- Location
- Bengaluru, Karnataka
- Workplace
- Onsite
- Department
- Technology & Security Services
- Education
- Master
- Source
- Lever
Description
About MoonPay
MoonPay is for builders with something to prove.
This isn't a "work on cool crypto stuff" company. It's a high-standards, high-velocity, high-accountability company building the operating system for value movement. If the internet moves information, we move value: crypto, stablecoins, tokenized assets, and whatever comes next. Four offerings make that real: fund, tokenize, trade, and spend. 30M+ customers and 500+ ecosystem partners run on us. Licensed in the U.S. Regulated across the UK, EU, Canada, and Australia.
AI is the default operating mode here. It's woven into every role, and we expect you to use it daily. It handles the manual work so you can deliver on what actually matters.
You'll thrive here if outcomes excite you more than process, if impact motivates you more than titles, and if you want hard problems, real ownership, and teammates who love winning, building, and doing it together.
The bar is high. The pace is real. We're building for what's next, for humans and agents.
Recent recognition:
Forbes' America's Best Startup Employers 2026 . 2nd in Crypto Services on Fortune's inaugural Crypto 100,
The Sunday Times Best Places to Work two years running.
Research has shown that women are less likely than men to apply for this role if they do not have experience in 100% of these areas. Please know that this list is indicative, and that we would still love to hear from you even if you feel that you are only a 75% match. Skills can be learned, diversity cannot.
Locations Supported 🌍
-
India - Bengaluru
Relocation available: No
Work pattern:
-
This role will be on-site
-
Rotational Shifts
-
24x7 follow-the-sun model
About the Opportunity
👉Join the Security Operations Center as a SOC Analyst, a critical frontline role responsible for protecting the organization against security threats and operational disruptions across 24×7 rotation. You'll be at the intersection of security and operations, monitoring real-time alerts, investigating suspicious activity, responding to incidents, and supporting infrastructure operations. This role is perfect for someone who thrives in a fast-paced environment where multiple security and IT issues can converge at once, and who wants to build deep expertise across both security-focused and operational-support workflows.
What You Will Do
-
Monitor real-time security alerts and investigate suspicious network, endpoint, and cloud activity through SIEM queries and threat-analysis tools to detect emerging threats.
-
Identify, declare, document, and escalate security incidents in line with established incident-response (IR) playbooks, ensuring rapid containment and remediation.
-
Analyze and remediate email-based threats including phishing, malware, spoofing attempts, and manage endpoint device security through EDR workflows and MDM policies.
-
Act as the first-line point of contact for IT requests including password resets, account unlocks, hardware provisioning, email/collaboration-platform issues, and application access problems
-
Maintain accurate and timely ticket documentation, case notes, and incident summaries, contribute to runbook improvements, process documentation, and knowledge base articles to support team efficiency.
-
Monitor external attack surface including brand-impersonation activity, fraudulent domain registrations, social-engineering threats, and validate honeytoken decoys to detect unauthorized lateral-movement attempts.
About You
Must-have experience and skills
-
2+ years of hands-on experience in a Security Operations Center, security monitoring, or incident-response role, demonstrated ability to triage alerts, investigate incidents, and execute incident-response procedures.
-
Experience investigating data-exfiltration indicators including unusual file transfers, large data-volume anomalies, credential harvesting attempts, and unauthorized cloud-service access
-
Solid understanding of IT infrastructure concepts including networks (IP, DNS, ports, protocols), endpoints (macOS), and identity systems (IAM, SSO, MFA).
-
Experience with incident-response frameworks (MITRE ATT&CK), incident-command models and familiarity with ticketing systems (Jira, Linear or similar).
-
Detail-oriented with strong documentation discipline. Able to write clear, concise incident summaries and shift notes, reliable follow-through on tasks and comfortable asking clarifying questions rather than making assumptions.
-
Proactive problem-solver and analytical-thinker with sound judgment about when to escalate vs. when to investigate further.
Nice-to-have experience
-
Bachelor's degree in Cybersecurity, Computer Science or Information Technology.
-
Proficiency with Okta for SSO/authentication workflows, admin console operations, and user access management is highly preferred.
-
Experience with Jamf for Apple/macOS device management
-
Exposure to Google SecOps, DoControl, Code42 and Cloudflare email security.