Security Manager / Lead – Information Security (India)

Security Manager / Lead – Information Security (India)

09 Oct
|
Global Step
|
India

09 Oct

Global Step

India

Position Types: Security Manager / Lead – Information Security Position Locations: India City: Pune Experience: 8-15 Years

Shift Timing: 3 PM-12 AM

About Global Step

Global Step is a global creative and technology services company in the video games industry, supporting leading game developers and publishers across studios in the USA, Canada, UK, Romania, Portugal, and India.

We partner deeply in the game development lifecycle—handling pre-release game builds, assets, and sensitive IP across services including art production, engineering, QA, localization, and player engagement.

With a distributed studio model, hybrid workforce, and high-value client IP, security is mission-critical to our business and growth.

Why This Role

- Greenfield opportunity to build and scale a global security program
- Own end-to-end security architecture and implementation
- Build and mature a SOC from the ground up
- Direct exposure to global clients, audits, and publisher expectations
- Work in a high-impact, IP-sensitive environment
- Strong pathway toward Head of Security / CISO roles

Role Purpose

This role is responsible for designing, building, and operationalizing Global Step’s cybersecurity program across a distributed, hybrid, and high-growth setting.

You will act as the single-threaded owner of security, while working closely with internal IT teams and external partners to implement scalable, enterprise-grade security controls.

Key Responsibilities

1. Security Architecture & Strategy

- Design and implement end-to-end security architecture across: Identity & Access Endpoints & Devices Network & Segmentation Logging & Monitoring Data Protection
- Establish identity as the primary control plane: MFA, RBAC, PAM, Conditional Access
- Drive Zero Trust-aligned access models
- Implement client/project-level environment segregation

2. Cross-Functional Collaboration

- Work closely with: Network Administrators (segmentation, firewall policies, VPN) M365 / Identity specialists (Entra ID, Conditional Access, collaboration security)
- Align security architecture with IT infrastructure and cloud strategy
- Act as the bridge between security and IT operations teams

3. Identity & Access Management (Critical Focus Area)

- Manage access for a high-churn workforce (FTEs,



contractors, freelancers)
- Implement strong Joiner–Mover–Leaver (JML) lifecycle controls
- Enforce: Least privilege access Privileged access separation Elimination of orphaned accounts
- Align access provisioning with project-based roles and groups

4. Endpoint, Device & BYOD Security

- Define and enforce controls for: Corporate devices Lab/testing devices BYOD endpoints
- Implement: Endpoint detection & response (EDR) Device compliance and hardening
- Establish differentiated trust models: Full access → managed devices Restricted access → BYOD

5. Security Monitoring, SIEM & SOC

- Select, deploy, and operationalize SIEM platform
- Onboard logs across identity, endpoint, network, and infrastructure systems
- Design and build a multi-tier SOC, including: Tier 1 monitoring Tier 2 investigation Detection engineering Threat hunting
- Develop detection use cases and response playbooks

6. SOC/NOC Leadership & Capability Building

- Lead and manage a team of network and security professionals supporting: SOC (Security Operations) NOC (Network Operations)
- Define: Roles and responsibilities Escalation models Performance metrics Career paths through skill gap analysis and focused training programs
- Ensure 24×7 monitoring readiness as the program matures

7. Incident Response & Threat Management

- Lead response to: Security incidents Threats and vulnerabilities
- Develop playbooks for: Ransomware Account compromise Data exfiltration / IP leakage
- Drive root cause analysis and continuous improvement

8. Data & Game IP Protection (Core Business Risk)

- Design and implement controls to protect high-value game IP
- Implement: Data Loss Prevention (DLP) File access monitoring Access traceability
- Enforce: USB restrictions Screen capture controls
- Monitor for unusual data access and movement patterns

9. Network & Infrastructure Security





- Work with network teams to implement studio-level segmentation
- Reduce lateral movement and enforce controlled east-west traffic
- Secure remote access (VPN and evolving models)

10. Vendor & Partner Management

- Engage with third-party vendors and service providers for: Security tool deployment Implementation support Ongoing platform management
- Evaluate vendors and ensure alignment with security architecture and standards

11. Governance, Risk & Compliance

- Develop and enforce security policies and procedures
- Own: Client security audits Questionnaires Compliance requirements
- Interface with client security stakeholders

12. Security Operations & Scaling

- Support a centralized security operations model (Pune hub)
- Build systems that scale from ~1400 to ~2800 users
- Embed security into business and IT processes

Must-Have

- 8–15 years of experience in cybersecurity
- Proven experience building or scaling security programs
- Strong hands-on expertise in:SIEM / SOC operations Incident response Identity & access management
- Experience working cross-functionally with IT, network, and cloud teams
- Experience managing or leading SOC/NOC or security operations teams
- Experience building team capability, training frameworks, or career paths
- Experience working with external vendors / implementation partners
- Strong understanding of: Network security and segmentation Access control models
- Excellent communication and stakeholder management skills

Good-to-Have

- Experience with: Microsoft Entra IDCrowd Strike (or similar EDR)Microsoft Intune Microsoft Sentinel / Splunk / QRadar DLP / data protection tools
- Experience in: Gaming, media, VFX, or IP-sensitive industries
- Familiarity with: Zero Trust architectures BYOD security models
- Certifications: CISSP, CISM, CEH or equivalent

Success Metrics

- Improvement in security maturity and visibility
- Effective incident detection and response
- Reduction in risk of IP leakage
- Successful rollout of security tools and platforms
- Strong SOC/NOC performance and team capability growth
- Clear career progression and upskilling within the security team
- Positive outcomes in client audits and security reviews

📌 Security Manager / Lead – Information Security (India)
🏢 Global Step
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security manager / lead – information security (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: security manager / lead – information security (india) / india