Senior Cyber Security Manager - GRC

2 Months ago • 4-8 Years • Cyber Security

Job Summary

Job Description

The Senior Cyber Security Manager - GRC at Jagex is responsible for developing, implementing, and managing the company's Governance, Risk, and Compliance (GRC) framework. This role involves aligning information security policies with industry regulations and internal objectives, particularly supporting game development processes. Key responsibilities include GRC framework development (ISO 27001, NIST CSF, PCI-DSS, GDPR), risk management, compliance & audit management, training & awareness programs, and vendor/third-party risk management. The ideal candidate possesses extensive GRC experience in gaming or software development, strong knowledge of security frameworks, and experience leading security audits. Strong leadership, project management, and communication skills are essential.
Must have:
  • Extensive GRC experience in gaming/software development
  • Strong knowledge of ISO 27001, NIST CSF, PCI-DSS, GDPR
  • Experience leading security audits
  • Risk assessment & treatment plan development
  • Excellent communication skills
Good to have:
  • CISA, CISM, CRISC, or ISO 27001 Lead Implementer certifications
Perks:
  • Private Healthcare (Dental Plan)
  • Pension contributions (min 6%)
  • Employee Assistance Programme
  • Life Insurance
  • Annual performance bonus
  • Enhanced family leave
  • Flexible working hours
  • 25 days annual leave + Bank holidays

Job Details

Description

Are you a GRC specialist? Want to play a crucial role in the development, implementation, and management of the Jagex's Governance, Risk, and Compliance (GRC) framework? Want to do that for one of the worlds leading online games companies?

This position will report to the Director of Cyber Security to ensure the company’s information security policies and practices align with both industry regulations and internal strategic objectives, particularly focusing on supporting game development processes.

This is an opportunity

What you'll be doing:

GRC Framework Development:

  • Develop and implement a comprehensive GRC framework that aligns with industry standards such as ISO 27001, NIST CSF, PCI-DSS, and GDPR.
  • Manage and update the information security policies, ensuring they are current and relevant to evolving risks.
  • Ensure alignment with legal, regulatory, and contractual obligations specific to the game development industry.
  • Oversee the creation, implementation, and regular review of security policies, standards, and procedures.
  • Collaborate with business units to ensure that policies are understood, accessible, and appropriately enforced.

Risk Management:

  • Identify, assess, and manage technical and non-technical security risks associated with game development, live operations, and supporting infrastructure.
  • Develop risk treatment plans, work with game development teams to mitigate identified risks, and track remediation efforts.

Compliance & Audit Management:

  • Lead internal and external audits for compliance certifications, ensuring successful completion with minimal business disruption.
  • Manage the lifecycle of compliance initiatives such as PCI-DSS, GDPR, and other regional requirements affecting game development operations.
  • Stay informed of industry trends and changes in regulations that may impact security compliance efforts.

Training & Awareness:

  • Develop and deliver a security awareness program that targets various departments, with an emphasis on secure coding and game development practices.
  • Ensure continuous education across the company on security policies, risks, and compliance.

Vendor & Third-Party Risk Management:

  • Evaluate the security posture of third-party vendors and partners, ensuring their practices align with the company’s security policies.
  • Oversee the third-party risk management process, conducting vendor security assessments and managing associated risks.

What you'll need:

  • Extensive experience in a GRC role within the gaming, technology, or software development industries.
  • Proven experience in managing security policies, risk assessments, and compliance programs (such as ISO 27001, PCI-DSS, GDPR, etc.).

Knowledge & Skills:

  • Deep understanding of governance, risk, and compliance processes as they relate to game development.
  • Strong knowledge of security frameworks and standards like ISO 27001, NIST CSF, SOC 2, and GDPR.
  • Experience leading security audits and working with both internal and external auditors.
  • Strong risk management skills, including conducting risk assessments, developing treatment plans, and overseeing remediation efforts.
  • Excellent written and verbal communication skills, with the ability to convey complex security topics to technical and non-technical stakeholders.
  • Relevant security certifications such as CISA, CISM, CRISC, or ISO 27001 Lead Implementer.

Soft Skills:

  • Strong leadership and project management abilities, with a track record of managing cross-functional teams.
  • High attention to detail, proactive in identifying risks, and a solution-oriented approach.
  • Ability to thrive in a dynamic, fast-paced game development environment.

What we offer:

When you join Jagex you can look forward to a generous Perks & Benefits package including:

  • Private Healthcare, including Dental Plan.
  • Minimum 6% Pension contributions.
  • Employee Assistance Programme & onsite Counselling.
  • Life Insurance.
  • Discretionary annual performance bonus.
  • Enhanced family leave policies from day 1.
  • Flexible working hours.
  • 25 days annual leave + Bank holidays & the option to buy/sell holidays + so much more!

Please note that due to us approaching the Christmas & New Year break, we have many people among the hiring teams who are on annual leave or will be absent due to the studio closing over the holiday period.
This means that, in most cases, applications made during December are unlikely to proceed to interview until January 2025. We appreciate your patience during this time.

 

Collaboration is at the heart of Jagex. We love getting together with our teams to share ideas and socialise.

Flexibility really is the key to how we set up working schedules, we’ll discuss your needs with you and be transparent about the working schedules of the team you’ll be working with during our interview process.

 

About Jagex:

Make forever games with us.

Jagex is a thriving international games company with a growing library of forever game IPs for core gamers. We have such huge expertise at running games for the long term that we re-define expectations for what evergreen success looks like.

We create spaces for our players to come together – with each other and with us – inside and outside of our games. We empower our players with real influence on the game’s evolution. We help our players belong. Our community experiences give players a greater stake in what they’re playing, creating loyal forever fans.

These strengths inform our vision of our studio as a thriving international games company with a growing library of forever game IPs for core gamers. Our forever games will nurture sizable communities whose loyalty provides consistent revenues.

This in turn drives our mission: We create forever fans by empowering our community. We give players experiences worthy of their long-term time investment and actively collaborate with them to shape the games and the community for the better.

If this is something you want to be a part of, get in touch.

We have 500 of the industry’s most talented individuals in our Cambridge studio; if you share our values and ambition, we’d love to talk to you. Worried you don’t meet all the requirements in the spec? Your attitude, fresh perspective and experience is just as important to us; if you think this could be the perfect job for you, let’s talk.

Similar Jobs

ION - Senior Linux Systems Administrator - Somerset, NJ

ION

Clifton, New Jersey, United States (Hybrid)
7 Months ago
Avalanche Studios Group - Brand Marketing Lead - The Hunter, Call of the Wild Franchise

Avalanche Studios Group

Stockholm, Stockholm County, Sweden (Hybrid)
3 Months ago
Evolution - Technical Compliance Specialist

Evolution

Atlantic City, New Jersey, United States (On-Site)
2 Months ago
Company3 Method Studios - Maintenance Technician

Company3 Method Studios

New York, New York, United States (On-Site)
2 Months ago
Fluence - Jr. Controls Engineer (m/f/d) - German speaker

Fluence

Erlangen, Bavaria, Germany (Hybrid)
7 Months ago
Activision - Gaming Cloud Security Engineer

Activision

Barcelona, Catalonia, Spain (Remote)
4 Months ago
PwC - IN-Senior Manager – ERP - Sales-Ms Dynamics– Advisory  - Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
7 Months ago
ION - Markets Governance, Risk and Controls Manager

ION

India (On-Site)
7 Months ago
Mattel  Inc  - Manager IT - Governance, Risk & Compliance (GRC)

Mattel Inc

California, United States (On-Site)
5 Months ago
Arkose Labs - Senior Machine Learning Researcher

Arkose Labs

Pune, Maharashtra, India (Hybrid)
8 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Onward Search - Marketing Project Manager

Onward Search

New York, New York, United States (Remote)
3 Months ago
Tencent - Global Sourcing Hub Intern

Tencent

Tokyo, Japan (On-Site)
4 Months ago
CatFace - Studio Operations Coordinator

CatFace

Austin, Texas, United States (On-Site)
2 Months ago
PwC - Senior Associate - Risk & Regulations | Advisory [US Client]

PwC

Buenos Aires, Buenos Aires, Argentina (On-Site)
7 Months ago
ByteDance - Insider Threat Program Manager Lead, Information Security

ByteDance

Singapore (On-Site)
3 Months ago
Probably Monsters - Producer

Probably Monsters

Washington, United States (On-Site)
3 Months ago
CloudHire - Operations Support Specialist

CloudHire

Philippines (Remote)
2 Months ago
Lionbridge Games - Technical Software Test Engineer

Lionbridge Games

Mexico City, Mexico City, Mexico (On-Site)
3 Months ago
NVIDIA - Deep Learning Solution Architect

NVIDIA

Shanghai, Shanghai, China (On-Site)
4 Months ago
Next Level Business Services - Talend Developer

Next Level Business Services

Scottsdale, Arizona, United States (On-Site)
7 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Cambridge, England, United Kingdom

PlayStation Global - Director of Development Strategy and Support

PlayStation Global

United Kingdom (Remote)
8 Months ago
Cloud Imperium Games - Sound Designer

Cloud Imperium Games

Manchester, England, United Kingdom (On-Site)
2 Months ago
Haptic - Senior Game Designer

Haptic

United Kingdom (Hybrid)
5 Months ago
Sitetracker - Enterprise Account Executive (Nordics)

Sitetracker

London, England, United Kingdom (Remote)
7 Months ago
Cloud Imperium Games - Principal Programmer

Cloud Imperium Games

Manchester, England, United Kingdom (On-Site)
5 Months ago
N-iX - Senior Unreal Engine/C++ Engineer

N-iX

United Kingdom (Remote)
3 Months ago
Playground Games - Gameplay Animator (All levels) - Contract

Playground Games

England, United Kingdom (Hybrid)
4 Months ago
Lionbridge Games - Business Development Director, Games

Lionbridge Games

United Kingdom (On-Site)
3 Months ago
Alphasense - Product Specialist

Alphasense

London, England, United Kingdom (On-Site)
6 Months ago
Rackspace Technology - Sales Executive VI BT.

Rackspace Technology

England, United Kingdom (Hybrid)
5 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Saviynt - Consultant, Professional Services, IAM/IGA

Saviynt

Bengaluru, Karnataka, India (Hybrid)
7 Months ago
PwC - Workday - Senior Consultant-  Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
8 Months ago
ION - SOC Manager

ION

Noida, Uttar Pradesh, India (On-Site)
7 Months ago
Fanatics - Offensive Security Engineer III

Fanatics

Hyderabad, Telangana, India (Hybrid)
7 Months ago
PwC - Security Operations Center and Incident Response Manager

PwC

Makati, Metro Manila, Philippines (On-Site)
8 Months ago
CD PROJEKT RED - Cybersecurity Specialist

CD PROJEKT RED

Warsaw, Masovian Voivodeship, Poland (On-Site)
3 Months ago
ION - Cyber Security Analyst, Italy

ION

Turin, Piedmont, Italy (On-Site)
7 Months ago
SmileGate - Security Vulnerability Diagnosis Specialist

SmileGate

Seongnam-si, Gyeonggi-do, South Korea (On-Site)
4 Months ago
Anavation - Cloud Engineer

Anavation

Reston, Virginia, United States (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded