Description
Scopely is looking for a Sr. Manager, Security Risk Manager to join the Information Security team remotely in Europe!At Scopely, we care deeply about what we do and want to inspire play, every day - whether in our work environments alongside our talented colleagues or through our deep connections with our communities of players. We are a global team of game lovers who are developing, publishing and innovating the mobile games industry, connecting millions of people around the world daily. What You Will Do
1. Assess compliance with internal security controls to ensure adherence to company policies and standards
2. Oversee the periodic review and governance of security policies and standards documents, ensuring they are current, effective, and appropriately governed
3. Manage the entire lifecycle of security risks from identification and assessment through mitigation, monitoring, and reporting
4. Support the continuous improvement of security controls, aligning them with NIST and ISO security framework
5. Conduct internal risk assessments to identify and address potential security risks across the organization
6. Recommend proactive improvements and strategic initiatives to address emerging security risks
7. Identify opportunities to leverage automation and AI for streamlining risk assessments, audits, and reporting processes
8. Perform third-party business partner risk assessments using our internal security questionnaire, evaluating the security posture of partners and service providers
9. Facilitate risk-gathering sessions to maintain a comprehensive understanding of the risk landscape and update the risk register accordingly
10. Manage and respond to external assessments requested by consulting firms, insurance underwriters, licensors, and business relationships that require security and data privacy evaluations
11. Collaborate with our parent company’s internal audit team, as needed, to support and align with broader security and compliance objectives
12. Document and report on findings from external assessments, providing actionable insights and recommendations to stakeholders
13. Maintain and update the risk register, ensuring it accurately reflects current risks, mitigation strategies, and status updates
14. Prepare regular reports for senior leadership on the status of security risks, compliance, and assessment outcomes
15. Develop and monitor key metrics related to security risk management, identifying trends and improvement areas
What We’re Looking For
16. Bachelor’s degree in Information Security, Computer Science, or a related field or equivalent experience
17. 6+ years of experience in security risk management, compliance, or related fields.
18. Strong knowledge of NIST, ISO 27001/27002, and other security frameworks.
19. Experience conducting internal and third-party risk assessments.
20. Familiarity with maintaining a risk register and developing risk management reports for senior leadership.
21. Strong project management skills, with the ability to oversee multiple assessments and manage competing priorities.
22. Excellent communication and interpersonal skills to collaborate effectively with internal and external stakeholders.
23. Strong ability to communicate complex security topics to both technical and non-technical stakeholders
24. Security certifications such as CISSP, CISM, CRISC, or similar are highly preferred.
25. Proven experience with security audits and compliance reviews.
26. Experience in the gaming or tech industry is a plus.
27. Proficient in risk management software and GRC tools.