Senior Information Security Analyst, Global Security Risk

2 days ago


London, Greater London, United Kingdom PlayStation Global Full time

Why PlayStation?

PlayStation isn't just the Best Place to Play — it's also the Best Place to Work. Today, we're recognized as a global leader in entertainment producing The PlayStation family of products and services including PlayStation5, PlayStation4, PlayStationVR, PlayStationPlus, acclaimed PlayStation software titles from PlayStation Studios, and more.

PlayStation also strives to create an inclusive environment that empowers employees and embraces diversity. We welcome and encourage everyone who has a passion and curiosity for innovation, technology, and play to explore our open positions and join our growing global team.

The PlayStation brand falls under Sony Interactive Entertainment, a wholly-owned subsidiary of Sony Group Corporation.

PlayStation is looking for a Senior Information Security Analyst for a 12-month fixed-term contract to join our team and operate the day-to-day Information Security, Risk and Compliance management processes. This is a mixture of processing requests from the business and driving internal security projects such as updating processes and frameworks. This role requires a sound understanding of technical and engineering terminology, and an outstanding ability to articulate risk across any security domains (technical and governance) with the proven ability to work independently and process high volumes of security requests on a weekly basis. This role also provides ample opportunity to work across technical and game-related projects with studio and PlayStation engineering teams and therefore requires risk advisory and influencing experience. 

Based in London, you will act as a primary business relationship partner for several European PlayStation Studios, providing risk advisory services. This role will liaise directly with business, technical and third-party stakeholders, as well as work collaboratively with our other Information Security specialist teams across the globe to protect PlayStation's intellectual property, data and infrastructure whilst delivering new and evolving games, services and hardware to the market. This is an opportunity to provide security directly to the global PlayStation business and our global Studios and their game development. 

What you'll be doing:  

  • Review, triage, risk assess and process security requests from technical, engineering and business stakeholders that require security input and approvals. 
  • Work independently to understand stakeholder requirements and the security risk involved. Use security policy, process and information security expertise to advise stakeholders on appropriate solutions that do not open PlayStation up to security risks. 
  • Review security requirements associated with third party engagement requests and determine what level of third-party assurance is required.  
  • Initiate and support the third-party due diligence and assurance assessment processes and able to articulate and advise on associated risks to the business, contractual requirements and resulting recommendations. 
  • Articulate and communicate risk to relevant stakeholders, whilst with technical teams, partners, and leadership teams to translate security risk into mitigation plans into action items. 
  • Negotiates, tracks and reports these remediation efforts within the PlayStation risk programme. 
  • Coordinates all aspects of information security and provides consulting services to business units and other partners. 
  • Works with business partners from across PlayStation and Studios to identify and implement information security requirements related to projects and engagements. 
  • Monitors and reviews IT security controls to identify operational efficiency. 
  • Performing security audits related to critical systems and prioritized business scopes. 
  • Triage information security incidents, working with our 24/7 SOC teams, business partners and related third parties, as well as being responsible for reporting and raising where necessary. 
  • Works with GRC and other security tools to collect and maintain security and risk information. 
  • Maintains broad knowledge of industry trends in the field of information security and other technologies relevant to systems handled by the operations teams. 
  • Advances the InfoSec program via partnerships with shared services teams within information security. 

What we're looking for:  
At least five years of related work experience within Information Security risk management or security audit, with a sound technical understanding of information technology, network or infrastructure management.  

  • Must be a self-starter, comfortable with processing security requests independently initiating discussion with stakeholders to drill down on exact requirements and how it aligns to process and policy. 
  • Comfortable operating in an environment where requirements are sometimes ambiguous or incomplete, and able to proactively uncover the real security needs 
  • Experience in business partner/stakeholder management, across technical and non-technical stakeholders. 
  • Used to working within KPIs and SLAs to ensure efficient responses and smooth ticket management. 
  • Experience in Jira, Confluence and GRC tracking and assessment tools. 
  • Can independently perform information Security due diligence and audits, identifying gaps and recommending appropriate mitigations. 
  • Excellent attention to detail and meticulous in approach, with excellent verbal and written communication and outstanding independent problem-solving experience 
  • Proven technical background in Information Security including work related to cloud infrastructure, SaaS applications, emerging technology. 
  • Must be able to understand technical terminology to understand and assess security environment. 
  • Experience with third party due diligence and contract reviews. 
  • Excellent communicator, able to translate both technical and business requirements and terminology to the applicable audience.  

Desirable Knowledge and Skills:  

  • Familiarity with AWS (or similar) cloud security and infrastructure. 
  • Knowledge of and experience with SaaS and web infrastructure security 
  • Experience with third party due diligence 
  • Awareness of security risks associated with AI and other emerging technologies 
  • Microsoft Windows and Apple Mac OS hardening 
  • Policy administration 
  • Security standards such as ISO 27001, NIST (CSF,
  • Ability to handle parallel tasks and accurately detail resolutions 
  • Bachelor's degree in Computer Science, Information Security, or related field or equivalent experience 
  • CISSP and/ or CCSP preferred 

Equal Opportunity Statement:

Sony is an Equal Opportunity Employer. All persons will receive consideration for employment without regard to gender (including gender identity, gender expression and gender reassignment), race (including colour, nationality, ethnic or national origin), religion or belief, marital or civil partnership status, disability, age, sexual orientation, pregnancy, maternity or parental status, trade union membership or membership in any other legally protected category.

We strive to create an inclusive environment, empower employees and embrace diversity. We encourage everyone to respond. 

PlayStation is a Fair Chance employer and qualified applicants with arrest and conviction records will be considered for employment.


  • Security Manager

    1 week ago


    London, Greater London, United Kingdom Information Security Solutions Full time £120,000 - £160,000 per year

    We are searching for candidates that match the role below:Title………………………Security ManagerCompany………………Financial ServicesLocation………………..LondonWorking pattern……Hybrid – 2 days per week in the officeSalary……………………£120,000 - £160,000The RoleWe are seeking a Security Manager to lead security...


  • London, Greater London, United Kingdom Xcede Full time

    Lead Information Security AnalystWe're partnering with a leading digital business that takes cyber risk seriously. Their InfoSec team is award-winning, collaborative, and one of the most gender-diverse in the industry.They're looking for aLead Information Security Analystto strengthen their security governance, risk, and compliance functions — ensuring...


  • London, Greater London, United Kingdom Oliver Bernard Full time £70,000 per year

    Information Security Analyst - FinTech - £70KOur client is a growing London SaaS company, working with clients across tech, trading, pharma and ecommerce around the world.Offering hybrid working, they're looking for an experienced Information Security / Cyber Security Analyst / Engineer to join them.You'll work directly with the CTO, CRO and IT teams to...


  • London, Greater London, United Kingdom Barclay Simpson Full time

    We're working with a leading financial services business committed to maintaining the highest standards of data protection and integrity across its cloud environments. They are seeking a dedicated Senior Information Security Analyst to focus on Cloud Security GRC.In this role, you'll lead cloud risk assessments, enforce security policies and standards, and...


  • London, Greater London, United Kingdom a-e77a-4835-bd2f-990673b69389 Full time £780,000 per year

    Role DescriptionAre you an experienced professional in information security looking to lead efforts in enhancing an organization's security posture? Allianz is seeking a dedicated Risk and Controls Information Security Senior Analyst to join our team.In this role you will take a leading position in maintaining and enhancing the organization's information...


  • London, Greater London, United Kingdom GoHenry Full time £40,000 - £80,000 per year

    Information Security Risk Analyst II | GoHenryGoHenry is a UK-based fintech company created by parents to pioneer financial education. More recently, GoHenry moved into Europe and the US by joining forces with French fintech company PixPay and US investing app, Acorns.Together, Acorns, PixPay, and GoHenry have over 6 million members across 5 countries. We...


  • London, Greater London, United Kingdom Robert Walters Full time

    My client, an International bank, based in London, is looking for an Information Security Analyst to join it's team. Three MUST for this role: 1) Three days per week in the office 2) They dont offer sponsorship 3) You must come from banking or financial services background 4) Must have at least 2/3 years experience in your current firmAbout The Information...


  • London, Greater London, United Kingdom Squarepoint Capital Full time £104,000 - £128,000 per year

    Position Overview:Squarepoint is seeking an Information Security Analyst to join the Security Operations team. The Information security Analyst provides first line of support for security inquires, manages vulnerability assessments, assesses third-party vendors and software requests, and investigates and responds to security alerts. The ideal candidate has a...


  • London, Greater London, United Kingdom Harmonic Security Full time £70,000 - £120,000 per year

    About  Harmonic SecurityHarmonic Security lets teams adopt AI tools safely by protecting sensitive data in real time with minimal effort. It gives enterprises full control and stops leaks so that their teams can innovate confidently.We are led by cybersecurity experts and backed by top investors including N47, Ten Eleven Ventures, and In-Q-Tel.As...


  • London, Greater London, United Kingdom Harmonic Security Full time £80,000 - £120,000 per year

    About  Harmonic SecurityHarmonic Security lets teams adopt AI tools safely by protecting sensitive data in real time with minimal effort. It gives enterprises full control and stops leaks so that their teams can innovate confidently.We are led by cybersecurity experts and backed by top investors including N47, Ten Eleven Ventures, and In-Q-Tel.As...