two years running Research has shown that women are less likely than men to apply for this role if they do not have experience in 100% of these areas. Please know that this list is indicative, and that we would still love to hear from you even if you feel that you are only a 75% match. Skills can be learned, diversity cannot. Locations Supported 🌍 India, Bengaluru Relocation available:No Work pattern: This role will be in the office. On-site 5 days per week. Working hours: 12:00 to 9:00 PM IST ## About the Opportunity The Security Operations (SecOps) team at MoonPay is dedicated to ensuring the security and integrity of our systems and data in an increasingly complex digital landscape. Comprising a diverse group of professionals from various regions around the globe, our multicultural team brings together a wealth of expertise and perspectives to tackle security challenges effectively. Our mission is to identify and mitigate vulnerabilities and threats while maintaining strict compliance with security policies and relevant regulations. By leveraging advanced security measures and proactive threat detection techniques, we work diligently to safeguard our infrastructure and protect our customers’ information. In collaboration with the IT team and other departments, we foster a culture of security awareness, sharing best practices and ensuring that everyone at MoonPay understands their role in maintaining a secure environment. Our key responsibilities include incident response, security monitoring, endpoint security, VPN,  vulnerability management, data leak protection and third-party risk management (TPRM), all of which contribute to our overarching goal: to create a secure environment for our employees, clients and partners. Join us in our commitment to security excellence and help us build a safer future in the blockchain and payments industry! ## What You Will Do We are looking for an Information Security Engineer, SaaS & Integration Security, to join our Information Security team, focused on securing our internal SaaS ecosystem, third-party integrations, APIs, and automation workflows. In this role, you will own the security review process for new SaaS applications and integrations end to end, build out threat modeling and secure design practices across the integration lifecycle, and contribute to incident response for SaaS and identity-related events. You are a hands-on individual contributor who is comfortable working across technical tooling, process development, and cross-functional collaboration. SaaS and integration securitySet and maintain security standards for SaaS apps, integrations, APIs, plugins, and automation platforms.Assess new applications and integrations before approval, reviewing architecture, data flows, and trust boundaries.Evaluate OAuth scopes, tokens, service accounts, webhooks, extensions, and marketplace apps for excessive permissions, cross-tenant exposure, and unauthorized access.Define approved security patterns for APIs, non-human identities, and automation workflows.Assess AI assistants and third-party AI integrations accessing company systems.Detects and reduces shadow IT and unsanctioned SaaS-to-SaaS connections. Threat modeling and secure design Facilitate risk-based threat modeling for SaaS apps, integrations, APIs, scripts, and internal tools. Identify trust boundaries, abuse cases, and sensitive-data exposure; ensure risks have owners, mitigations, and timelines. Provide secure design alternatives when proposed solutions create unacceptable risk. Maintain reusable threat models and review checklists for common integration patterns. Script and automation security Review Python, JavaScript, shell, and low-code/no-code automations for secrets handling, injection risks, unsafe data processing, and excessive permissions. Promote centralized secrets management, short-lived credentials, and least privilege. Build automated checks for exposed secrets and insecure configurations. Provide clear remediation guidance to engineers and automation owners. Perform targeted testing of integrations, APIs, identity flows, and configurations. Vendor / Third-Party SecurityConduct vendor and third-party security assessments, evaluating risk posture and reviewing security questionnaires.Review vendor documentation (SOC 2 reports, pen test summaries) as part of the SaaS approval process.Assess third-party access to company systems and data, including sub-processor risk.Reassess vendor risk over time as scope or posture changes.Partner with Legal and Privacy on contractual security requirements. L2 Incident Response (Operational Role) Monitor SaaS environments for suspicious activity, unauthorized integrations, and data-leakage risksActively participate in Security Operations activities as an L2 Incident Responder.Lead incidents through all stages: identification, containment, eradication, recovery, and lessons learned. Serve as the primary point of contact for the SOC regarding SIEM investigations, platform behavior, detection logic, and operational troubleshooting.Support continuous improvement by translating incident learnings into better detections, dashboards, and playbooks. ## About You 👉 Describe the ideal candidate’s qualifications, skills, experience, and behaviours that show strong culture alignment. You’re an Information Security Engineer who can both build and operate at scale. You have strong expertise in DLP and are equally comfortable with leading incident response. You will be working primarily on the following stack: Apple systems, Google Workspace, Slack, Mimecast Code42, Okta, Crowdstrike, Cloudflare WARP, Tenable Nessus and Jamf Pro. Must-have experience and skills Experiences3+ years in SaaS security, application security, cloud security, or a related defensive security roleExperience conducting technical security reviews and risk-based threat modelingTrack record of assessing third-party integrations, APIs, and vendor risk before adoptionExperience validating security findings and driving remediation with engineering/business teams Cybersecurity Principles Strong grasp of least privilege, defense in depth, and trust boundary analysis Solid understanding of identity and access concepts: OAuth, SAML, OIDC, SSO, MFA Familiarity with common integration risks: excessive permissions, cross-tenant exposure, insecure data flows, injection, credential exposure, supply-chain compromise Working knowledge of frameworks such as OWASP, MITRE ATT&CK, NIST, or CIS Controls Technical Proficiency Ability to read and review scripts in Python, JavaScript, or shell for security weaknesses Understanding of secrets management, short-lived credentials, and secure API design Hands-on experience securing identity and productivity platforms such as Okta, Google Workspace, and Google Cloud Platform Experience assessing security and access controls in collaboration/SaaS tools such as Linear, Slack, Notion, Intercom, and Atlassian (Jira/Confluence) Comfort building or using automated checks/tooling to detect exposed secrets, misconfigurations, or permission risks across a SaaS-first stack Analytical Skills Excellent analytical and problem-solving abilities. Crisis Management Ability to work effectively under pressure. Capable of handling multiple incidents simultaneously. Communication Strong communication and interpersonal skills to collaborate with various teams. Nice-to-have experience EducationBachelor's degree in Computer Science, Information Security, or a related field. Equivalent work experience will be considered. Security Frameworks Experience with frameworks such as ISO 27001, SOC 2, and PCI-DSS. Responsible for defining and implementing key security controls. Incident Response Practical incident response experience including triage, investigation, containment, and communications. Vulnerability Management Identifying, prioritizing, and automating remediation of security vulnerabilities. Vendor / Third-Party Security Experience conducting vendor and third-party security assessments, including evaluating risk posture, reviewing security questionnaires, and ensuring third parties meet organizational security standards. Bonus Points 👉 Optional extras that would help a candidate stand out (keep this short). Certifications CompTIA Security+, CySA+, CCSP or equivalent certifications are a plus.OSCP, GWAPT are a plus. Technical Proficiency Proven experience with tools such as: Google Workspace / Cloud Platform Okta Slack Intercom Notion Linear Crowdstrike ## About MoonPay ## Company Overview - **One-liner**: MoonPay builds payment infrastructure for crypto, allowing individuals and businesses to easily buy, sell, and swap digital assets using traditional payment methods. - **Entity Type**: Private (Venture-backed; latest round Debt Financing in April 2025) - **Headquarters**: Miami, Florida, United States - **Founded**: 2018 - **Founders**: Ivan Soto-Wright, Victor Faramond ## Core Business - **Primary industry/industries**: Fintech, Cryptocurrency, Web3 Infrastructure - **Target customers (B2B, B2C, Enterprise, SMB, etc.)**: B2B (wallets, websites, apps, enterprises needing crypto on/off ramps) and B2C (individual users buying/selling crypto). - **Mission or purpose statement**: "Help everyone own their digital future" and "bring the whole world into Web3." ## Products & Services - **On-Ramp (Buy Crypto)**: Allows users to purchase crypto with credit/debit cards, Apple Pay, Google Pay, PayPal, Venmo, Revolut Pay, and bank transfers. Integrates into any app or website for a seamless user experience. - **Off-Ramp (Sell Crypto)**: Enables users to sell crypto and withdraw fiat currency to their bank accounts or payment methods. Customizable SDK for business partners. - **MoonPay Balance**: A custodial wallet that allows users to store funds and transact within the MoonPay ecosystem. - **Enterprise & Web3 Infrastructure**: Provides smart contract tools, NFT checkout, and stablecoin management APIs for brands and enterprises to build and manage Web3 experiences. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed. - **Key Metric**: Total Funding of **$1.04 billion** (across 7 rounds) and estimated **Annual Revenue of $150 million**. - **Notable Investors/Partners**: Tiger Global Management (led Series A), Galaxy Digital (led 2025 debt financing), Coinbase Ventures, Google (via partnerships, not publicly confirmed as direct investor), and many others. Partners with 500+ companies and 300+ wallets/apps. - **Growth Signals**: 30 million customers served. Workforce of ~400+ people from 125+ nationalities across 9 key locations. Yearly headcount growth of +17% (YoY). Powering infrastructure for major brands and is fully licensed in the U.S., UK, EU, Canada, and Australia. Ranked on the Forbes Fintech 50 list. ## Competitive Advantages - **Licensed & Regulated**: Highly regulated and compliant in multiple global jurisdictions, offering a trusted on/off-ramp for mainstream adoption. - **Broad Payment Method Support**: Integrates with nearly every major payment method, lowering the barrier to entry for users. - **Enterprise-Grade Infrastructure**: Trusted by some of the world's most icconic brands for their Web3 experiences. - **Global Reach**: Availale in 160+ countries, with localized payment methods. ## Strategic Focus - **Web3 Adoption**: Continuning to build products that bridge the gap between traditional finance (TradFi) and decentralized finance (DeFi). - **Stablecoin & Institutional Growth**: Recent $200M debt facility from Galaxy Digital signals a push into stablecoin infrastructure and more institutional-grade products. - **US Compliance & Expansion**: Acively hiring for regulatory compliance specialists and focusing on state-level licensing within the US. - **Product Innovation**: Imroving wallet, smart contract, and developer tools to remain the go-to infrastructure layer for the crypto economy. ## Why Work Here - **Culture & Values**: Emphasizes a "Kaizen" (continuous improvement) mindset, autonomy ("Own It"), and a strong sense of ownership. Describes itself as having an "innovation-led culture" with extreme ownership. - **Remote/Hybrid Policy**: Global-first mindset. Offers Remote, Hybrid (e.g., New York), and Office-based roles across 9 key locations (Miami, London, Bangalore, etc.). - **Perks & Benefits**: Equity package, comprehensive private healthcare, annual training budget, home office allowance, and 3x/year offsites for Product, Engineering, and Data teams. - **Growth & Impact**: Work with a global team of experts. Strong emphasis on career autonomy and learning by doing. ## Sources 1. [moonpay.com/careers](https://www.moonpay.com/careers) - Company culture, values, and benefits. 2. [linkedin.com/company/moonpay](https://www.linkedin.com/company/moonpay) - Employee count, headcount growth, funding details, and recent hiring trends. 3. [cbinsights.com/company/moonpay](https://www.cbinsights.com/company/moonpay) - Products, competitors, and financial overview. 4. [support.moonpay.com](https://support.moonpay.com/en/articles/380731-what-is-moonpay) - Official product description and purpose. ## Other roles at MoonPay - [Staff Engineer, Agents](https://feeny.ai/job/staff-engineer-agents-moonpay-united-states-crbf0m75trd1) — United States - [Software Engineer, Agents](https://feeny.ai/job/software-engineer-agents-moonpay-united-states-dffvdn4mvkxz) — United States - [Product Manager, Crypto Asset Management](https://feeny.ai/job/product-manager-crypto-asset-management-moonpay-london-y85mhza33ww0) — London, United Kingdom - [Deputy Treasurer](https://feeny.ai/job/deputy-treasurer-moonpay-new-york-ba2qxdbaj5ex) — New York, NY - [Senior Product Manager, KYB - MoonPay Enterprise](https://feeny.ai/job/senior-product-manager-kyb-moonpay-enterprise-moonpay-london-qa3vf6c696ez) — London, United Kingdom - [Senior SOC Analyst](https://feeny.ai/job/senior-soc-analyst-moonpay-bengaluru-htbfkmhbt2xr) — Bengaluru, India - [SOC Analyst](https://feeny.ai/job/soc-analyst-moonpay-bengaluru-073wyvppm3s1) — Bengaluru, India - [Staff Machine Learning Engineer](https://feeny.ai/job/staff-machine-learning-engineer-moonpay-london-tm08v43gaqxk) — London, United Kingdom - [Chief Control Officer](https://feeny.ai/job/chief-control-officer-moonpay-new-york-kv0pmjfnqppc) — New York, NY - [Product Manager, Identity](https://feeny.ai/job/product-manager-identity-moonpay-london-1g60szwa1s3s) — London, United Kingdom