- Location
- Bengaluru, Karnataka, India
- Workplace
- Hybrid, Onsite
- Department
- Security
- Seniority
- Senior
- Experience
- 5+ years
- Source
- Greenhouse
Description
At Rockstar Games, we create world-class entertainment experiences.
Become part of a team working on some of the most rewarding, large-scale creative projects to be found in any entertainment medium - all within an inclusive, highly-motivated environment where you can learn and collaborate with some of the most talented people in the industry.
Rockstar is on the lookout for a passionate Senior Security Vulnerability Engineer to own the health, reliability, and performance of the tooling that drives our vulnerability management program. This is a hands-on platform engineering role focused on keeping vulnerability scanning, asset inventory, and reporting systems running reliably and producing accurate data. You will serve as the technical backbone of the Vulnerability Management team by ensuring scans run on schedule, data accurately reflects our network, and the tools our analysts depend on are configured, patched, tuned, and operating effectively. This role centers on administering and troubleshooting platforms that support vulnerability management across on-prem, cloud, and hybrid environments.
This is a full-time, in-office position based out of Rockstar’s large game development studio in Bangalore, India.
WHAT WE DO
- The Rockstar Games Security team is responsible for advancing the state of information security across the company globally in collaboration with numerous partners and stakeholders by prioritizing and executing security initiatives that drive down risk.
- We strive to understand the threat landscape affecting our development studios, the gaming industry, and the world at large to define information security policies, standards, and procedures to safeguard our business and protect our players.
- We lead efforts to build enterprise security controls ranging from endpoint protection technologies to security incidents and event monitoring solutions.
- We have a passion for identifying threats and vulnerabilities and coming up with clever solutions to mitigate or remediate those risks.
RESPONSIBILITIES
- Administer, maintain, and troubleshoot Tenable Nessus and Tenable Security Center, including scanner deployment, upgrades, plugin updates, scan policy configuration, and credentialed scan tuning.
- Own the lifecycle of vulnerability management tooling infrastructure, including provisioning, patching, capacity planning, and decommissioning aging scan infrastructure.
- Maintain and troubleshoot integrations across the vulnerability management tool ecosystem, including asset inventory, endpoint telemetry, cloud posture, and related security platforms.
- Pull, compile, and present monthly patch compliance data by translating raw findings into clear metrics and reporting for stakeholders and leadership.
- Diagnose and resolve scan failures, credential issues, coverage gaps, false positives or negatives, and data-quality problems affecting reporting accuracy.
- Tune scan configurations to balance coverage, performance, and impact on production systems. Develop scripts and lightweight automation using Python, APIs, or similar technologies to reduce manual effort and improve data consistency.
- Document tool configurations, runbooks, and standard operating procedures.
- Partner with infrastructure, cloud, and application teams to ensure scan coverage across on-prem, cloud, and hybrid environments.
REQUIREMENTS
- 5+ years of experience in security engineering, infrastructure, or vulnerability management role with direct, hands-on ownership of vulnerability scanning tools.
- Demonstrated administration experience with Tenable Nessus and/or Tenable Security Center, including scanner deployment, policy management, and troubleshooting.
- Strong understanding of vulnerability management concepts, including CVEs, CVSS, authenticated and unauthenticated scan types, and asset coverage.
- Working knowledge of networking, including TCP/IP, firewalls, ports, and protocols, sufficient to diagnose scan connectivity and credential issues.
- Familiarity with Windows and Linux environments, including credential and authentication mechanisms used in credentialed scanning.
- Scripting ability using Python, PowerShell, or similar technologies, with comfort working with REST APIs.
- Experience integrating security tooling with workflow platforms.
- Exposure to cloud security posture tooling and cloud-native scanning approaches.
PLUSES
Please note that these are desirable skills and are not required to apply for the position.
- Relevant certifications such as Security+, GCIH, Tenable certifications, cloud security certifications, or similar credentials.
- Experience with asset management, discovery tooling, or similar platforms.
- Experience deploying and managing exposure management, attack path analysis, or related security tooling.
HOW TO APPLY
Please apply with a resume and cover letter demonstrating how you meet the skills above. If we would like to move forward with your application, a Rockstar recruiter will reach out to you to explain next steps and guide you through the process.
Rockstar is committed to creating a work environment that promotes equal opportunity, dignity and respect. In line with this commitment, Rockstar will provide reasonable accommodations to qualified job applicants with disabilities during the recruitment process in order for such applicants to be considered for the position for which they are applying, as well as to qualified employees to enable them to perform the essential functions of their roles. If you need more information about Rockstar’s reasonable accommodation policies or process, or need to request an accommodation, please notify your recruiter during the interview process.
If you’ve got the right skills for the job, we want to hear from you. We encourage applications from all suitable candidates regardless of age, disability, gender identity, sexual orientation, religion, belief, race, or any other protected category.
#LI-SK1