---
title: "Specialist, Information Security and Privacy"
company: "Mindtickle"
company_url: "https://www.remjobs.works/companies/mindtickle"
url: "https://www.remjobs.works/job/mindtickle-specialist-information-security-and-privacy-b57d2b39-b447-4c75-9504-b8423f6e1a35"
apply_url: "https://jobs.lever.co/mindtickle/da0c54e2-5dca-4fb5-b236-57080dbf8648"
workplace: onsite
location: "Pune, Maharashtra"
employment_type: full-time
seniority: mid
role: devops-infrastructure
region: india
skills: ["aws", "gcp", "jira"]
date_posted: 2026-09-10T05:43:20.841Z
first_seen_by_remjobs: 2026-09-10T05:44:11.118Z
---

# Specialist, Information Security and Privacy

**Mindtickle** · Pune, Maharashtra

Apply: https://jobs.lever.co/mindtickle/da0c54e2-5dca-4fb5-b236-57080dbf8648

## About Mindtickle

The Mindtickle Revenue Enablement Platform is a solution for your entire sales team to elevate team performance, achieve more sales quotas, and drive revenue

## About the role

**Job Brief

**Mindtickle is hiring a Specialist, Information Security and Privacy to join our Information Security and Privacy team in Pune. This role sits at the intersection of compliance, technical security, third-party risk management, and customer trust. You will be responsible for various functions related to the security, privacy, and protection of Mindtickle's growing cloud platform.**
**

Your role will involve handling enterprise customer and prospect security RFP requests, managing third-party risk, and owning the operational backbone of our compliance program across SOC 2 Type II, ISO (27001, 22301, 27701, 27017, 27018 & 42001), 21 CFR Part 11, HIPAA, and DR testing. You will coordinate with customers, vendors, and internal teams to ensure Mindtickle adheres to the highest data security standards. A proactive and pragmatic approach to data security and privacy is essential as you help build systems that make compliance self-evident. This role reports to the Senior Manager, Information Security and Privacy.

######

##### Key Responsibilities

- Serve as the main point of contact for sales and customer teams regarding security, privacy, and compliance topics, communicating with customers and prospects through RFPs, emails, or calls.

- Review customer/prospect questionnaires and security addendums, providing and building necessary information, collaterals, and resources.

- Maintain information security reports, RFP knowledgebase, and security assets for the security due diligence process utilizing existing RFP management tools.

- Work flexibly across all teams in the organization, driving security RFP and third-party risk management projects, including sales, customer success, product, and engineering.

- Own the third-party risk management process, including planning, scoping, needs analysis, ongoing project management, and communication with stakeholders.

- Conduct security due diligence on new third parties and perform periodic risk reviews of existing third parties.

- Own and manage controls across SOC 2 Type II, ISO standards, 21 CFR Part 11, and HIPAA frameworks, maintaining an up-to-date control landscape and evidence inventory.

- Coordinate and support external audits end-to-end - from audit scoping and evidence preparation to auditor walkthroughs and post-audit remediation tracking.

- Manage compliance tracking across Google Workspace (Sheets, Drive, Docs, Gmail) - maintaining structured control registers, evidence repositories, and policy documentation.

- Send and track corrective action communications to control owners, following up through resolution and maintaining a clear audit trail.

- Conduct periodic internal compliance reviews and produce structured reports for leadership.

- Collaborate closely with privacy, internal governance, audit, Engineering, DevOps, Legal, and HR teams to gather necessary information related to compliance and ensure controls are implemented.

- Work with engineering, business applications, legal, and other teams as required to fulfill customer, prospect, or third-party compliance requirements.

- Maintain and periodically review information security policies, procedures, and standards in Google Docs, ensuring they remain current and aligned with framework controls.

- Coordinate access reviews, vendor security assessments, and third-party risk evaluations as part of the ongoing compliance calendar.

- Undertake any other reasonable and related tasks associated with the role.

##### Requirements

##### Experience and Background

- 3-5 years of experience in information security and compliance, with exposure to cloud software platforms (AWS/GCP).

- Extensive experience in handling customer security queries, including RFPs, questionnaires, security architecture reviews, and data protection evaluations.

- Experience in managing third-party risk evaluation and management processes.

- Strong understanding of cloud governance and technology security controls covered in SOC 2, ISO Standards, NIST, GDPR, HIPAA, CSA STAR, CIS, etc.

##### Tooling and Workflow

- Proficient in Google Workspace - comfortable using Sheets for control tracking, Drive and Docs for policy and evidence management, Gmail for formal communications, and Calendar for scheduling.

- Utilize existing RFP management tools to maintain the knowledge base in line with changing customer needs, global standards, product releases, and updates.

- Experience using Jira for cross-functional issue tracking and Slack for team collaboration.

##### Soft Skills and Working Style

- Excellent communication, interpersonal, project management, and issue-resolution skills.

- Strong written communication skills - able to draft clear policy documents, corrective action notices, and executive summaries.

- Strong analytical and organizational skills, with the ability to work effectively as part of a team.

- Proactive, pragmatic, and self-driven - able to learn quickly, take initiative, identify gaps, propose solutions, and drive complex projects in a fast-paced SaaS environment.

**Good to have

**

- Certifications: CISSP, CISM, CISA, CRISC, CCSP, ISO 27001, ISO 42001, ISO 22301, CompTIA Security+, etc.

- Understanding of data privacy principles under GDPR and HIPAA, including data classification, retention policies, and subject rights processes.

**
**

---

Source: Mindtickle's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/mindtickle-specialist-information-security-and-privacy-b57d2b39-b447-4c75-9504-b8423f6e1a35
