This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Games Workshop has an exciting opportunity for a Cyber Security Operations and Vulnerability Engineer to deliver pivotal IT Security initiatives. We are looking for someone who thrives in environments that demand resilience, decisiveness, and the courage to hold firm under pressure. As a Security and Vulnerability Engineer, you will be a key member of the wider IT function in supporting the business to safeguard Games Workshop’s digital assets, intellectual property and operational environments from cyber threats and cyber security risks. This role will see you collaborate with the wider IT team to proactively manage vulnerabilities, implement, and use threat detection tools in accordance with our change control processes. Fostering a culture of innovation and continuous improvement will ensure a seamless integration of security operations.
Job Responsibility:
Deliver pivotal IT Security initiatives
Safeguard Games Workshop’s digital assets, intellectual property and operational environments from cyber threats and risks
Collaborate with the wider IT team to proactively manage vulnerabilities
Implement and use threat detection tools in accordance with change control processes
Foster a culture of innovation and continuous improvement
Manage vulnerability tooling to assess and track risks across all platforms
Analyse vulnerability data to prioritise, coordinate and verify patching and remediation efforts
Manage the relationship with the external Security Operations Centre to enhance SIEM and SOAR tooling
Focus on reducing false positives, refining detection logic, and improving automated capabilities
Work alongside the external Security Operations Centre to monitor security alerts, manage escalations, and operationalise threat intelligence
Ensure all tasks are completed with the highest level of accuracy
Requirements:
Background in cyber security operations across a multi-site operation
Ability to influence with a drive to make positive changes
Detailed understanding of vulnerability management tools (Qualys, Tenable, or Rapid7) and how they integrate into enterprise patching and asset management
Knowledge of TCP/IP networking, OS-level security (Windows, Linux, Mac), and cloud security principles (Azure and/or AWS)
Familiarity with the full vulnerability lifecycle from discovery and assessment to risk rating, remediation, and exception management
Natural curiosity to understand systems and uncover root causes behind vulnerability
Ability to find workable solutions that balance business need and technical risk
Resilience, decisiveness, and courage to hold firm under pressure
Effective communication skills
Ability to build strong relationships across Infrastructure Teams
Ability to work with an external Security Operations Centre to enhance SIEM and SOAR tooling, monitor alerts, manage escalations, and operationalise threat intelligence
Hands-on approach to managing vulnerability tooling across endpoints, servers, websites, and mobile applications
What we offer:
33 days holiday per year (including public holidays)
Matching contributory pension scheme up to 7.5%
Profit share bonus (subject to GW meeting profit targets)