Senior Cyber Security Manager - GRC

1 Month ago • 4-8 Years • Cyber Security

Job Summary

Job Description

The Senior Cyber Security Manager - GRC at Jagex will play a crucial role in developing, implementing, and managing the company's Governance, Risk, and Compliance (GRC) framework. Responsibilities include developing and implementing a comprehensive GRC framework aligned with industry standards (ISO 27001, NIST CSF, PCI-DSS, GDPR), managing information security policies, overseeing security audits, identifying and managing security risks, leading compliance initiatives, and developing security awareness programs. The role requires extensive GRC experience in gaming or software development, strong knowledge of security frameworks, and excellent communication skills. The position reports to the Director of Cyber Security and supports game development processes.
Must have:
  • Extensive GRC experience in gaming/software development
  • Manage security policies, risk assessments, compliance programs
  • Knowledge of ISO 27001, NIST CSF, PCI-DSS, GDPR
  • Lead security audits, work with internal/external auditors
  • Strong risk management skills, remediation efforts
  • Excellent communication (written and verbal)
Good to have:
  • CISA, CISM, CRISC, or ISO 27001 Lead Implementer certifications
Perks:
  • Private Healthcare, including Dental Plan
  • Pension contributions
  • Employee Assistance Programme
  • Life Insurance
  • Annual performance bonus
  • Enhanced family leave policies
  • Flexible working hours
  • 25 days annual leave + Bank holidays

Job Details

Description

Are you a GRC specialist? Want to play a crucial role in the development, implementation, and management of the Jagex's Governance, Risk, and Compliance (GRC) framework? Want to do that for one of the worlds leading online games companies?

This position will report to the Director of Cyber Security to ensure the company’s information security policies and practices align with both industry regulations and internal strategic objectives, particularly focusing on supporting game development processes.

This is an opportunity

What you'll be doing:

GRC Framework Development:

  • Develop and implement a comprehensive GRC framework that aligns with industry standards such as ISO 27001, NIST CSF, PCI-DSS, and GDPR.
  • Manage and update the information security policies, ensuring they are current and relevant to evolving risks.
  • Ensure alignment with legal, regulatory, and contractual obligations specific to the game development industry.
  • Oversee the creation, implementation, and regular review of security policies, standards, and procedures.
  • Collaborate with business units to ensure that policies are understood, accessible, and appropriately enforced.

Risk Management:

  • Identify, assess, and manage technical and non-technical security risks associated with game development, live operations, and supporting infrastructure.
  • Develop risk treatment plans, work with game development teams to mitigate identified risks, and track remediation efforts.

Compliance & Audit Management:

  • Lead internal and external audits for compliance certifications, ensuring successful completion with minimal business disruption.
  • Manage the lifecycle of compliance initiatives such as PCI-DSS, GDPR, and other regional requirements affecting game development operations.
  • Stay informed of industry trends and changes in regulations that may impact security compliance efforts.

Training & Awareness:

  • Develop and deliver a security awareness program that targets various departments, with an emphasis on secure coding and game development practices.
  • Ensure continuous education across the company on security policies, risks, and compliance.

Vendor & Third-Party Risk Management:

  • Evaluate the security posture of third-party vendors and partners, ensuring their practices align with the company’s security policies.
  • Oversee the third-party risk management process, conducting vendor security assessments and managing associated risks.

What you'll need:

  • Extensive experience in a GRC role within the gaming, technology, or software development industries.
  • Proven experience in managing security policies, risk assessments, and compliance programs (such as ISO 27001, PCI-DSS, GDPR, etc.).

Knowledge & Skills:

  • Deep understanding of governance, risk, and compliance processes as they relate to game development.
  • Strong knowledge of security frameworks and standards like ISO 27001, NIST CSF, SOC 2, and GDPR.
  • Experience leading security audits and working with both internal and external auditors.
  • Strong risk management skills, including conducting risk assessments, developing treatment plans, and overseeing remediation efforts.
  • Excellent written and verbal communication skills, with the ability to convey complex security topics to technical and non-technical stakeholders.
  • Relevant security certifications such as CISA, CISM, CRISC, or ISO 27001 Lead Implementer.

Soft Skills:

  • Strong leadership and project management abilities, with a track record of managing cross-functional teams.
  • High attention to detail, proactive in identifying risks, and a solution-oriented approach.
  • Ability to thrive in a dynamic, fast-paced game development environment.

What we offer:

When you join Jagex you can look forward to a generous Perks & Benefits package including:

  • Private Healthcare, including Dental Plan.
  • Minimum 6% Pension contributions.
  • Employee Assistance Programme & onsite Counselling.
  • Life Insurance.
  • Discretionary annual performance bonus.
  • Enhanced family leave policies from day 1.
  • Flexible working hours.
  • 25 days annual leave + Bank holidays & the option to buy/sell holidays + so much more!

Please note that due to us approaching the Christmas & New Year break, we have many people among the hiring teams who are on annual leave or will be absent due to the studio closing over the holiday period.
This means that, in most cases, applications made during December are unlikely to proceed to interview until January 2025. We appreciate your patience during this time.

 

Collaboration is at the heart of Jagex. We love getting together with our teams to share ideas and socialise.

Flexibility really is the key to how we set up working schedules, we’ll discuss your needs with you and be transparent about the working schedules of the team you’ll be working with during our interview process.

 

About Jagex:

Make forever games with us.

Jagex is a thriving international games company with a growing library of forever game IPs for core gamers. We have such huge expertise at running games for the long term that we re-define expectations for what evergreen success looks like.

We create spaces for our players to come together – with each other and with us – inside and outside of our games. We empower our players with real influence on the game’s evolution. We help our players belong. Our community experiences give players a greater stake in what they’re playing, creating loyal forever fans.

These strengths inform our vision of our studio as a thriving international games company with a growing library of forever game IPs for core gamers. Our forever games will nurture sizable communities whose loyalty provides consistent revenues.

This in turn drives our mission: We create forever fans by empowering our community. We give players experiences worthy of their long-term time investment and actively collaborate with them to shape the games and the community for the better.

If this is something you want to be a part of, get in touch.

We have 500 of the industry’s most talented individuals in our Cambridge studio; if you share our values and ambition, we’d love to talk to you. Worried you don’t meet all the requirements in the spec? Your attitude, fresh perspective and experience is just as important to us; if you think this could be the perfect job for you, let’s talk.

Similar Jobs

Employ - Senior Software Engineer

Employ

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Tesla - Magnetics Test Engineer

Tesla

Athens, Greece (On-Site)
1 Month ago
Universal Music - Director, Commercial Marketing

Universal Music

Beverly Hills, California, United States (On-Site)
1 Month ago
The Walt Disney Company - Senior Master Control Operator

The Walt Disney Company

Bristol, Connecticut, United States (On-Site)
1 Month ago
ION - Front End Developer - Italy

ION

Rome, Lazio, Italy (On-Site)
6 Months ago
PwC - Endpoint Engineer - US Client (Olivos/Barracas)

PwC

Olivos, Buenos Aires Province, Argentina (On-Site)
5 Months ago
PwC - AES SAP Security Manager - Operate

PwC

Hyderabad, Telangana, India (On-Site)
6 Months ago
Trend Micro - (Sr.) Backend Engineer

Trend Micro

Taipei City, Taiwan (On-Site)
6 Months ago
Trend Micro - (Sr.) Cloud Developer (Vision One)

Trend Micro

Taipei City, Taiwan (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Assystems - Hydrology and Hydraulic Engineer

Assystems

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Hutch - Lead Game Designer

Hutch

England, United Kingdom (Hybrid)
3 Weeks ago
Epic Games - Gameplay Systems Engineer Intern

Epic Games

Cary, North Carolina, United States (On-Site)
3 Months ago
Nielsen Holdings - Staff Software Engineer- Full Stack Developer (AM-TECH-DA-39)

Nielsen Holdings

Bengaluru, Karnataka, India (Hybrid)
5 Months ago
LeoVegas - Outbound Specialist Dutch Speaking

LeoVegas

Newcastle Upon Tyne, England, United Kingdom (On-Site)
5 Months ago
Seedify - Fundraising Manager

Seedify

Philippines (Remote)
1 Month ago
PlayStation Global - Senior Application Security Engineer

PlayStation Global

United States (Remote)
1 Month ago
Netflix - Events Manager - Korea

Netflix

Seoul, South Korea (On-Site)
3 Months ago
ByteDance - Threat Intelligence Engineer, Security Assurance - 2025 Start

ByteDance

Singapore (On-Site)
5 Months ago
Scanline VFX - VFX Editor

Scanline VFX

Seoul, South Korea (On-Site)
7 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Cambridge, England, United Kingdom

Take-Two Interactive - Business Planning and Analysis Intern (FP&A)

Take-Two Interactive

London, England, United Kingdom (On-Site)
3 Months ago
version 1 - Outsystems Technical Lead

version 1

Belfast, Northern Ireland, United Kingdom (On-Site)
3 Months ago
ION - IT/Cyber Security Analyst

ION

London, England, United Kingdom (On-Site)
6 Months ago
Deliveroo - Site Manager

Deliveroo

Manchester, England, United Kingdom (On-Site)
1 Month ago
Tesla - Inside Sales Advisor

Tesla

London, England, United Kingdom (On-Site)
1 Month ago
Hutch - Lead Game Designer

Hutch

England, United Kingdom (Hybrid)
3 Weeks ago
Take-Two Interactive - Intern, People Operations

Take-Two Interactive

London, England, United Kingdom (On-Site)
3 Months ago
ION - Project Manager - PS

ION

London, England, United Kingdom (On-Site)
6 Months ago
Activision - Senior VFX Destruction Artist

Activision

Guildford, England, United Kingdom (Hybrid)
3 Months ago
Universally Speaking - Simplified Chinese Games Tester

Universally Speaking

England, United Kingdom (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

USE Insider - Security Engineer - Red Team

USE Insider

Türkiye (Remote)
5 Months ago
Penumbra - Sr Manager Cybersecurity

Penumbra

Alameda, California, United States (On-Site)
5 Months ago
PwC - Associate - IFS - IT Infrastructure

PwC

Jakarta, Jakarta, Indonesia (On-Site)
4 Months ago
PwC - ETC, Oracle Technical Consultant - Senior Associate

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
5 Months ago
Anavation - Information Systems Security Officer - ISSO

Anavation

Reston, Virginia, United States (On-Site)
5 Months ago
PAPAYA - Chief Information Security Officer

PAPAYA

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
1 Month ago
ByteDance - Security Software Engineer

ByteDance

Singapore (On-Site)
5 Months ago
Britive - STRATEGIC ACCOUNT EXECUTIVE

Britive

(Remote)
4 Months ago
PwC - Senior Consultant en Cybersécurité GRC | CDI | H/F

PwC

Neuilly-sur-Seine, Île-de-France, France (On-Site)
6 Months ago
Rackspace Technology - Cloud Security Engineer IV

Rackspace Technology

United States (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

About The Company

A leader in creating deep and engaging forever games on PC, Console & Mobile that empower our communities. Jagex was founded in 2001 and is today one of the UK’s biggest and most respected video game developers and publishers.


Famed for its flagship MMOs RuneScape and Old School RuneScape, Jagex has welcomed more than 300 million player accounts to its world and created a $1bn lifetime franchise revenue. Today the RuneScape franchise exists beyond running games in live operations; our titles are forever games that connect and inspire millions of players, with content and experiences both inside and outside of inexhaustible game worlds.


Both RuneScape and Old School RuneScape, on PC and mobile, offer ever-evolving, highly-active worlds and our community-focused development ethos empowers players to have a real say in how each game is shaped.


Jagex has added to its skill set with the acquisitions of Pipeworks and Gamepires in 2022, bringing our expertise to titles such as SCUM, helping to make SCUM a forever game. It also works with external partners on products such as Melvor Idle and This Means Warp; bringing these titles to new and existing audiences.


Jagex employs more than 600 people at its Cambridge headquarters and around the world at Pipeworks in North America, and Gamepires in Europe. We’re always on the hunt for talented people to work across the business, to help the company to achieve its goals.

Cambridge, England, United Kingdom (Hybrid)

Cambridge, England, United Kingdom (Hybrid)

Cambridge, England, United Kingdom (Remote)

Cambridge, England, United Kingdom (Hybrid)

View All Jobs

Get notified when new jobs are added by Jagex

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug