Mimecast

Customer Framework Technical Specialist

Mimecast  •  Bengaluru, IN (Hybrid)  •  1 day ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Customer Framework Technical Specialist – Customer RFI & Audit Support

About Mimecast

Mimecast is a global cybersecurity and data governance leader redefining how organizations secure human and AI risk. Since 2003, Mimecast has stopped bad things from happening to good organizations by enabling them to work protected. Our AI-powered, API-enabled connected human risk platform is purpose-built to protect organizations from the evolving threat landscape across email, collaboration tools, and emerging AI-driven attack surfaces. As we continue to scale globally, our compliance and audit function plays a vital role in maintaining the trust our customers place in us — and this role is central to that mission.

About the Role

This role is based in our Bangalore office and reports to the Senior Manager, Framework Compliance within the Governance Certification Office (GCO). We are seeking a technically strong, self-driven Customer Framework Technical Specialist to provide technical expertise in the customer RFI process. The majority of this role's work will involve responding to customer RFIs, RFPs, and security questionnaires with accurate, technically sound answers grounded in Mimecast's security and compliance posture. When required and logistically possible, the individual will also assist the audit team on external certification audits (SOC 2, ISO 27001, and related frameworks), making this a strong development path toward broader audit and assurance work over time. The ideal candidate is someone who can "pick up and run" with limited supervision, manage competing priorities, and engage confidently with stakeholders across the organization and externally.

You will work independently on moderately complex projects, set objectives for your own area of responsibility to meet project goals, and communicate with contacts inside and outside your team to explain and interpret operational processes, practices, and procedures. You will exercise sound judgment within defined procedures and practices, with your results having a direct impact on the team and contributing to wider departmental outcomes.


Key Responsibilities

  • Serve as the technical subject matter expert responding to customer RFIs, RFPs, and security questionnaires, ensuring accurate, consistent, and timely answers within SLAs.
  • Translate technical controls (access management, change management, vulnerability management, penetration testing, cloud security) into clear, customer-facing responses.
  • Maintain and quality-check the RFP/RFI response library and other repositories used in response development.
  • Consult with internal subject matter experts across security, IT, and engineering to compile and validate responses.
  • Evaluate cloud security and compliance posture within AWS environments as it relates to customer enquiries.
  • When required and logistically possible, assist the audit team with external certification audits (SOC 2, ISO 27001, and other ISO frameworks) — supporting evidence collection, control walkthroughs, and remediation tracking.
  • Identify control gaps surfaced during RFI or audit work and provide pragmatic recommendations to stakeholders.
  • Communicate RFI/RFP progress, and, where involved, audit status, risks, and findings clearly to stakeholders at varying levels of seniority.
  • Recommend and contribute to enhancements in audit processes, documentation, and readiness as the compliance program scales.

Required Qualifications

  • 3 – 4 years of experience in IT compliance, security questionnaire/RFI management, audit, or information security roles.
  • One or more of the following certifications required: CISSP, CCSP, CEH (Certified Ethical Hacker), an AWS certification (e.g., AWS Certified Cloud Practitioner or Solutions Architect), and a well-recognized networking certification (e.g., CCNA or CompTIA Network+).
  • Strong working knowledge of ISO 27001 and related frameworks, sufficient to answer customer security questionnaires; formal audit experience is a plus but not required.
  • Exposure to or familiarity with SOC 2 and ISO 27001 audits desirable; direct audit experience is a plus, not a prerequisite.
  • Technical understanding of AWS services and cloud security controls.
  • Working knowledge of penetration testing concepts, vulnerability management, change management, and access controls.
  • Demonstrated ability to work independently under limited supervision and deliver under pressure.
  • Excellent verbal and written communication skills, with proven ability to engage diverse stakeholders.
  • Functional knowledge gained through experience; university degree or equivalent desirable, with relevant certifications and developing professional networks.
  • This is a hybrid role requiring shifted working hours to align with the West Coast (Pacific Time) US Sales Team, generally 11:00 PM – 8:00 AM IST. A consistently stable internet connection is required, alongside the standard hybrid office attendance expectations.

Preferred Qualifications

  • CISA certification, or ISO 27001 Lead Auditor/Implementer credential.
  • Experience in a fast-paced, multi-framework compliance environment.

What We’re Looking For

A proactive, growth-minded professional who thrives in complexity, brings structure to ambiguity, and can independently drive customer RFI responses to successful completion while building strong relationships with internal subject matter experts, stakeholders, and — when supporting audits — external auditors.

What We Bring

Join us to accelerate your career while working with cutting-edge technologies and leading impactful initiatives for our customers. You will be immersed in a dynamic environment that recognises and celebrates your achievements.

Mimecast offers formal and on-the-job learning opportunities, maintains a comprehensive benefits package that helps our employees and their family members sustain a healthy lifestyle, and importantly, working in cross-functional teams to build your knowledge.

We believe in growth that’s good, we have a culture that cares and we are on a mission that matters.

Belonging at Mimecast

Cybersecurity is a community effort. That’s why we’re committed to building an inclusive, diverse community that celebrates and welcomes everyone – unless they’re a cybercriminal, of course.

We’re proud to be an Equal Opportunity and Affirmative Action Employer, and we’d encourage you to join us whatever your background. We particularly welcome applicants from traditionally underrepresented groups.

We consider everyone equally: your race, age, religion, sexual orientation, gender identity, ability, marital status, nationality, or any other protected characteristic won’t affect your application.

Due to certain obligations to our customers, an offer of employment will be subject to your successful completion of applicable background checks, conducted in accordance with local law.

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment.



LI-GK1

Belonging at Mimecast

Cybersecurity is a community effort. That’s why we’re committed to building an inclusive, diverse community that celebrates and welcomes everyone – unless they’re a cybercriminal, of course.

We’re proud to be an Equal Opportunity and Affirmative Action Employer, and we’d encourage you to join us whatever your background. We particularly welcome applicants from traditionally underrepresented groups.

We consider everyone equally: your race, age, religion, sexual orientation, gender identity, ability, marital status, nationality, or any other protected characteristic won’t affect your application.

Due to certain obligations to our customers, an offer of employment will be subject to your successful completion of applicable background checks, conducted in accordance with local law.

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment.

Mimecast

About Mimecast

Human Risk, Secured

Mimecast is transforming the way businesses manage and secure human risk. Its AI-powered, API-enabled connected human risk platform is purpose-built to protect organizations from the spectrum of cyber threats. Integrating cutting-edge technology with human-centric pathways, our platform enhances visibility and provides strategic insight. Our technology safeguards critical data and actively engages employees in reducing risk and enhancing productivity. More than 42,000 businesses worldwide trust Mimecast to help them keep ahead of the ever-evolving threat landscape. From insider risk to external threats, customers get more with Mimecast. More visibility. More agility. More control. More security.

For help, please email support@mimecast.com.

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
London, GB
Year Founded
2003
Social Media