Mindtickle

Specialist, Information Security and Privacy at Mindtickle (Pune, India)

Mindtickle· Pune, India·

Role details

Work type
Onsite
Employment
Full-Time

Job description

Mindtickle is hiring a Specialist, Information Security and Privacy to join our Information Security and Privacy team in Pune. This role sits at the intersection of compliance, technical security, third-party risk management, and customer trust. You will be responsible for various functions related to the security, privacy, and protection of Mindtickle's growing cloud platform.

Your role will involve handling enterprise customer and prospect security RFP requests, managing third-party risk, and owning the operational backbone of our compliance program across SOC 2 Type II, ISO (27001, 22301, 27701, 27017, 27018 & 42001), 21 CFR Part 11,  HIPAA, and DR testing. You will coordinate with customers, vendors, and internal teams to ensure Mindtickle adheres to the highest data security standards. A proactive and pragmatic approach to data security and privacy is essential as you help build systems that make compliance self-evident. This role reports to the Senior Manager, Information Security and Privacy.

Key Responsibilities

- Serve as the main point of contact for sales and customer teams regarding security, privacy, and compliance topics, communicating with customers and prospects through RFPs, emails, or calls.

- Review customer/prospect questionnaires and security addendums, providing and building necessary information, collaterals, and resources.

- Maintain information security reports, RFP knowledgebase, and security assets for the security due diligence process utilizing existing RFP management tools.

- Work flexibly across all teams in the organization, driving security RFP and third-party risk management projects, including sales, customer success, product, and engineering.

- Own the third-party risk management process, including planning, scoping, needs analysis, ongoing project management, and communication with stakeholders.

- Conduct security due diligence on new third parties and perform periodic risk reviews of existing third parties.

- Own and manage controls across SOC 2 Type II, ISO standards, 21 CFR Part 11, and HIPAA frameworks, maintaining an up-to-date control landscape and evidence inventory.

- Coordinate and support external audits end-to-end - from audit scoping and evidence preparation to auditor walkthroughs and post-audit remediation tracking.

- Manage compliance tracking across Google Workspace (Sheets, Drive, Docs, Gmail) - maintaining structured control registers, evidence repositories, and policy documentation.

- Send and track corrective action communications to control owners, following up through resolution and maintaining a clear audit trail.

- Conduct periodic internal compliance reviews and produce structured reports for leadership.

- Collaborate closely with privacy, internal governance, audit, Engineering, DevOps, Legal, and HR teams to gather necessary information related to compliance and ensure controls are implemented.

- Work with engineering, business applications, legal, and other teams as required to fulfill customer, prospect, or third-party compliance requirements.

- Maintain and periodically review information security policies, procedures, and standards in Google Docs, ensuring they remain current and aligned with framework controls.

- Coordinate access reviews, vendor security assessments, and third-party risk evaluations as part of the ongoing compliance calendar.

- Undertake any other reasonable and related tasks associated with the role.

Experience and Background

- 3-5 years of experience in information security and compliance, with exposure to cloud software platforms (AWS/GCP).

- Extensive experience in handling customer security queries, including RFPs, questionnaires, security architecture reviews, and data protection evaluations.

- Experience in managing third-party risk evaluation and management processes.

- Strong understanding of cloud governance and technology security controls covered in SOC 2, ISO Standards, NIST, GDPR, HIPAA, CSA STAR, CIS, etc.

Tooling and Workflow

- Proficient in Google Workspace - comfortable using Sheets for control tracking, Drive and Docs for policy and evidence management, Gmail for formal communications, and Calendar for scheduling.

- Utilize existing RFP management tools to maintain the knowledge base in line with changing customer needs, global standards, product releases, and updates.

- Experience using Jira for cross-functional issue tracking and Slack for team collaboration.

Soft Skills and Working Style

- Excellent communication, interpersonal, project management, and issue-resolution skills.

- Strong written communication skills - able to draft clear policy documents, corrective action notices, and executive summaries.

- Strong analytical and organizational skills, with the ability to work effectively as part of a team.

- Proactive, pragmatic, and self-driven - able to learn quickly, take initiative, identify gaps, propose solutions, and drive complex projects in a fast-paced SaaS environment.

Good to have:

- Certifications: CISSP, CISM, CISA, CRISC, CCSP,  ISO 27001, ISO 42001, ISO 22301, CompTIA Security+, etc.

- Understanding of data privacy principles under GDPR and HIPAA, including data classification, retention policies, and subject rights processes.

Why work at Mindtickle

  • Culture & Impact: The company emphasizes that "people matter most" and is focused on creating a best-in-class team to build best-in-class products.
  • Remote/Hybrid Policy: Offers a remote work program; roles in Pune, India are hybrid or on-site. San Francisco HQ is OnSite.
  • Benefits: Generous parental leave, 401(K), healthcare benefits, and family/childcare benefits.
  • Engineering & Product Culture: Opportunity to work on cutting-edge AI applied to revenue enablement; roles include Group Product Manager, UX Research Manager, and Senior Solutions Architect.
  • Global Team: Work with a diverse, international team spanning 9 countries with a strong presence in both the US and India.

Application questions