Senior Information Security Risk Analyst
Take-Two Interactive Software, Inc.About the role
Who We Are
Headquartered in New York City, Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. The Company develops and publishes products principally through Rockstar Games, 2K, Private Division, and Zynga. Our products are currently designed for console gaming systems, PC, and Mobile, including smartphones and tablets, and are delivered through physical retail, digital download, online platforms, and cloud streaming services. The Company’s common stock is publicly traded on NASDAQ under the symbol TTWO.
While our offices (physical and virtual) are casual and inviting, we are deeply committed to our core tenets of creativity, innovation and efficiency, and individual and team development opportunities. Our industry and business are continually evolving and fast-paced, providing numerous opportunities to learn and hone your skills. We work hard, but we also like to have fun, and believe that we provide a great place to come to work each day to pursue your passions.
The Challenge
The Information Security Risk Management team at Take-Two Interactive (T2) is an aspiring, hard working and collaborative group which works together to mature the security posture of T2 and its labels, Rockstar, 2K and Zynga. The team is looking for a Senior Information Security Risk Analyst to help manage the internal and external Information Technology (IT) risks for the organization. The analyst will assist with planning, organizing, coordinating, and performing risk assessments to identify key controls, critical risks, action plans, and recommendations.The candidate must be able to build working relationships and drive change with various levels of management on an enterprise scale, and be able to articulate how risk assessment results translate to business risk for the organization.
What You’ll Take On
- Manage the development, implementation and maturity of the Information Security (IS) risk management program.
- Lead, plan and manage the execution and delivery of risk-based cyber assessments, which may include vendors, IT applications, IT infrastructure, and IT operational process reviews, IT governance & strategy design assessments, and SOX compliance related activities.
- Communicate, track and provide guidance on remediation activities of identified security and gaps to internal (i.e., T2 business units, labels, studios) and external parties (i.e., vendors, partners).
- Prepare deliverables, reports, for review by the risk management and senior leadership that include issues, trends and other micro/macro level risks identified through the execution of IT internal control work and other assurance-related activities.
- Define and capture metrics that measure effectiveness of the overall information security program and report them to the management.
- Contribute "best practices" in terms of findings, checklists, templates, testing methods, and techniques to support and advance the risk management program.
- Serve as a trusted advisor and consultant between T2 information security and labels on internal and external information security audit requests (i.e., SOX, external compliance audits).
- Ensure compliance with information security policies and standards.
- Assist junior members of the team and perform quality review of their work.
- Oversee the design, implementation and operation of an IT Governance, Risk and Compliance (GRC) solution.
- Support T2 and labels on development and implementation of GRC workflows to meet business objectives.
- Keep abreast of the latest security, privacy, and regulatory concerns and best practices impacting T2 and labels.
- Performs other duties as assigned.
What You Bring
- Have a heart of serving, a desire to learn, and an ego in check
- 5+ years of experience in IT risk management, IT governance, or internal controls.
- Bachelor’s degree in Business Management, Risk Management, Computer Science, or equivalent job experience.
- In-depth understanding of core information technology processes and controls.
- Experience in supporting, analyzing with use of risk scoring, managing, communicating and acting as a primary resource for risk reviews (new and ongoing).
- In-depth experience with information security related work (e.g., implemented and/or conducted audits or assessments based on relevant security control frameworks), and have experience with security standards such as CIS, NIST CSF, or ISO 27001.
- Experience in leading information security, vendor or cloud security risk assessments.
- Experience with Governance, Risk, and Compliance (GRC) and vendor risk managem
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s