Staff Security Engineer - Security Architecture & Engineering (Project Hire) na DISNEY Skip Navigation
EN
The Walt Disney Company. Be you. Be here. Be part of the story.

Be Part of the Story

Staff Security Engineer - Security Architecture & Engineering (Project Hire)

Candidate-se agora mesmo! Candidatar-se depois Job ID 10069072 Local Glendale, Califórnia, Estados Unidos Empresa The Walt Disney Company (Corporate) Data da publicação 29/04/2024

Esta função é considerada remota, o que significa que o funcionário trabalhará remotamente de forma contínua e não terá um espaço de trabalho determinado em um local designado pela Empresa.

Descrição do cargo:

We are defenders of the magic, waging an epic battle to ­­­­­­safeguard our franchises, protect our people, and ensure the world’s most admired entertainment company is not impacted by cybersecurity threats. The Walt Disney Company is scouring the known talent universe to find security engineers desiring to join our Studios Cyber Team. This position builds and operates systems that provide stay-secure capabilities to our Studio customers. We are partners in protecting Disney’s highly respected portfolio including Marvel Studios, Pixar Animation Studios, Lucasfilm, Disney Live Action Films, Walt Disney Animation Studios, Searchlight Pictures, and 20th Century Studios.

To exceed the expectations of our versatile, creative partners, we need highly motivated, professionals who are passionate about finding new ways to deliver best-in-class cybersecurity capabilities. The Staff Security Engineer - Security Architecture & Engineering role is part of a team that is responsible for validating our content creation and delivery platforms, services, applications, workflows, and websites are designed and implemented to the highest security standards. You will be responsible for assisting in the secure design and analysis of on-premise and cloud-based infrastructure and applications where studio content is produced. This is a deeply technical role, requiring a solid grasp and experience implementing a variety of cloud infrastructure solutions and services, as well as network security, identity, cyber security, privileged access, and related technologies, using solid design principles.

Areas of Responsibilities

  • Conduct security architecture and design reviews of high-impact applications including both internally developed applications and 3rd party managed applications.
  • Lead in-depth security assessments of sophisticated workflows spanning multiple applications, performing and/or coordinating multiple security assessment workstreams such as threat modeling, penetration testing, DAST scanning, and code review.
  • Review output from Dynamic Application Security Testing (DAST) tools and provide feedback on results.
  • Evaluate the security posture of cloud environments through manual review and automated tooling. Review output from Cloud Security Posture Management (CSPM) tools. Provide guidance to stakeholders on approaches to remediating identified issues.
  • Conduct hands-on security testing of web, mobile applications and cloud-based services. Be capable of identifying traditional application-level issues such as injection, authentication, and misconfiguration vulnerabilities, but also identify vulnerabilities that lead to bypass of security controls.
  • Participate in proof of concepts and other technical evaluations of technologies, designs, and solutions and provide security requirements and recommendations.
  • Serve as a point of escalation/mentor for junior engineers, and provide guidance on the use of DAST, SAST, CSPM tools, and application/cloud security standard methodologies. Participate in the evaluation of security tools used across the organization.

Basic Qualifications

  • Minimum of 7+ years of experience in cybersecurity and cloud infrastructure engineering/architecture.
  • In-depth knowledge of public clouds such as AWS, Azure, and GCP. Experience with securing AWS workloads is required.
  • Proven ability to analyze and assess complicated application architectures and workflows to identify risk.
  • Significant penetration testing experience and offensive capabilities in key focus areas including web applications, mobile applications, networks, cloud, and infrastructure.
  • Basic knowledge of content security controls such as DRM, and visible and forensic watermarking is required.
  • Detailed understanding of network technologies including routers, switches, load balancers, firewalls, proxies, etc.
  • Familiarity with CI/CD principals, tools, and services. Hands-on experience implementing SAST, DAST, and SCA tooling is a plus.
  • Experience securing a microservice environment, along with demonstrable knowledge of container technologies such as Kubernetes and Docker and securing such environments.

Preferred Qualifications

  • One or more current security-related certifications (e.g., CISSP, SANS GIAC, etc.)
  • One or more cloud security certifications (AWS, Azure, GCP, CCSP).
  • Consistent track record of driving application security assessments for an organization.

Education

  • Bachelor’s degree in Computer Science, Computer Engineering, or related technical field, and/or equivalent work experience, or significant experience and progress towards professional credentials.

This is an estimated 30-month project hire placement with no guarantee of permanent placement.

#DISNEYTECH


The hiring range for this position in California is $136,038 - $182,490 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

Weitere Informationen:

DISNEYTECH


Sobre The Walt Disney Company (Corporate):

Na área empresarial da Disney, você pode ver como os negócios por trás das marcas mais poderosas da empresa se reúnem para criar a mais inovadora, conhecida e admirada empresa de entretenimento do mundo. Como integrante de uma equipe empresarial, você trabalhará com líderes de padrão internacional para promover estratégias que mantêm a The Walt Disney Company na vanguarda do entretenimento. Veja e seja visto por outros pensadores inovadores enquanto possibilita que os melhores contadores de histórias do mundo criem momentos inesquecíveis para milhões de famílias de todo o planeta.

Sobre The Walt Disney Company:

A The Walt Disney Company, juntamente com suas subsidiárias e afiliadas, é uma líder diversificada em entretenimento familiar e mídia internacional que inclui três segmentos principais de negócios: Disney Entertainment, ESPN e Disney Experiences. Desde seus primeiros passos como um estúdio de desenho animado na década de 1920 até se tornar o atual nome de destaque na indústria do entretenimento, a Disney orgulhosamente dá continuidade a seu legado de criação de histórias e experiências de padrão internacional para toda a família. As histórias, personagens e experiências da Disney tocam consumidores e visitantes de todas as partes do mundo. Com operações em mais de 40 países, nossos funcionários e colaboradores trabalham juntos para criar experiências de entretenimento adoradas por todos.

Esta vaga é oferecida junto à Disney Worldwide Services, Inc., que é parte de um segmento de negócios que chamamos de The Walt Disney Company (Corporate).

Disney Worldwide Services, Inc. é um empregador de oportunidades iguais. Os candidatos serão selecionados para emprego independente de raça, cor, religião, sexo, idade, nacionalidade, orientação sexual, identidade de gênero, necessidade especial, status de veterano protegido ou qualquer outro motivo proibido por lei federal, estadual ou local. A Disney promove uma cultura de negócios em que ideias e decisões de todas as pessoas nos ajudam a crescer, inovar, criar as melhores histórias e ser relevantes em um mundo de rápidas mudanças.

Candidate-se agora mesmo! Candidatar-se depois

Acompanhe nossas vagas

Inscreva-se para receber notificações sobre novas vagas e informações sobre a empresa com base em suas preferências.

Specify LocationsSelecione uma categoria de emprego da lista de opções. Selecione um local da lista de opções. Por fim, clique em "Adicionar" para criar seu alerta de emprego.