| Job Position and Company | Posted | Location | Salary | Tags |
|---|---|---|---|---|
| $117k - $150k | ||||
| $158k - $260k | ||||
| $150k - $210k | ||||
|
| ||||
ISO 9001 Certified | 400+ students | Learn more | by Metana | ||
| $90k - $130k | ||||
| $83k - $101k | ||||
| $135k - $150k | ||||
| $98k - $150k | ||||
| $121k - $180k | ||||
| $105k - $120k | ||||
| $105k - $120k | ||||
| $230k - $297k | ||||
| $85k - $115k | ||||
| $190k - $230k | ||||
| $150k - $250k |
TSS Information Security Engineer, SaaS & Integrations
About MoonPay
MoonPay is for builders with something to prove.
This isn't a "work on cool crypto stuff" company. It's a high-standards, high-velocity, high-accountability company building the operating system for value movement. If the internet moves information, we move value: crypto, stablecoins, tokenized assets, and whatever comes next. Four offerings make that real: fund, tokenize, trade, and spend. 30M+ customers and 500+ ecosystem partners run on us. Licensed in the U.S. Regulated across the UK, EU, Canada, and Australia.
AI is the default operating mode here. It's woven into every role, and we expect you to use it daily. It handles the manual work so you can deliver on what actually matters.
You'll thrive here if outcomes excite you more than process, if impact motivates you more than titles, and if you want hard problems, real ownership, and teammates who love winning, building, and doing it together.
The bar is high. The pace is real. We're building for what's next, for humans and agents.
Recent recognition:
Forbes' America's Best Startup Employers 2026 . 2nd in Crypto Services on Fortune's inaugural Crypto 100,
The Sunday Times Best Places to Work two years running.
Research has shown that women are less likely than men to apply for this role if they do not have experience in 100% of these areas. Please know that this list is indicative, and that we would still love to hear from you even if you feel that you are only a 75% match. Skills can be learned, diversity cannot.
Locations Supported 🌍
-
India, Bengaluru
Relocation available: No
Work pattern:
-
This role will be in the office.
-
On-site 5 days per week.
-
Working hours: 12:00 to 9:00 PM IST
About the Opportunity
The Security Operations (SecOps) team at MoonPay is dedicated to ensuring the security and integrity of our systems and data in an increasingly complex digital landscape. Comprising a diverse group of professionals from various regions around the globe, our multicultural team brings together a wealth of expertise and perspectives to tackle security challenges effectively.
Our mission is to identify and mitigate vulnerabilities and threats while maintaining strict compliance with security policies and relevant regulations. By leveraging advanced security measures and proactive threat detection techniques, we work diligently to safeguard our infrastructure and protect our customers’ information.
In collaboration with the IT team and other departments, we foster a culture of security awareness, sharing best practices and ensuring that everyone at MoonPay understands their role in maintaining a secure environment.
Our key responsibilities include incident response, security monitoring, endpoint security, VPN, vulnerability management, data leak protection and third-party risk management (TPRM), all of which contribute to our overarching goal: to create a secure environment for our employees, clients and partners.
Join us in our commitment to security excellence and help us build a safer future in the blockchain and payments industry!
What You Will Do
We are looking for an Information Security Engineer, SaaS & Integration Security, to join our Information Security team, focused on securing our internal SaaS ecosystem, third-party integrations, APIs, and automation workflows. In this role, you will own the security review process for new SaaS applications and integrations end to end, build out threat modeling and secure design practices across the integration lifecycle, and contribute to incident response for SaaS and identity-related events. You are a hands-on individual contributor who is comfortable working across technical tooling, process development, and cross-functional collaboration.
-
SaaS and integration security
-
Set and maintain security standards for SaaS apps, integrations, APIs, plugins, and automation platforms.
-
Assess new applications and integrations before approval, reviewing architecture, data flows, and trust boundaries.
-
Evaluate OAuth scopes, tokens, service accounts, webhooks, extensions, and marketplace apps for excessive permissions, cross-tenant exposure, and unauthorized access.
-
Define approved security patterns for APIs, non-human identities, and automation workflows.
-
Assess AI assistants and third-party AI integrations accessing company systems.
-
Detects and reduces shadow IT and unsanctioned SaaS-to-SaaS connections.
-
-
Threat modeling and secure design
-
Facilitate risk-based threat modeling for SaaS apps, integrations, APIs, scripts, and internal tools.
-
Identify trust boundaries, abuse cases, and sensitive-data exposure; ensure risks have owners, mitigations, and timelines.
-
Provide secure design alternatives when proposed solutions create unacceptable risk.
-
Maintain reusable threat models and review checklists for common integration patterns.
-
-
Script and automation security
-
Review Python, JavaScript, shell, and low-code/no-code automations for secrets handling, injection risks, unsafe data processing, and excessive permissions.
-
Promote centralized secrets management, short-lived credentials, and least privilege.
-
Build automated checks for exposed secrets and insecure configurations.
-
Provide clear remediation guidance to engineers and automation owners.
-
-
Perform targeted testing of integrations, APIs, identity flows, and configurations.
-
Vendor / Third-Party Security
-
Conduct vendor and third-party security assessments, evaluating risk posture and reviewing security questionnaires.
-
Review vendor documentation (SOC 2 reports, pen test summaries) as part of the SaaS approval process.
-
Assess third-party access to company systems and data, including sub-processor risk.
-
Reassess vendor risk over time as scope or posture changes.
-
Partner with Legal and Privacy on contractual security requirements.
-
-
L2 Incident Response (Operational Role)
-
Monitor SaaS environments for suspicious activity, unauthorized integrations, and data-leakage risks
-
Actively participate in Security Operations activities as an L2 Incident Responder.
-
Lead incidents through all stages: identification, containment, eradication, recovery, and lessons learned.
-
Serve as the primary point of contact for the SOC regarding SIEM investigations, platform behavior, detection logic, and operational troubleshooting.
-
Support continuous improvement by translating incident learnings into better detections, dashboards, and playbooks.
-
About You
👉 Describe the ideal candidate’s qualifications, skills, experience, and behaviours that show strong culture alignment.
You’re an Information Security Engineer who can both build and operate at scale. You have strong expertise in DLP and are equally comfortable with leading incident response.
You will be working primarily on the following stack: Apple systems, Google Workspace, Slack, Mimecast Code42, Okta, Crowdstrike, Cloudflare WARP, Tenable Nessus and Jamf Pro.
Must-have experience and skills
-
Experiences
-
3+ years in SaaS security, application security, cloud security, or a related defensive security role
-
Experience conducting technical security reviews and risk-based threat modeling
-
Track record of assessing third-party integrations, APIs, and vendor risk before adoption
-
Experience validating security findings and driving remediation with engineering/business teams
-
-
Cybersecurity Principles
-
Strong grasp of least privilege, defense in depth, and trust boundary analysis
-
Solid understanding of identity and access concepts: OAuth, SAML, OIDC, SSO, MFA
-
Familiarity with common integration risks: excessive permissions, cross-tenant exposure, insecure data flows, injection, credential exposure, supply-chain compromise
-
Working knowledge of frameworks such as OWASP, MITRE ATT&CK, NIST, or CIS Controls
-
-
Technical Proficiency
-
Ability to read and review scripts in Python, JavaScript, or shell for security weaknesses
-
Understanding of secrets management, short-lived credentials, and secure API design
-
Hands-on experience securing identity and productivity platforms such as Okta, Google Workspace, and Google Cloud Platform
-
Experience assessing security and access controls in collaboration/SaaS tools such as Linear, Slack, Notion, Intercom, and Atlassian (Jira/Confluence)
-
Comfort building or using automated checks/tooling to detect exposed secrets, misconfigurations, or permission risks across a SaaS-first stack
-
-
Analytical Skills
-
Excellent analytical and problem-solving abilities.
-
-
Crisis Management
-
Ability to work effectively under pressure.
-
Capable of handling multiple incidents simultaneously.
-
-
Communication
-
Strong communication and interpersonal skills to collaborate with various teams.
-
Nice-to-have experience
-
Education
-
Bachelor's degree in Computer Science, Information Security, or a related field. Equivalent work experience will be considered.
-
-
Security Frameworks
-
Experience with frameworks such as ISO 27001, SOC 2, and PCI-DSS.
-
Responsible for defining and implementing key security controls.
-
-
Incident Response
-
Practical incident response experience including triage, investigation, containment, and communications.
-
-
Vulnerability Management
-
Identifying, prioritizing, and automating remediation of security vulnerabilities.
-
-
Vendor / Third-Party Security
-
Experience conducting vendor and third-party security assessments, including evaluating risk posture, reviewing security questionnaires, and ensuring third parties meet organizational security standards.
-
Bonus Points
👉 Optional extras that would help a candidate stand out (keep this short).
-
Certifications
-
CompTIA Security+, CySA+, CCSP or equivalent certifications are a plus.
-
OSCP, GWAPT are a plus.
-
-
Technical Proficiency
-
Proven experience with tools such as:
-
Google Workspace / Cloud Platform
-
Okta
-
Slack
-
Intercom
-
Notion
-
Linear
-
Crowdstrike
-
-
______________________________________________________________________________________________________
Benefits & Perks 💡
-
💰 Competitive salary package
-
🤝 Equity package: financial freedom starts with our employees, so all employees have ownership at MoonPay
-
📈 Pay-for-performance equity bonus: those who drive outsized outcomes receive outsized rewards
-
🚀 Moonshot award: we honor exceptional impact. 10 employees twice a year, each earning a $250,000 equity grant
-
📊Pension: employer contributions from day one
-
🎁Employee referral program: refer great people, earn 10K in USDC
-
🏝 Flexible Time Off: choose when to work and when to switch off
-
🎂 Birthday leave: take the day off to celebrate you
-
🍼 Enhanced parental leave: more time with family, no second thought
-
🌍 Hybrid working schedule: work fully remotely or from your nearest Moonbase
-
🚆 Commuter benefits: public transport to and from the office
-
🩺 Private healthcare benefits: to protect you and your loved ones
-
🧘 Wellhub wellness membership: access to gyms, studios, classes, and wellness apps in one membership
-
🤖 Unlimited enterprise access to the latest AI tools: Claude, ChatGPT, Gemini and whatever's next
-
🍱 Lunch credit: meals covered on the days you're in the office
-
🪑 Home office setup allowance: build the home office of your dreams
-
👛 Remote working allowance: those working fully remotely get a little extra for utilities
-
🌕 Monthly product budget and zero-fee crypto transactions
-
📚 $1,000 Annual training budget: we support your learning journey
-
🎯 High Potential Program: structured development, mentorship, and stretch opportunities
-
✈️ Regular remote company offsites: high-impact in-person sessions and hackathons
-
🚲 (Ireland) Cycle to Work scheme: tax-efficient bike, gear, and safety kit
-
🔌 (UK) EV Salary Sacrifice: lease an electric vehicle through pre-tax salary
How much do crypto jobs pay?
The salaries for cryptocurrency jobs vary widely depending on the specific role, industry, location, experience, and other factors
However, in general, cryptocurrency jobs tend to pay relatively well compared to other industries
Here are some examples of average salaries for popular cryptocurrency jobs:
- Blockchain Developer: The average salary for a blockchain developer in the US is around $105,000 per year, with salaries ranging from $60,000 to $180,000 per year.
- Cryptocurrency Analyst: The average salary for a cryptocurrency analyst in the US is around $85,000 per year, with salaries ranging from $50,000 to $135,000 per year.
- Cryptocurrency Trader: The average salary for a cryptocurrency trader in the US is around $95,000 per year, with salaries ranging from $40,000 to $180,000 per year.
- Marketing and PR Manager: The average salary for a marketing and PR manager in the US is around $77,000 per year, with salaries ranging from $43,000 to $128,000 per year.
- Crypto Lawyer: The average salary for a crypto lawyer in the US is around $120,000 per year, with salaries ranging from $70,000 to $200,000 per year.
Is crypto jobs legit?
Yes, cryptocurrency jobs are generally legitimate, and the industry has created many job opportunities over the years
As the cryptocurrency industry has grown, it has attracted a significant number of legitimate businesses and organizations that require talented individuals to work in various roles, such as blockchain development, cryptocurrency analysis, trading, marketing, public relations, law, and compliance, among others
However, as with any industry, there are also fraudulent job postings and scams that try to take advantage of people looking for work
It is essential to be cautious and thoroughly research any company or job opportunity before applying or accepting a position
You should always verify that the job posting is from a legitimate company and never provide sensitive personal or financial information without ensuring that the opportunity is genuine
To avoid scams, you can do the following:
- Research the company before applying for a job or accepting a job offer. Check the company's website, social media, and reviews to ensure that it is legitimate.
- Verify the job posting and contact information. Ensure that the email, phone number, or website listed in the job posting is valid.
- Don't pay for a job or training. A legitimate company will not ask you to pay for a job or training.
- Be wary of job offers that sound too good to be true. If a job offer promises a high salary or unrealistic benefits, it could be a scam.
What careers are there in crypto?
The market of cryptocurrency jobs has grown rapidly in recent years, creating a wide range of career opportunities in various sectors
Here are some of the careers in crypto that you can explore:
- Blockchain Consultant: Consultants offer advice to businesses and organizations that are exploring the implementation of blockchain technology. They help with strategic planning, implementation, and optimization.
- Blockchain Developer: Developers are responsible for creating and maintaining blockchain-based applications and smart contracts. They need to have experience in coding languages like Solidity, C++, and Python.
- Crypto Compliance Officer: These professionals ensure that businesses operating in the crypto industry comply with relevant laws and regulations.
- Crypto Journalist: A journalist who specializes in reporting on cryptocurrencies and the blockchain industry. They write news articles, feature stories, and analysis.
- Crypto Lawyer: Lawyers who specialize in the crypto industry help navigate complex regulatory and legal frameworks.
- Cryptocurrency Analyst: An analyst researches and analyzes cryptocurrencies and the market trends. They provide insights on trading, investments, and risk management.
- Cryptocurrency Educator: Educators help individuals and businesses understand the concepts and technicalities of cryptocurrencies and the blockchain technology.
- Cryptocurrency Trader: Traders buy and sell cryptocurrencies on exchanges, making profits by predicting market movements.
- Marketing and PR Manager: These professionals are responsible for promoting crypto projects, managing the brand's online presence, and building community engagement.
Can you make a career out of cryptocurrency?
Yes, it is possible to make a career out of cryptocurrency
The cryptocurrency industry has grown rapidly in recent years, and there are now many job opportunities available in various sectors related to blockchain and digital currencies
Some of the most common career paths in cryptocurrency include blockchain development, cryptocurrency trading, cryptocurrency analysis, marketing and public relations, and cryptocurrency journalism
There are also roles in cryptocurrency consulting, law, and compliance, among others
To pursue a career in cryptocurrency, it is important to have a strong understanding of the technology and how it works
This may require education or training in computer science, economics, or finance, depending on the specific career path you choose
Additionally, keeping up with the latest developments in the industry is crucial to stay competitive and relevant
As with any career, success in the cryptocurrency industry also requires a strong work ethic, dedication, and a willingness to continuously learn and adapt to new developments
While the industry is still relatively new and rapidly evolving, it has the potential to offer exciting and rewarding career opportunities for those who are passionate about the technology and willing to put in the effort to succeed.
What is crypto jobs?
Crypto jobs refer to employment opportunities in the cryptocurrency industry
This can include jobs related to the development of cryptocurrency technology, such as blockchain development, as well as jobs in crypto-related companies, such as exchanges or payment processing firms
Some examples of crypto jobs include blockchain engineers, crypto traders, and compliance specialists
These jobs often require specialized knowledge and expertise in the field of cryptocurrencies and blockchain technology.