Who we are
Mindtickle is the market-leading revenue productivity platform that combines on-the-job learning and deal execution to get more revenue per rep. Mindtickle is recognized as a market leader by top industry analysts and is ranked by G2 as the #1 sales onboarding and training product. Weβre honoured to be recognized as a Leader in the first-ever Forrester Waveβ’: Revenue Enablement Platforms, Q3 2024!
Whatβs in it for you?
Compliance operations and audit readiness
β’
Own and manage controls across SOC 2 Type II, ISO 27001, GDPR, and HIPAA frameworks, maintaining an up-to-date control landscape and evidence inventory.
β’
Coordinate and support external audits end-to-end β from audit scoping and evidence preparation to auditor walkthroughs and post-audit remediation tracking.
β’
Manage compliance tracking across Google Workspace (Sheets, Drive, Docs, Gmail) β maintaining structured control registers, evidence repositories, and policy documentation.
β’
Send and track corrective action communications to control owners, following up through resolution and maintaining a clear audit trail.
β’
Conduct periodic internal compliance reviews and produce structured reports for leadership.
Technical security and vulnerability management
β’
Participate in Vulnerability Assessment and Penetration Testing (VAPT) cycles β reviewing findings, contextualising them for engineering teams, and tracking remediation to closure.
β’
Monitor and triage security findings from external risk and rating platforms including SecurityScorecard, Panorays, UpGuard, Whistic, ProcessUnity, Qualys SSL Labs, and similar sources.
β’
Act as the liaison between the security team and engineering β translating security findings into actionable tickets in Jira, validating fixes post-sign-off, and gradually taking ownership of resolutions.
β’
Maintain a working knowledge of common vulnerability classes (OWASP Top 10), exploits, and secure architecture patterns relevant to cloud-hosted SaaS platforms.
β’
Support cloud security reviews and configuration assessments on AWS (primary) and GCP, with an understanding of IAM, network security groups, storage controls, and logging configurations.
Compliance automation and AI-assisted workflows
β’
Build and maintain Python-based automation scripts that collect compliance evidence from internal systems, APIs, and Google Workspace β reducing manual evidence gathering for external audits.
β’
Develop automated email workflows and scheduled reports that keep control owners, team leads, and leadership informed of compliance status, upcoming obligations, and open remediation items.
β’
Create and maintain compliance dashboards that provide a real-time view of control health, audit readiness, and key risk indicators.
β’
Progressively design and deploy AI-assisted internal audit workflows β acting as the orchestrator of agentic pipelines that perform control checks, generate evidence summaries, and flag anomalies for human review.
β’
Leverage AI-assisted coding tools such as Cursor and Claude Code to accelerate development of automation and internal tooling.
Cross-functional collaboration and programme hygiene
β’
Collaborate with Engineering, DevOps, Legal, and HR teams to ensure controls are implemented, tested, and documented in alignment with framework requirements.
β’
Maintain and periodically review information security policies, procedures, and standards in Google Docs, ensuring they remain current and aligned with framework controls.
β’
Coordinate access reviews, vendor security assessments, and third-party risk evaluations as part of the ongoing compliance calendar.
β’
Support onboarding and awareness initiatives by contributing to security training content and policy communications.
Weβd love to hear from you, if you:
Experience and background
β’
2β3 years of hands-on experience in information security, GRC (Governance, Risk and Compliance), or a security-adjacent technical role.
β’
Demonstrated experience working with at least one major compliance framework (SOC 2, ISO 27001, GDPR, or HIPAA) β including evidence collection, control testing, or audit support.
β’
1+ year of programming experience, with practical Python skills for scripting, automation, or data processing tasks.
β’
Exposure to cloud platforms, with working knowledge of AWS services (IAM, S3, CloudTrail, Security Hub, or equivalent) and basic familiarity with GCP.
Technical security knowledge
β’
Understanding of common vulnerability classes, OWASP Top 10, and secure development principles sufficient to contextualise findings and communicate them to engineering teams.
β’
Familiarity with VAPT processes β including scoping, findings review, and remediation validation.
β’
Basic understanding of network security concepts: TLS/SSL, DNS, firewalls, VPNs, and cloud-native security controls.
β’
Working knowledge of authentication and identity concepts: SSO, OAuth 2.0, SAML, IAM, RBAC, and MFA.
β’
Ability to read and interpret security findings from external platforms such as SecurityScorecard, Qualys, or similar security rating and scanning tools.
Tooling and workflow
β’
Proficient in Google Workspace β comfortable using Sheets for control tracking and mapping, Drive and Docs for policy and evidence management, Gmail for formal communications and sign-offs, and Calendar for compliance scheduling.
β’
Experience using Jira for cross-functional issue tracking and Slack for team collaboration.
β’
Comfortable writing Python scripts for automation, data extraction, API integrations, or report generation.
β’
Exposure to or genuine curiosity about AI tooling, LLMs, and agent-based workflows.
Soft skills and working style
β’
Strong written communication skills β able to draft clear policy documents, corrective action notices, and executive summaries.
β’
Methodical and organised β able to manage multiple concurrent workstreams, deadlines, and stakeholders without losing detail.
β’
Comfortable with ambiguity and ad-hoc requests in a fast-paced SaaS environment.
β’
Proactive and self-driven β able to identify gaps, propose solutions, and execute independently once direction is set.
Good to have:
β’
Certifications: CISA, CISSP, CEH, CompTIA Security+, or any recognised AI / machine learning certification.
β’
Experience building or interacting with AI agents, LLM-based pipelines, or automation using frameworks such as LangChain or LangGraph.
β’
Hands-on experience with AI-assisted development tools such as Cursor or Claude Code.
β’
Familiarity with third-party risk and security rating platforms (SecurityScorecard, Panorays, UpGuard, Whistic, ProcessUnity).
β’
Prior experience with GCP services for development or workflow automation.
β’
Understanding of data privacy principles under GDPR and HIPAA, including data classification, retention policies, and subject rights processes.
β’
Exposure to SAST/DAST tooling, container security, or cloud security posture management (CSPM).
Our culture & accolades
As an organization, itβs our priority to create a highly engaging and rewarding workplace. We offer tons of awesome perks and many opportunities for growth.
Our culture reflects our employee's globally diverse backgrounds along with our commitment to our customers, and each other, and a passion for excellence. We live up to our values, DAB, Delight your customers, Act as a Founder, and Better Together.
Mindtickle is proud to be an Equal Opportunity Employer.
All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, national origin, disability, protected veteran status, or any other characteristic protected by law.
Your Right to Work - In compliance with applicable laws, all persons hired will be required to verify identity and eligibility to work in the respective work locations and to complete the required employment eligibility verification document form upon hire.