Role Overview
The Specialist, Information Security and Privacy will handle enterprise customer and prospect security RFP requests, manage third-party risk, and own the operational backbone of the compliance program across SOC 2 Type II, ISO standards, HIPAA, and DR testing.
About Mindtickle
Mindtickle is hiring a Specialist, Information Security and Privacy to join our Information Security and Privacy team in Pune. This role sits at the intersection of compliance, technical security, third-party risk management, and customer trust.
Key Responsibilities
- Serve as the main point of contact for sales and customer teams regarding security, privacy, and compliance topics, communicating with customers and prospects through RFPs, emails, or calls.
- Review customer/prospect questionnaires and security addendums, providing and building necessary information, collaterals, and resources.
- Maintain information security reports, RFP knowledgebase, and security assets for the security due diligence process utilizing existing RFP management tools.
- Own the third-party risk management process, including planning, scoping, needs analysis, ongoing project management, and communication with stakeholders.
- Conduct security due diligence on new third parties and perform periodic risk reviews of existing third parties.
Requirements & Eligibility
- 3-5 years of experience in information security and compliance, with exposure to cloud software platforms (AWS/GCP).
- Extensive experience in handling customer security queries, including RFPs, questionnaires, security architecture reviews, and data protection evaluations.
- Experience in managing third-party risk evaluation and management processes.
- Strong understanding of cloud governance and technology security controls covered in SOC 2, ISO Standards, NIST, GDPR, HIPAA, CSA STAR, CIS, etc.
Required Skills & Tech
Information SecurityComplianceSOC 2 TypeISO 27001