Continuously delivering content to a global audience of millions of players while also building new games affords Riot's InfoSec discipline with a mountain of exciting and complex challenges. And of course, the attention of very interesting adversary groups.
That's where you come in. Riot Security Operations Engineers hold an in-depth knowledge of specific areas of expertise. We don't just focus on breaking things; we proactively support teams across Riot to develop robust security capabilities which help protect player experiences. We relish the opportunity to work with new tech stacks and product teams, each with their own unique security risk profile. At the most fundamental level, their goal is to help deliver value to players and make life harder for troublemakers.
Our Security Operations team is responsible for regularly monitoring and analyzing Riot’s security efforts across the organization and for our players. Its mission is to quickly detect, analyze, and respond to various threat actors from across the globe. The ability to not only think critically when it comes to security threats, but technically by developing tools (e.g. automating security processes) is vital to their success. From working closely with local and federal law enforcement agencies around security incidents to defending against the next DDoS, they are here to protect Riot and our players.
You will report to the Manager of Security Operations.
Responsibilities:
Lead, mentor, and develop engineers who are part of our global Security team Probe, research, and analyze security risks that directly impact players Triage and investigate security events Improve Riot's security posture by ensuring remediation, eradication and lessons learned are rolled back into day to day operations Help identify new exploits, threats and mitigations for detection engineering Contribute to and drive Riot’s global Security Operations roadmap Work with product teams throughout the incident investigation cycle to ensure proper remediation, eradication, and lessons learned are rolled back into day to day operations. Part of the US team acting as the escalation point for all security events and investigations You will be expected to do a small amount of travel as part of a global team
Required Qualifications:
5+ years of experience in an Security Operations or Incident Response role 3+ years of computer network defense (identify, protect, detect, respond, recover) experience within a Computer Incident Response organization Understanding of the life cycle of network threats, attack vectors, and methods of exploitation and common tactics, techniques, and procedures of advanced attackers You can automate common tasks in Python, Powershell, Go or a similar language Experience being a part of a highly technical team, including Incident Response, Security Engineering, or Forensics teams Experience driving efforts in and leading incident response. This should include hands on experience completing tasks like malware detection and analysis, memory analysis, or disk forensics As comfortable communicating in distributed teams as with people sitting right next to you
Desired Qualifications:
Experience working with cloud infrastructure and services such as AWS, Azure, Google Cloud, SoftLayer or Private Clouds Experience working with security tooling and logging technology (e.g. ELK, Splunk, SentinelOne, Defender ATP, Carbon Black, etc.) Experience with container security and automation such as docker, kubernetes, terraform and ansible Experience working with forensics (networking, memory, disk) Industry certifications (GCFE, GCFA, GNFA, GCIH, EnCE, CISSP) a plus, but not required
For this role, you'll find success through craft expertise, a collaborative spirit, and choices that focus on your fellow Rioters, who are the customers of your work. Being a dedicated fan of games is not necessary for this position!
Our Perks:
Riot has a focus on work/life balance, shown by our open paid time off policy, in addition to other perks such as flexible work schedules. We offer medical, dental, and life insurance, parental leave for you, your spouse/domestic partner and children, and a 401k with company match. Check out our benefits pages for more information.
Riot Games fosters a player and workplace experience that values teamwork embodied by the Summoner's Code and Community Code. Our culture embraces differences as a strength, and our values are the guiding principles for how we approach work. We are committed to putting diversity and inclusion (D&I) at the center of everything we do, and promoting a fair and collaborative culture where Rioters treat one another with dignity and respect. We encourage you to read more about our value of thriving together and our ongoing work to build the most inclusive company in Gaming.