Specialist, Information Security and Privacy

Mindtickle

Full Time3+ yearsPosted 3 days ago

Let the right jobs find you

Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.

Overview

Position Type

Full Time

Experience

3+ years

Job Description

Key Responsibilities

  • Serve as the main point of contact for sales and customer teams regarding security, privacy, and compliance topics, communicating with customers and prospects through RFPs, emails, or calls.
  • Review customer/prospect questionnaires and security addendums, providing and building necessary information, collaterals, and resources.
  • Maintain information security reports, RFP knowledgebase, and security assets for the security due diligence process utilizing existing RFP management tools.
  • Work flexibly across all teams in the organization, driving security RFP and third-party risk management projects, including sales, customer success, product, and engineering.
  • Own the third-party risk management process, including planning, scoping, needs analysis, ongoing project management, and communication with stakeholders.
  • Conduct security due diligence on new third parties and perform periodic risk reviews of existing third parties.
  • Own and manage controls across SOC 2 Type II, ISO standards, 21 CFR Part 11, and HIPAA frameworks, maintaining an up-to-date control landscape and evidence inventory.
  • Coordinate and support external audits end-to-end - from audit scoping and evidence preparation to auditor walkthroughs and post-audit remediation tracking.
  • Manage compliance tracking across Google Workspace (Sheets, Drive, Docs, Gmail) - maintaining structured control registers, evidence repositories, and policy documentation.
  • Send and track corrective action communications to control owners, following up through resolution and maintaining a clear audit trail.
  • Conduct periodic internal compliance reviews and produce structured reports for leadership.
  • Collaborate closely with privacy, internal governance, audit, Engineering, DevOps, Legal, and HR teams to gather necessary information related to compliance and ensure controls are implemented.
  • Work with engineering, business applications, legal, and other teams as required to fulfill customer, prospect, or third-party compliance requirements.
  • Maintain and periodically review information security policies, procedures, and standards in Google Docs, ensuring they remain current and aligned with framework controls.
  • Coordinate access reviews, vendor security assessments, and third-party risk evaluations as part of the ongoing compliance calendar.
  • Undertake any other reasonable and related tasks associated with the role.

Requirements

Experience and Background

  • 3-5 years of experience in information security and compliance, with exposure to cloud software platforms (AWS/GCP).
  • Extensive experience in handling customer security queries, including RFPs, questionnaires, security architecture reviews, and data protection evaluations.
  • Experience in managing third-party risk evaluation and management processes.
  • Strong understanding of cloud governance and technology security controls covered in SOC 2, ISO Standards, NIST, GDPR, HIPAA, CSA STAR, CIS, etc.

Tooling and Workflow

  • Proficient in Google Workspace - comfortable using Sheets for control tracking, Drive and Docs for policy and evidence management, Gmail for formal communications, and Calendar for scheduling.
  • Utilize existing RFP management tools to maintain the knowledge base in line with changing customer needs, global standards, product releases, and updates.
  • Experience using Jira for cross-functional issue tracking and Slack for team collaboration.

Soft Skills and Working Style

  • Excellent communication, interpersonal, project management, and issue-resolution skills.
  • Strong written communication skills - able to draft clear policy documents, corrective action notices, and executive summaries.
  • Strong analytical and organizational skills, with the ability to work effectively as part of a team.
  • Proactive, pragmatic, and self-driven - able to learn quickly, take initiative, identify gaps, propose solutions, and drive complex projects in a fast-paced SaaS environment.

Good to have:

  • Certifications: CISSP, CISM, CISA, CRISC, CCSP, ISO 27001, ISO 42001, ISO 22301, CompTIA Security+, etc.
  • Understanding of data privacy principles under GDPR and HIPAA, including data classification, retention policies, and subject rights processes.

Required Skills

Information SecurityComplianceCloud Software PlatformsSoc2Iso DesignNistGdprHipaaCsa StarCisGoogle WorkspaceJiraSlackCxo CommunicationProject Mgmt

About the Company

Mindtickle

Bengaluru, India

Share This Job