GRC Engineer
ZBD is a fintech company for games. It provides embedded real-money rewards, payments, payouts, debit cards, and embedded accounts to help game studios improve player engagement, retention, and revenue.
Projects
About ZBD
ZBD provides a platform for the full money lifecycle in games, including player funding, in-game value movement, real-money rewards, payouts, debit cards, and embedded accounts. Its products are aimed at game studios and apps that want to integrate financial features and programmable rewards into gameplay. ZBD manages payment compliance, KYC, AML, and payout flows, and offers a Unity-native SDK for embedding rewards and cash-out experiences.
Skills
About the Role
You will design, implement, and maintain security compliance frameworks and risk management programs. You will conduct cybersecurity and third-party risk assessments, identify security and policy gaps, and improve systems and architectures. You will maintain compliance with relevant frameworks, develop security standards and documentation, support cloud recovery and backup solutions, collaborate with engineers, and participate in an on-call rotation.
Requirements
- 3+ years of experience in security governance, cloud and application security assessments, risk management, and/or third-party risk.
- Understanding of cybersecurity principles, cloud security, and identity and access management.
- Understanding of cloud computing principles.
- Experience with Infrastructure as Code using Terraform or OpenTofu.
- Working knowledge of Linux.
- Experience with metrics gathering, alerting, and reporting.
- Experience with Git, GitLab, and CI/CD pipelines.
- Ability to design, implement, and improve cybersecurity solutions.
- Ability to balance cybersecurity initiatives with business initiatives.
- Ability to identify and analyze potential methods of attack.
Responsibilities
- Conduct cybersecurity risk assessments, including third-party and vendor risk evaluations.
- Identify and address security and policy gaps in systems and architectures.
- Maintain compliance with relevant frameworks, including SOC 2, DORA, GDPR, and PCI DSS.
- Design, implement, and maintain security solutions that address vulnerabilities and risks.
- Collaborate with software engineers and developers to maintain security compliance.
- Develop and enforce technical security standards, patterns, and best practices.
- Maintain security documentation, policies, procedures, and technical guides.
- Develop and maintain cloud recovery and backup solutions.
- Participate in an on-call rotation.
- Document processes and procedures.
