Jobs
>
Bellevue

    Sr. Product Security Engineer - Bellevue, United States - Warner Media, LLC

    Default job background
    Description
    Every great story has a new beginning, and yours starts here.
    Welcome to Warner Bros. Discovery... the stuff dreams are made of.
    Who We Are...

    When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth.

    Behind WBD's vast portfolio of iconic content and beloved brands, are the

    storytellers

    bringing our characters to life, the

    creators

    bringing them to your living rooms and the

    dreamers

    creating what's next...

    From brilliant creatives, to technology trailblazers, across the globe, WBD offers career defining opportunities, thoughtfully curated benefits, and the tools to explore and grow into your best selves.

    Here you are supported, here you are celebrated, here you can thrive.
    Your New Role...
    The Sr.

    Product Security Engineer will work within WBD's Global Information and Content Security team and cooperate with Direct to Consumer (DTC) teams on initiatives to design and deploy appropriate, risk-based application security safeguards and technical application security controls to protect data, services, and technology assets of WBD's products.

    The role will focus on application security for our streaming media service and other supporting applications. This Sr.

    Product Security Engineer will work closely with development and engineering teams to ensure secure architectures, patterns, and solutions are created and maintained.

    The person taking this position will strive to become a subject matter expert on product security and secure code development gaining experience through communication and collaboration with various application engineering teams to facilitate the improvement of the existing SSDLC process within the organization.


    If you:

    • Are passionate about web and mobile application security
    • Want to work in an international, face-paced company
    • Want to learn how to secure applications and infrastructure in the cloud
    • Would like to be a part of an experienced team of practitioners opened to sharing their knowledge
    • Want to learn how to implement security into SDLC (CI\CD)
    • Want to have a visible impact on the security of a large suite of products
    Join us

    Your Role Accountabilities...

    • Run, maintain, and utilize security tools for the Appsec program, e.g., static and dynamic code analysis
    tools

    • Create and run secure code assessments with various application and services engineering teams
    • Perform manual and automated penetration tests and retests of web and mobile applications.
    • Review technical architecture and delivery for Web and other Client Delivery Platforms
    • Review current system security measures and recommend or implement enhancements.
    • Review and contribute to application designs and solutions
    • Review developers' codes, provide feedback and perform security assessments for consumer-facing
    applications, services and future technology.

    • Triage risk of identified vulnerabilities and findings.
    • Work with external penetration testers, oversee ongoing pentests and exercises, work with application
    engineering teams on remediation of found vulnerabilities.

    • Participate in information security operations duties, including occasional incident response
    escalations as a subject matter expert.

    • Evaluate, deploy and support application security technologies, processes and workflows on multiple
    platforms (e.g., Server, Client, Mobile, Tablet, etc.)

    • Identify and define application security requirements and security baselines.
    • Work collaboratively and proactively across the organization (e.g., Technical Architects, Engineering
    Leads, Product managers, Digital Media Program (AGILE) Teams, etc.) to support and remediate
    security gaps
    Qualifications & Experiences...

    • 5+ years of product/application security work experience
    • Ability to work a hybrid schedule (3 days onsite) out of our Bellevue office.
    • Knowledge of common security principles for web application architectures
    • Experience in code reviews, business logic assessment, and application security testing
    • Solid understanding of security protocols, cryptography, authentication, authorization and security
    • Broad knowledge of Security technologies, process, and techniques and a strong understanding of
    application security leading practices including OWASP and CWE

    • Familiarity with HTML\CSS, JavaScript and UI\UX design and software quality assurance principles
    • Hands-on experience working with DevOps and Agile driven product teams.
    • Familiar with application security tools like BurpSuite Pro, SAST, DAST, nmap, Metasploit, and Kali
    Linux.

    • Knowledge of practical threat modeling for consumer applications
    • Experience in secure software development principles in various languages (Java, Go, JavaScript,
    Python, etc.)

    • Excellent communication and presentation abilities with great attention to detail
    • Demonstrated ability to explain risks and vulnerabilities to both technical and non-technical audiences

    Preferred Qualifications:

    • Bachelor's degree in IT, Computer Science or Information Security preferred.
    • Knowledge of cloud security principles
    • Experience in application/tool development with at least one modern programming language
    • GPEN, GXPN, GMOB or other Security Certifications
    #LI-Hybrid
    How We Get Things Done...

    This last bit is probably the most important Here at WBD, our guiding principles are the core values by which we operate and are central to how we get things done.

    You can find them at


    along with some insights from the team on what they mean and how they show up in their day to day.

    We hope they resonate with you and look forward to discussing them during your interview.
    The Legal Bits...

    In compliance with local law, we are disclosing the compensation, or a range thereof, for roles in locations where legally required.

    Actual salaries will vary based on several factors, including but not limited to external market data, internal equity, location, skill set, experience, and/or performance.

    Base pay is just one component of Warner Bros. Discovery's total compensation package for employees.


    Pay Range:
    $98, $183,297.00 salary per year. Other rewards may include annual bonuses, short- and long-term incentives, and program-specific awards. In addition, Warner Bros. Discovery provides a variety of benefits to employees, including health insurance coverage, an employee wellness program, life and disability insurance, a retirement savings plan, paid holidays and sick time and vacation.
    Warner Bros.

    Discovery embraces the opportunity to build a workforce that reflects the diversity of our society and the world around us.

    Being an equal opportunity employer means that we take seriously our responsibility to consider qualified candidates on the basis of merit, without regard to race, color, religion, national origin, gender, sexual orientation, gender identity or expression, age, mental or physical disability, and genetic information, marital status, citizenship status, military status, protected veteran status or any other category protected by law.

    If you're a qualified candidate and you require adjustments or accommodations to search for a job opening or apply for a position, please contact us at
    #J-18808-Ljbffr


  • Omni Inclusive Bellevue, United States

    Primary Tasks and Responsibilities: · ssist in defining, driving, and delivering key elements of Truveta's vulnerability management strategy, deriving best practices for vulnerability and exposure analysis across the Company · Establish regular and actionable vulnerability repo ...


  • Omni Inclusive Bellevue, United States

    Primary Tasks and Responsibilities: · • ssist in defining, driving, and delivering key elements of Truveta's vulnerability management strategy, deriving best practices for vulnerability and exposure analysis across the Company · • Establish regular and actionable vulnerability re ...


  • Robinhood Bellevue, United States

    Join a leading fintech company that's democratizing finance for all.Robinhood was founded on a simple idea: that our financial markets should be accessible to all. With customers at the heart of our decisions, Robinhood is lowering barriers and providing greater access to financi ...


  • Epic Games Bellevue, United States

    WHAT MAKES US EPIC? · At the core of Epics success are talented, passionate people. Epic prides itself on creating a collaborative, welcoming, and creative environment. Whether its building award-winning games or crafting engine technology that enables others to make visually st ...


  • Flexport Bellevue, United States

    The opportunity: Flexport is looking for a Staff Product Security Engineer to help Flexport establish itself as the most trusted company in the global trade ecosystem. As a Product Security Engineer, you have a deep understanding of product development and strategy, and are able ...


  • Epic Games Bellevue, United States

    WHAT MAKES US EPIC?At the core of Epic's success are talented, passionate people. Epic prides itself on creating a collaborative, welcoming, and creative environment. Whether it's building award-winning games or crafting engine technology that enables others to make visually stun ...


  • UiPath Bellevue, United States

    Life at UiPath · The people at UiPath believe in the transformative power of automation to change how the world works. We're committed to creating category-leading enterprise software that unleashes that power. · To make that happen, we need people who are curious, self-propell ...

  • Experis

    Security Engineer

    6 days ago


    Experis Redmond, United States

    Our Client, a Multinational Technology Corporation, is seeking a Security Engineer with strong Project Management skills for a 5-18 month contract assignment onsite in Redmond, WA. As a Security Engineer with this Cybersecurity Team, you will support threat intelligence and defen ...


  • MediaAlpha Bellevue, United States

    Job Description · Job DescriptionMediaAlpha is a customer acquisition solutions provider powered by technology and data science. The company provides industry-leading solutions designed to reach consumers shopping within high-consideration categories such as property and casualty ...


  • 株式会社ポケモン Bellevue, United States

    Get to know The Pokémon Company International · The Pokémon Company International, a subsidiary of The Pokémon Company in Japan, manages the property outside of Asia and is responsible for brand management, licensing, marketing, the Pokémon Trading Card Game, the animated TV ser ...

  • Bluehawk Consulting

    Security Engineer

    1 week ago


    Bluehawk Consulting Kirkland, United States

    Mechanical Designer · Remote · Bluehawk Consulting is seeking a Mechanical Designer. Join our client who is pioneering the advancement of space exploration and enabling millions to live and work beyond Earth's bounds. · Project Overview · As a Mechanical Design Engineer Consul ...


  • Salesforce Bellevue, United States

    To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job CategoryProduct · Job DetailsAbout SalesforceWe're Salesforce, the Customer Company, inspiring the future of business with AI+ D ...


  • Salesforce Bellevue, United States

    To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job CategoryProduct · Job DetailsAbout SalesforceWe're Salesforce, the Customer Company, inspiring the future of business with AI+ D ...


  • Warner Media, LLC Bellevue, United States

    Welcome to Warner Bros. Discovery the stuff dreams are made of. · Who We Are · When we say, the stuff dreams are made of, were not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBDs vast portfolio of iconic cont ...


  • Insight Global Bellevue, United States

    Performs security, compliance, and risk assessments on projects throughout project lifecycle. · Collaborates and participates on identification of security needs & recommends plans/resolutions. Implements, tests & monitors info security improvements. · Maintains visibility insi ...


  • The Trade Desk Bellevue, United States

    The Trade Desk is changing the way global brands and their agencies advertise to audiences around the world. How? With a media buying platform that helps brands deliver a more insightful and relevant ad experience for consumers -- and sets a new standard for global reach, accurac ...

  • Manpower Group Inc.

    Security Engineer

    3 days ago


    Manpower Group Inc. Redmond, United States

    Our Client, a Multinational Technology Corporation, is seeking a Security Engineer with strong Project Management skills for a 5-18 month contract assignment onsite in Redmond, WA. As a Security Engineer with this Cybersecurity Team, you will support threat intelligence and defen ...

  • AGS Cyber

    Security Engineer

    4 weeks ago


    AGS Cyber Seattle, United States

    Embedded Security Engineer - Hybrid - Seattle, Washington · The salary base is approximately $130K—170K (dependent on experience), plus an employee stock option plan and additional benefits (401K, etc.). · You MUST be an American citizen or a Green Card Holder. · You MUST have 3+ ...

  • Tik Tok

    Security Engineer

    3 days ago


    Tik Tok Seattle, United States

    Responsibilities · TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo. · Why Join UsAt Ti ...

  • Circle

    Security Engineer

    3 days ago


    Circle Seattle, United States

    Circle is a financial technology company at the epicenter of the emerging internet of money, where value can finally travel like other digital data globally, nearly instantly and less expensively than legacy settlement systems. This ground-breaking new internet layer opens up pre ...