HamburgerMenu
hirist

Job Description

Manager IT Security - Pune Magarpatta

About GlobalStep

GlobalStep is a global creative and technology services company in the video games industry, supporting leading game developers and publishers across studios in the USA, Canada, UK, Romania, Portugal, and India.

We partner deeply in the game development lifecycle handling pre-release game builds, assets, and sensitive IP across services including art production, engineering, QA, localization, and player engagement.

With a distributed studio model, hybrid workforce, and high-value client IP, security is mission-critical to our business and growth.

Why This Role

- Greenfield opportunity to build and scale a global security program

- Own end-to-end security architecture and implementation

- Build and mature a SOC from the ground up

- Direct exposure to global clients, audits, and publisher expectations

- Work in a high-impact, IP-sensitive environment

- Strong pathway toward Head of Security / CISO roles

Role Purpose

This role is responsible for designing, building, and operationalizing GlobalStep's cybersecurity program across a distributed, hybrid, and high-growth environment.

You will act as the single-threaded owner of security, while working closely with internal IT teams and external partners to implement scalable, enterprise-grade security controls.

Key Responsibilities

1. Security Architecture & Strategy:

- Design and implement end-to-end security architecture across Identity & Access, Endpoints & Devices, Network & Segmentation, Logging & Monitoring, and Data Protection

- Establish identity as the primary control plane (MFA, RBAC, PAM, Conditional Access)

- Drive Zero Trust-aligned access models

- Implement client/project-level environment segregation

2. Cross-Functional Collaboration:

- Work closely with Network Administrators and M365/Identity specialists

- Align security architecture with IT infrastructure and cloud strategy

- Act as the bridge between security and IT operations teams

3. Identity & Access Management:

- Manage access for a high-churn workforce (FTEs, contractors, freelancers)

- Implement strong JoinerMoverLeaver (JML) lifecycle controls

- Enforce least privilege access, privileged access separation, and elimination of orphaned accounts

4. Endpoint, Device & BYOD Security:

- Define and enforce controls for corporate, lab/testing, and BYOD endpoints

- Implement endpoint detection & response (EDR) and device compliance/hardening

- Establish differentiated trust models

5. Security Monitoring, SIEM & SOC:

- Select, deploy, and operationalize SIEM platform

- Onboard logs across identity, endpoint, network, and infrastructure systems

- Design and build a multi-tier SOC (Tier 1 monitoring, Tier 2 investigation, detection engineering, threat hunting)

- Develop detection use cases and response playbooks

6. SOC/NOC Leadership & Capability Building:

- Lead and manage a team of network and security professionals

- Define roles, responsibilities, escalation models, performance metrics, and career paths

- Ensure 24x7 monitoring readiness

7. Incident Response & Threat Management:

- Lead response to security incidents, threats, and vulnerabilities

- Develop playbooks for ransomware, account compromise, and data exfiltration

- Drive root cause analysis and continuous improvement

8. Data & Game IP Protection:

- Design and implement controls to protect high-value game IP (DLP, file access monitoring, access traceability)

- Enforce USB restrictions and screen capture controls

9. Network & Infrastructure Security:

- Work with network teams to implement studio-level segmentation

- Reduce lateral movement and enforce controlled east-west traffic

- Secure remote access (VPN and evolving models)

10. Vendor & Partner Management:

- Engage with third-party vendors for security tool deployment and platform management

11. Governance, Risk & Compliance:

- Develop and enforce security policies and procedures

- Own client security audits, questionnaires, and compliance requirements

12. Security Operations & Scaling:

- Support a centralized security operations model (Pune hub)

- Build systems that scale from 1400 to 2800 users

Candidate Profile :

Must-Have :

- 8 - 15 years of experience in cybersecurity

- Proven experience building or scaling security programs

- Strong hands-on expertise in SIEM / SOC operations, incident response, and identity & access management

- Experience working cross-functionally with IT, network, and cloud teams

- Experience managing or leading SOC/NOC or security operations teams

- Experience building team capability, training frameworks, or career paths

- Experience working with external vendors / implementation partners

- Strong understanding of network security, segmentation, and access control models

- Excellent communication and stakeholder management skills

Good-to-Have :

- Experience with Microsoft Entra ID, CrowdStrike, Microsoft Intune, Microsoft Sentinel / Splunk / QRadar, and DLP tools

- Experience in gaming, media, VFX, or IP-sensitive industries

- Familiarity with Zero Trust architectures and BYOD security models

- Certifications: CISSP, CISM, CEH or equivalent

Location : Pune

Shift : 3 PM - 12 AM

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...