814,841open jobs
52,433companies
131,214added this week
Browse all
Location
Hybrid
Seniority
Staff · 8+ years exp

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Sep 24, 2026.

Overview
Company
Impact
Profile match
Leading game testing and technology services at GlobalStep - your top choice in game testing companies globally.

Shift Timing : 3 PM-12 AM

About GlobalStep

GlobalStep is a global creative and technology services company in the video games industry, supporting leading game developers and publishers across studios in the USA, Canada, UK, Romania, Portugal, and India.

We partner deeply in the game development lifecycle-handling pre-release game builds, assets, and sensitive IP across services including art production, engineering, QA, localization, and player engagement.

With a distributed studio model, hybrid workforce, and high-value client IP, security is mission-critical to our business and growth.

Why This Role

  • Greenfield opportunity to build and scale a global security program
  • Own end-to-end security architecture and implementation
  • Build and mature a SOC from the ground up
  • Direct exposure to global clients, audits, and publisher expectations
  • Work in a high-impact, IP-sensitive environment
  • Strong pathway toward Head of Security / CISO roles

Role Purpose

This role is responsible for designing, building, and operationalizing GlobalStep’s cybersecurity program across a distributed, hybrid, and high-growth environment.

You will act as the single-threaded owner of security, while working closely with internal IT teams and external partners to implement scalable, enterprise-grade security controls.

Key Responsibilities

1. Security Architecture & Strategy

  • Design and implement end-to-end security architecture across:
    • Identity & Access
    • Endpoints & Devices
    • Network & Segmentation
    • Logging & Monitoring
    • Data Protection

  • Establish identity as the primary control plane:
    • MFA, RBAC, PAM, Conditional Access

  • Drive Zero Trust-aligned access models
  • Implement client/project-level environment segregation

2. Cross-Functional Collaboration

  • Work closely with:
    • Network Administrators (segmentation, firewall policies, VPN)
    • M365 / Identity specialists (Entra ID, Conditional Access, collaboration security)

  • Align security architecture with IT infrastructure and cloud strategy
  • Act as the bridge between security and IT operations teams

3. Identity & Access Management (Critical Focus Area)

  • Manage access for a high-churn workforce (FTEs, contractors, freelancers)
  • Implement strong Joiner-Mover-Leaver (JML) lifecycle controls
  • Enforce:
    • Least privilege access
    • Privileged access separation
    • Elimination of orphaned accounts

  • Align access provisioning with project-based roles and groups

4. Endpoint, Device & BYOD Security

  • Define and enforce controls for:
    • Corporate devices
    • Lab/testing devices
    • BYOD endpoints

  • Implement:
    • Endpoint detection & response (EDR)
    • Device compliance and hardening

  • Establish differentiated trust models:
    • Full access → managed devices
    • Restricted access → BYOD

5. Security Monitoring, SIEM & SOC

  • Select, deploy, and operationalize SIEM platform
  • Onboard logs across identity, endpoint, network, and infrastructure systems
  • Design and build a multi-tier SOC, including:
    • Tier 1 monitoring
    • Tier 2 investigation
    • Detection engineering
    • Threat hunting

  • Develop detection use cases and response playbooks

6. SOC/NOC Leadership & Capability Building

  • Lead and manage a team of network and security professionals supporting:
    • SOC (Security Operations)
    • NOC (Network Operations)

  • Define:
    • Roles and responsibilities
    • Escalation models
    • Performance metrics
    • Career paths through skill gap analysis and focused training programs

  • Ensure 24x7 monitoring readiness as the program matures

7. Incident Response & Threat Management

  • Lead response to:
    • Security incidents
    • Threats and vulnerabilities

  • Develop playbooks for:
    • Ransomware
    • Account compromise
    • Data exfiltration / IP leakage

  • Drive root cause analysis and continuous improvement

8. Data & Game IP Protection (Core Business Risk)

  • Design and implement controls to protect high-value game IP
  • Implement:
    • Data Loss Prevention (DLP)
    • File access monitoring
    • Access traceability

  • Enforce:
    • USB restrictions
    • Screen capture controls

  • Monitor for unusual data access and movement patterns

9. Network & Infrastructure Security

  • Work with network teams to implement studio-level segmentation
  • Reduce lateral movement and enforce controlled east-west traffic
  • Secure remote access (VPN and evolving models)

10. Vendor & Partner Management

  • Engage with third-party vendors and service providers for:
    • Security tool deployment
    • Implementation support
    • Ongoing platform management

  • Evaluate vendors and ensure alignment with security architecture and standards

11. Governance, Risk & Compliance

  • Develop and enforce security policies and procedures
  • Own:
    • Client security audits
    • Questionnaires
    • Compliance requirements

  • Interface with client security stakeholders

12. Security Operations & Scaling

  • Support a centralized security operations model (Pune hub)
  • Build systems that scale from ~1400 to ~2800 users
  • Embed security into business and IT processes

Must-Have

  • 8-15 years of experience in cybersecurity
  • Proven experience building or scaling security programs
  • Strong hands-on expertise in:
    • SIEM / SOC operations
    • Incident response
    • Identity & access management

  • Experience working cross-functionally with IT, network, and cloud teams
  • Experience managing or leading SOC/NOC or security operations teams
  • Experience building team capability, training frameworks, or career paths
  • Experience working with external vendors / implementation partners
  • Strong understanding of:
    • Network security and segmentation
    • Access control models

  • Excellent communication and stakeholder management skills

Good-to-Have

  • Experience with:
    • Microsoft Entra ID
    • CrowdStrike (or similar EDR)
    • Microsoft Intune
    • Microsoft Sentinel / Splunk / QRadar
    • DLP / data protection tools

  • Experience in:
    • Gaming, media, VFX, or IP-sensitive industries

  • Familiarity with:
    • Zero Trust architectures
    • BYOD security models

  • Certifications:
    • CISSP, CISM, CEH or equivalent

Success Metrics

  • Improvement in security maturity and visibility
  • Effective incident detection and response
  • Reduction in risk of IP leakage
  • Successful rollout of security tools and platforms
  • Strong SOC/NOC performance and team capability growth
  • Clear career progression and upskilling within the security team
  • Positive outcomes in client audits and security reviews

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
814,841 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $97k – $220k per year (Estimated) • In office • Wayne
Cybersecurity
ISO 27001
PCI DSS
SOC 2
GDPR
HIPAA
SIEM
Apply
≈ $118k – $216k per year (Estimated) • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • United States
DevOps
Azure
Cybersecurity
Microsoft Sentinel
Zero Trust
Least Privilege
Microsoft Defender for Cloud
Apply
≈ $38k – $86k per year (Estimated) • Hybrid • 3+ years exp • Thessaloniki
Python
PowerShell
C#
AI/ML
Red Teaming
Cybersecurity
Burp Suite
Metasploit
Nmap
Nessus
Cobalt Strike
Impacket
BloodHound
MITRE ATT&CK
OWASP
Analytics
Microsoft Excel
Management
Agile
Apply
$122k – $140k per year • Remote (United States) • Full-Time • 8+ years exp • Bachelor's Degree • United States
AI/ML
Model Context Protocol
Prompt Engineering
Human-in-the-Loop
DevOps
GitHub
Cybersecurity
Snyk
Nessus
Qualys Cloud Platform
ISO 27001
Wiz
NIST CSF
PCI DSS
SOC 2
CVSS
EPSS
QA
Postman
Apply
$45k – $71k per year • In office • Full-Time • Tokyo
AI/ML
ChatGPT
DevOps
GitHub
Cybersecurity
SIEM
Management
Slack
Miro
Google Workspace
Apply
$99k – $130k per year • In office • 2+ years exp • Richardson
DevOps
Windows Server
Linux
Windows
DNS
VPN
Cybersecurity
Zero Trust
Apply
$132k – $219k per year • Remote (United States) • Full-Time • 12+ years exp • Bachelor's Degree • United States
C
C
SDL
DevOps
Docker
Kubernetes
Cybersecurity
Threat Modeling
SIEM
Apply
≈ $43k – $125k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Puteaux
Cybersecurity
GDPR
Least Privilege
Apply
≈ $89k – $199k per year (Estimated) • Equity • Hybrid • Full-Time • 4+ years exp • New York
AI/ML
AI Agents
Machine Learning
DevOps
Platform Engineering
IAM
Cybersecurity
Zero Trust
Management
Slack
Marketing
Salesforce
LinkedIn
Apply
$64k – $106k per year • In office • Full-Time • 3+ years exp • Calgary
DevOps
Rest API
SOAP
Cybersecurity
Least Privilege
Apply
≈ $33k – $74k per year (Estimated) • Hybrid • 8+ years exp • Nagpur • Pune
DevOps
Splunk
Incident Management
VPN
Cybersecurity
Crowdstrike
Microsoft Sentinel
Zero Trust
Least Privilege
Microsoft Entra ID
SIEM
DLP
Apply
≈ $35k – $78k per year (Estimated) • Hybrid • 8+ years exp • Nagpur • Pune
DevOps
Incident Management
IAM
Cybersecurity
Zero Trust
Threat Modeling
SIEM
DLP
Apply
In office • 5+ years exp • High School Diploma
DevOps
Splunk
Azure
AWS
Cybersecurity
Microsoft Sentinel
ISO 27001
IBM QRadar
SIEM
Apply
In office • 8+ years exp
Python
DevOps
Rest API
Docker
Kubernetes
Linux
TCP/IP
DNS
VPN
Cybersecurity
Wireshark
Tcpdump
Apply
VP Finance 3 days ago
In office • 18+ years exp
Analytics
Microsoft Excel
Apply
See all jobs
This is one of many
814,841 more open roles from verified company boards, updated every day.