About the role
MoonPay is the operating system for moving value across crypto, stablecoins, and tokenized assets. With 30 million customers and 500+ ecosystem partners, the company is licensed in the U.S. and regulated across the UK, EU, Canada, and Australia. MoonPay ranks second in Crypto Services on Fortune's inaugural Crypto 100 list and has been recognized as one of America's Best Startup Employers for 2026.
The company operates at high velocity with a culture centered on outcomes, impact, and real ownership. AI is embedded across every role, and you'll use it daily to handle manual work so you can focus on what matters most. MoonPay attracts people who thrive on hard problems, value winning and building together, and prefer accountability over process.
You're joining the Technology & Security Services team as an Information Security Engineer focused on SaaS and integration security. Your work will center on protecting MoonPay's internal SaaS ecosystem, third-party integrations, APIs, and automation workflows from threats and vulnerabilities.
Your responsibilities include
- Owning the end-to-end security review process for new SaaS applications and integrations, assessing architecture, data flows, and trust boundaries before approval
- Setting and maintaining security standards across SaaS apps, APIs, plugins, webhooks, OAuth scopes, tokens, service accounts, and automation platforms
- Evaluating permissions across integrations for excessive access, cross-tenant exposure, and unauthorized use; assessing AI assistants and third-party AI tools accessing company systems
- Facilitating risk-based threat modeling for SaaS apps, scripts, and internal tools; identifying trust boundaries, abuse cases, and sensitive-data exposure with clear owners and timelines
- Reviewing Python, JavaScript, shell, and low-code automations for secrets handling, injection risks, unsafe data processing, and excessive permissions
- Conducting vendor and third-party security assessments, evaluating risk posture and reviewing SOC 2 reports as part of the SaaS approval process
- Contributing to incident response for SaaS and identity-related events
You bring hands-on technical expertise in SaaS security, integration architecture, and threat modeling. You're comfortable reviewing code and configurations for security flaws, familiar with secrets management and least-privilege principles, and experienced in vendor risk assessment. You work across technical tooling, process development, and cross-functional teams with clarity and accountability.
This is a full-time, on-site position in Bengaluru, Karnataka. You'll work 12:00 PM to 9:00 PM IST, five days per week. We encourage applications from candidates with 75% of the listed qualifications; skills can be developed, but we value the perspectives you bring.
Pay, location & hours
Salary not listed. Based in Bengaluru, Karnataka.
About Moonpay

31 open roles in this building · Company page → · See it on the map
Ripple · Sydney