
About GlobalStep:
GlobalStep is a global creative and technology services company in the video games industry, supporting leading game developers and publishers across studios in the USA, Canada, UK, Romania, Portugal, and India.
We partner deeply in the game development lifecycle - handling pre-release game builds, assets, and sensitive IP across services including art production, engineering, QA, localization, and player engagement.
With a distributed studio model, hybrid workforce, and high - value client IP, security is mission - critical to our business and growth.
Why This Role:
- Greenfield opportunity to build and scale a global security program
- Own end - to - end security architecture and implementation
- Build and mature a SOC from the ground up
- Direct exposure to global clients, audits, and publisher expectations
- Work in a high - impact, IP - sensitive environment
- Strong pathway toward Head of Security / CISO roles
Role Purpose:
This role is responsible for designing, building, and operationalizing GlobalStep's cybersecurity program across a distributed, hybrid, and high - growth environment.
You will act as the single - threaded owner of security, while working closely with internal IT teams and external partners to implement scalable, enterprise - grade security controls.
Key Responsibilities:
1. Security Architecture & Strategy:
Design and implement end - to - end security architecture across:
1. Identity & Access
2. Endpoints & Devices
3. Network & Segmentation
4. Logging & Monitoring
5. Data Protection
Establish identity as the primary control plane:
1. MFA, RBAC, PAM, Conditional Access
2. Drive Zero Trust - aligned access models
3. Implement client/project - level environment segregation
2. Cross - Functional Collaboration:
Work closely with:
1. Network Administrators (segmentation, firewall policies, VPN)
2. M365 / Identity specialists (Entra ID, Conditional Access, collaboration security)
3. Align security architecture with IT infrastructure and cloud strategy
4. Act as the bridge between security and IT operations teams
3. Identity & Access Management (Critical Focus Area):
Manage access for a high - churn workforce (FTEs, contractors, freelancers)
Implement strong Joiner - Mover - Leaver (JML) lifecycle controls
Enforce:
1. Least privilege access
2. Privileged access separation
3. Elimination of orphaned accounts
4. Align access provisioning with project - based roles and groups
4. Endpoint, Device & BYOD Security:
Define and enforce controls for:
1. Corporate devices
2. Lab/testing devices
3. BYOD endpoints
Implement:
1. Endpoint detection & response (EDR)
2. Device compliance and hardening
3. Establish differentiated trust models:
i. Full access - managed devices
ii. Restricted access - BYOD
5. Security Monitoring, SIEM & SOC:
Select, deploy, and operationalize SIEM platform
Onboard logs across identity, endpoint, network, and infrastructure systems
Design and build a multi - tier SOC, including:
1. Tier 1 monitoring
2. Tier 2 investigation
3. Detection engineering
4. Threat hunting
5. Develop detection use cases and response playbooks
6. SOC/NOC Leadership & Capability Building:
Lead and manage a team of network and security professionals supporting:
1. SOC (Security Operations)
2. NOC (Network Operations)
Define:
1. Roles and responsibilities
2. Escalation models
3. Performance metrics
4. Career paths through skill gap analysis and focused training programs
5. Ensure 24x7 monitoring readiness as the program matures
7. Incident Response & Threat Management:
Lead response to:
1. Security incidents
2. Threats and vulnerabilities
Develop playbooks for:
1. Ransomware
2. Account compromise
3. Data exfiltration / IP leakage
4. Drive root cause analysis and continuous improvement
8. Data & Game IP Protection (Core Business Risk):
Design and implement controls to protect high - value game IP
Implement:
1. Data Loss Prevention (DLP)
2. File access monitoring
3. Access traceability
Enforce:
1. USB restrictions
2. Screen capture controls
3. Monitor for unusual data access and movement patterns
9. Network & Infrastructure Security:
Work with network teams to implement studio - level segmentation
Reduce lateral movement and enforce controlled east - west traffic
Secure remote access (VPN and evolving models)
10. Vendor & Partner Management:
Engage with third - party vendors and service providers for:
1. Security tool deployment
2. Implementation support
3. Ongoing platform management
4. Evaluate vendors and ensure alignment with security architecture and standards
11. Governance, Risk & Compliance:
Develop and enforce security policies and procedures
Own:
1. Client security audits
2. Questionnaires
3. Compliance requirements
4. Interface with client security stakeholders
12. Security Operations & Scaling:
Support a centralized security operations model (Pune hub)
Build systems that scale from ~1400 to ~2800 users
Embed security into business and IT processes
Candidate Profile:
Must - Have:
- 8 - 15 years of experience in cybersecurity
- Proven experience building or scaling security programs
- Strong hands - on expertise in:
1. SIEM / SOC operations
2. Incident response
3. Identity & access management
- Experience working cross - functionally with IT, network, and cloud teams
- Experience managing or leading SOC/NOC or security operations teams
- Experience building team capability, training frameworks, or career paths
- Experience working with external vendors / implementation partners
- Strong understanding of:
1. Network security and segmentation
2. Access control models
- Excellent communication and stakeholder management skills
Good - to - Have:
- Experience with:
1. Microsoft Entra ID
2. CrowdStrike (or similar EDR)
3. Microsoft Intune
4. Microsoft Sentinel / Splunk / QRadar
5. DLP / data protection tools
- Experience in:
1. Gaming, media, VFX, or IP - sensitive industries
- Familiarity with:
1. Zero Trust architectures
2. BYOD security models
- Certifications:
1. CISSP, CISM, CEH or equivalent
Success Metrics:
- Improvement in security maturity and visibility
- Effective incident detection and response
- Reduction in risk of IP leakage
- Successful rollout of security tools and platforms
- Strong SOC/NOC performance and team capability growth
- Clear career progression and upskilling within the security team
- Positive outcomes in client audits and security reviews
Location: Pune
Shift: 3 PM - 12 AM
Didn’t find the job appropriate? Report this Job