Senior Security GRC Analyst
Core
Establishing governing policies, standards, and risk assessment frameworks to enable risk-informed decisions for Roblox's global community of developers and creators.
Role type
Senior Security GRC Analyst
Builds
A portfolio of governing policies, scalable risk assessment methods, and oversight processes for the Information Security organization.
Domain
Cybersecurity Governance, Risk, and Compliance (GRC) for a digital platform/metaverse
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Risk assessment methodologies (including FAIR), policy creation and management, control design validation, security risk identification, compliance framework knowledge, stakeholder partnership with engineering and legal
Preferred skills
Automation of risk management processes, supply chain risk management, AI risk management, education and guidance on security concepts
Technologies
FAIR, risk management automation tools
Responsibilities
Write, revise, and manage information security policies, standards, and procedures; Identify and assess information security risks and implement controls; Partner with Engineering, Legal, and leadership to design a 'risk first' governance function; Provide regular reporting to the Board of Directors and Audit & Compliance Committee; Validate control design and effectiveness; Support ongoing risk monitoring and reporting
Seniority
Senior, hands-on IC