Security GRC Analyst
rockstargames · Bengaluru, Karnataka, India
Experience: 3+ years of experience
At Rockstar Games, we create world-class entertainment experiences.
Become part of a team working on some of the most rewarding, large-scale creative projects to be found in any entertainment medium - all within an inclusive, highly-motivated environment where you can learn and collaborate with some of the most talented people in the industry.
Rockstar is on the lookout for a talented Security Analyst within Security GRC to support Security Compliance Operations through recurring control validation, evidence review, reporting preparation, and remediation tracking. This role will help determine whether key security safeguards are operating as intended by performing manual and semi-automated validation activities, analyzing evidence from multiple sources, documenting control gaps, and preparing clear reporting that helps interpret validation results.
This is a full-time permanent position based out of Rockstar’s studio in Bangalore, India.
## WHAT WE DO
• The Rockstar Games Security team is responsible for advancing the state of information security across the company globally in collaboration with numerous partners and stakeholders by prioritizing and executing security initiatives that drive down risk.
• We strive to understand the threat landscape affecting our development studios, the gaming industry, and the world at large to define information security policies, standards, and procedures to safeguard our business and protect our players.
• We lead efforts to build enterprise security controls ranging from endpoint protection technologies to security incidents and event monitoring solutions.
• We have a passion for identifying threats and vulnerabilities and coming up with clever solutions to mitigate or remediate those risks.
## RESPONSIBILITIES
• Perform recurring manual and semi-automated validation of security controls to confirm safeguards are operating as intended.
• Collect, review, and organize evidence from systems, tools, reports, and stakeholders to support control validation, audit readiness, and compliance reporting.
• Analyze validation results to identify control gaps, exceptions, inconsistencies, and trends that may require remediation or further review.
• Support the maintenance of control validation procedures, evidence standards, reporting templates, and control health metrics.
• Track remediation actions, follow up on open items, and help ensure control gaps are documented, prioritized, and progressed to closure.
• Partner with technology and security stakeholders to clarify evidence needs, validate findings, and support practical remediation of control gaps.
• Work with colleagues to help identify repeatable validation activities that can be improved through automation or enhanced reporting.
• Support audits, assessments, and compliance reviews by preparing evidence, validating control operation, and responding to information requests.
• Provide support for broader Security Risk Management activities, including risk documentation, issue tracking, metrics preparation, and continuous improvement of GRC processes.
## REQUIREMENTS
• Bachelor’s degree in Cybersecurity, Computer Science, or a related field.
• 3+ years of experience in security compliance, GRC, technology risk, security operations, or a related cybersecurity role.
• Strong written and verbal communication skills to deliver concise compliance reporting and trend analysis, with a proven ability to translate complex technical evidence and validation results into actionable insights for diverse stakeholders.
• Familiarity with security control domains such as identity and access management, vulnerability management, patch management, endpoint security, cloud configuration, logging and monitoring, and third-party access.
• Ability to review evidence, compare data, identify exceptions, and determine whether controls are operating as intended.
• Ability to develop clear, concise reporting that communicates validation results, control gaps, remediation status, trends, and compliance posture.
• Familiarity with the CIS Critical Security Controls and related frameworks, with awareness of how controls are validated and reported.
• Strong attention to detail, organizational skills, and follow-through when managing recurring validation activities, evidence requests, and reporting cycles.
## PLUSES
Please note that these are desirable skills and are not required to apply for the position.
• Relevant certifications in cybersecurity, audit, risk, or compliance domains, such as Security+, CISA, CISSP, CRISC, or similar certifications.
## HOW TO APPLY
Please apply with a CV and cover letter demonstrating how you meet the skills above. If we would like to move forward with your application, a Rockstar recruiter will reach out to you to explain next steps and guide you through the process.
Rockstar is committed to creating a work environment that promotes equal opportunity, dignity and respect. In line with this commitment, Rockstar will provide reasonable accommodations to qualified job applicants with disabilities during the recruitment process in order for such applicants to be considered for the position for which they are applying, as well as to qualified employees to enable them to perform the essential functions of their roles. If you need more information about Rockstar’s reasonable accommodation policies or process, or need to request an accommodation, please notify your recruiter during the interview process.
If you’ve got the right skills for the job, we want to hear from you. We encourage applications from all suitable candidates regardless of age, disability, gender identity, sexual orientation, religion, belief, race, or any other protected category.
#LI-RN1
Become part of a team working on some of the most rewarding, large-scale creative projects to be found in any entertainment medium - all within an inclusive, highly-motivated environment where you can learn and collaborate with some of the most talented people in the industry.
Rockstar is on the lookout for a talented Security Analyst within Security GRC to support Security Compliance Operations through recurring control validation, evidence review, reporting preparation, and remediation tracking. This role will help determine whether key security safeguards are operating as intended by performing manual and semi-automated validation activities, analyzing evidence from multiple sources, documenting control gaps, and preparing clear reporting that helps interpret validation results.
This is a full-time permanent position based out of Rockstar’s studio in Bangalore, India.
## WHAT WE DO
• The Rockstar Games Security team is responsible for advancing the state of information security across the company globally in collaboration with numerous partners and stakeholders by prioritizing and executing security initiatives that drive down risk.
• We strive to understand the threat landscape affecting our development studios, the gaming industry, and the world at large to define information security policies, standards, and procedures to safeguard our business and protect our players.
• We lead efforts to build enterprise security controls ranging from endpoint protection technologies to security incidents and event monitoring solutions.
• We have a passion for identifying threats and vulnerabilities and coming up with clever solutions to mitigate or remediate those risks.
## RESPONSIBILITIES
• Perform recurring manual and semi-automated validation of security controls to confirm safeguards are operating as intended.
• Collect, review, and organize evidence from systems, tools, reports, and stakeholders to support control validation, audit readiness, and compliance reporting.
• Analyze validation results to identify control gaps, exceptions, inconsistencies, and trends that may require remediation or further review.
• Support the maintenance of control validation procedures, evidence standards, reporting templates, and control health metrics.
• Track remediation actions, follow up on open items, and help ensure control gaps are documented, prioritized, and progressed to closure.
• Partner with technology and security stakeholders to clarify evidence needs, validate findings, and support practical remediation of control gaps.
• Work with colleagues to help identify repeatable validation activities that can be improved through automation or enhanced reporting.
• Support audits, assessments, and compliance reviews by preparing evidence, validating control operation, and responding to information requests.
• Provide support for broader Security Risk Management activities, including risk documentation, issue tracking, metrics preparation, and continuous improvement of GRC processes.
## REQUIREMENTS
• Bachelor’s degree in Cybersecurity, Computer Science, or a related field.
• 3+ years of experience in security compliance, GRC, technology risk, security operations, or a related cybersecurity role.
• Strong written and verbal communication skills to deliver concise compliance reporting and trend analysis, with a proven ability to translate complex technical evidence and validation results into actionable insights for diverse stakeholders.
• Familiarity with security control domains such as identity and access management, vulnerability management, patch management, endpoint security, cloud configuration, logging and monitoring, and third-party access.
• Ability to review evidence, compare data, identify exceptions, and determine whether controls are operating as intended.
• Ability to develop clear, concise reporting that communicates validation results, control gaps, remediation status, trends, and compliance posture.
• Familiarity with the CIS Critical Security Controls and related frameworks, with awareness of how controls are validated and reported.
• Strong attention to detail, organizational skills, and follow-through when managing recurring validation activities, evidence requests, and reporting cycles.
## PLUSES
Please note that these are desirable skills and are not required to apply for the position.
• Relevant certifications in cybersecurity, audit, risk, or compliance domains, such as Security+, CISA, CISSP, CRISC, or similar certifications.
## HOW TO APPLY
Please apply with a CV and cover letter demonstrating how you meet the skills above. If we would like to move forward with your application, a Rockstar recruiter will reach out to you to explain next steps and guide you through the process.
Rockstar is committed to creating a work environment that promotes equal opportunity, dignity and respect. In line with this commitment, Rockstar will provide reasonable accommodations to qualified job applicants with disabilities during the recruitment process in order for such applicants to be considered for the position for which they are applying, as well as to qualified employees to enable them to perform the essential functions of their roles. If you need more information about Rockstar’s reasonable accommodation policies or process, or need to request an accommodation, please notify your recruiter during the interview process.
If you’ve got the right skills for the job, we want to hear from you. We encourage applications from all suitable candidates regardless of age, disability, gender identity, sexual orientation, religion, belief, race, or any other protected category.
#LI-RN1