SOC Analyst

Moonpay
Bengaluru +1 more
On-site

Who this role is best for

Strong fit for candidates who thrive in on-site, 24x7 rotational environments and have hands-on security monitoring experience.

Best fit for

  • Candidates with 2+ years in SOC or incident response roles and a focus on threat analysis and documentation
    β€” β€œ2+ years of hands-on experience in a Security Operations Center”
  • Individuals who enjoy combining security and operational workflows in a fast-paced setting
    β€” β€œYou'll be at the intersection of security and operations”
  • Proficient in macOS endpoint management and threat analysis tools like SIEM and EDR
    β€” β€œSolid understanding of IT infrastructure concepts including networks (IP, DNS, ports, protocols), endpoints (macOS)”

Things to consider

  • On-site presence is mandatory with no remote flexibility in this location
    β€” β€œThis role will be on-site”
  • Candidates must be comfortable with rotating shifts and 24x7 operations
    β€” β€œ24x7 follow-the-sun model”

How to stand out

  • Emphasize experience with incident response frameworks like MITRE ATT&CK in your resume and interviews
    β€” β€œExperience with incident-response frameworks (MITRE ATT&CK)”
  • Showcase your ability to document incidents clearly and contribute to process improvements
    β€” β€œMaintain accurate and timely ticket documentation”
  • Highlight your familiarity with SIEM, EDR, and threat analysis tools in your application materials
    β€” β€œMonitor real-time security alerts and investigate suspicious network, endpoint, and cloud activity through SIEM queries and threat-analysis tools”
  • Demonstrate your proactive problem-solving approach with examples from past investigations
    β€” β€œProactive problem-solver and analytical-thinker”
Pace Β· Fast PacedCollaboration Β· HighAutonomy Β· MediumDecision Impact Β· Team

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • Monitor real-time security alerts and investigate suspicious activity
  • Identify, declare, document, and escalate security incidents
Typical background
Experience in security operations or related field

Skills & requirements

Required

Security MonitoringIncident ResponseThreat AnalysisIT Support

Preferred

SIEM QueriesEDR WorkflowsMDM PoliciesHoneytoken Validation

Stack & domain

SIEMThreat-analysisEDRMDMSecurityOperations

About the role

Original posting from Moonpay via Lever

About MoonPay

MoonPay is for builders with something to prove.

This isn't a "work on cool crypto stuff" company. It's a high-standards, high-velocity, high-accountability company building the operating system for value movement. If the internet moves information, we move value: crypto, stablecoins, tokenized assets, and whatever comes next. Four offerings make that real: fund, tokenize, trade, and spend. 30M+ customers and 500+ ecosystem partners run on us. Licensed in the U.S. Regulated across the UK, EU, Canada, and Australia.

AI is the default operating mode here. It's woven into every role, and we expect you to use it daily. It handles the manual work so you can deliver on what actually matters.

You'll thrive here if outcomes excite you more than process, if impact motivates you more than titles, and if you want hard problems, real ownership, and teammates who love winning, building, and doing it together.

The bar is high. The pace is real. We're building for what's next, for humans and agents.

Recent recognition:

Forbes' America's Best Startup Employers 2026 . 2nd in Crypto Services on Fortune's inaugural Crypto 100,Β 

The Sunday Times Best Places to Work two years running.

Research has shown that women are less likely than men to apply for this role if they do not have experience in 100% of these areas. Please know that this list is indicative, and that we would still love to hear from you even if you feel that you are only a 75% match. Skills can be learned, diversity cannot.

______________________________________________________________________________________________________

Locations Supported 🌍

India - Bengaluru

Relocation available: No

Work pattern:

This role will be on-site

Rotational Shifts

24x7 follow-the-sun model

About the Opportunity

πŸ‘‰Join the Security Operations Center as a SOC Analyst, a critical frontline role responsible for protecting the organization against security threats and operational disruptions across 24Γ—7 rotation. You'll be at the intersection of security and operations, monitoring real-time alerts, investigating suspicious activity, responding to incidents, and supporting infrastructure operations. This role is perfect for someone who thrives in a fast-paced environment where multiple security and IT issues can converge at once, and who wants to build deep expertise across both security-focused and operational-support workflows.

What You Will Do

Monitor real-time security alerts and investigate suspicious network, endpoint, and cloud activity through SIEM queries and threat-analysis tools to detect emerging threats.

Identify, declare, document, and escalate security incidents in line with established incident-response (IR) playbooks, ensuring rapid containment and remediation.

Analyze and remediate email-based threats including phishing, malware, spoofing attempts, and manage endpoint device security through EDR workflows and MDM policies.

Act as the first-line point of contact for IT requests including password resets, account unlocks, hardware provisioning, email/collaboration-platform issues, and application access problems

Maintain accurate and timely ticket documentation, case notes, and incident summaries, contribute to runbook improvements, process documentation, and knowledge base articles to support team efficiency.

Monitor external attack surface including brand-impersonation activity, fraudulent domain registrations, social-engineering threats, and validate honeytoken decoys to detect unauthorized lateral-movement attempts.

About You

Must-have experience and skills

2+ years of hands-on experience in a Security Operations Center, security monitoring, or incident-response role, demonstrated ability to triage alerts, investigate incidents, and execute incident-response procedures.

Experience investigating data-exfiltration indicators including unusual file transfers, large data-volume anomalies, credential harvesting attempts, and unauthorized cloud-service access

Solid understanding of IT infrastructure concepts including networks (IP, DNS, ports, protocols), endpoints (macOS), and identity systems (IAM, SSO, MFA).

Experience with incident-response frameworks (MITRE ATT&CK), incident-command models and familiarity with ticketing systems (Jira, Linear or similar).

Detail-oriented with strong documentation discipline. Able to write clear, concise incident summaries and shift notes, reliable follow-through on tasks and comfortable asking clarifying questions rather than making assumptions.

Proactive problem-solver and analytical-thinker with sound judgment about when to escalate vs. when to investigate further.

Nice-to-have experience

Bachelor's degree in Cybersecurity, Computer Science or Information Technology.

Proficiency with Okta for SSO/authentication workflows, admin console operations, and user access management is highly preferred.

Experience with Jamf for Apple/macOS device management

Exposure to Google SecOps, DoControl, Code42 and Cloudflare email security.

______________________________________________________________________________________________________

Benefits & Perks πŸ’‘

πŸ’° Competitive salary package

🀝 Equity package: financial freedom starts with our employees, so all employees have ownership at MoonPay

πŸ“ˆ Pay-for-performance equity bonus: those who drive outsized outcomes receive outsized rewards

πŸš€ Moonshot award: we honor exceptional impact. 10 employees twice a year, each earning a $250,000 equity grant

πŸ“ŠPension: employer contributions from day one

🎁Employee referral program: refer great people, earn 10K in USDC

🏝 Flexible Time Off: choose when to work and when to switch off

πŸŽ‚ Birthday leave: take the day off to celebrate you

🍼 Enhanced parental leave: more time with family, no second thought

🌍 Hybrid working schedule: work fully remotely or from your nearest Moonbase

πŸš† Commuter benefits: public transport to and from the office

🩺 Private healthcare benefits: to protect you and your loved ones

🧘 Wellhub wellness membership: access to gyms, studios, classes, and wellness apps in one membership

πŸ€– Unlimited enterprise access to the latest AI tools: Claude, ChatGPT, Gemini and whatever's next

🍱 Lunch credit: meals covered on the days you're in the office

πŸͺ‘ Home office setup allowance: build the home office of your dreams

πŸ‘› Remote working allowance: those working fully remotely get a little extra for utilities

πŸŒ• Monthly product budget and zero-fee crypto transactions

πŸ“š $1,000 Annual training budget: we support your learning journey

🎯 High Potential Program: structured development, mentorship, and stretch opportunities

✈️ Regular remote company offsites: high-impact in-person sessions and hackathons

🚲 (Ireland) Cycle to Work scheme: tax-efficient bike, gear, and safety kit

πŸ”Œ (UK) EV Salary Sacrifice: lease an electric vehicle through pre-tax salary

Source: Moonpay careers (Lever)

Similar roles