Jobs
>
Glendale

    Staff Security Engineer - Glendale, United States - The Walt Disney Company

    Default job background
    Description


    We are defenders of the magic, waging an epic battle to ­­­­­­safeguard our franchises, protect our people, and ensure the world's most admired entertainment company is not impacted by cybersecurity threats.

    The Walt Disney Company is scouring the known talent universe to find security engineers desiring to join our Studios Cyber Team.

    This position builds and operates systems that provide stay-secure capabilities to our Studio customers.

    We are partners in protecting Disney's highly respected portfolio including Marvel Studios, Pixar Animation Studios, Lucasfilm, Disney Live Action Films, Walt Disney Animation Studios, Searchlight Pictures, and 20th Century Studios.


    To exceed the expectations of our versatile, creative partners, we need highly motivated, professionals who are passionate about finding new ways to deliver best-in-class cybersecurity capabilities.

    The Staff Security Engineer - Security Architecture & Engineering role is part of a team that is responsible for validating our content creation and delivery platforms, services, applications, workflows, and websites are designed and implemented to the highest security standards.

    You will be responsible for assisting in the secure design and analysis of on-premise and cloud-based infrastructure and applications where studio content is produced.

    This is a deeply technical role, requiring a solid grasp and experience implementing a variety of cloud infrastructure solutions and services, as well as network security, identity, cyber security, privileged access, and related technologies, using solid design principles.

    Areas of Responsibilities

    Conduct security architecture and design reviews of high-impact applications including both internally developed applications and 3rd party managed applications.


    Lead in-depth security assessments of sophisticated workflows spanning multiple applications, performing and/or coordinating multiple security assessment workstreams such as threat modeling, penetration testing, DAST scanning, and code review.

    Review output from Dynamic Application Security Testing (DAST) tools and provide feedback on results.

    Evaluate the security posture of cloud environments through manual review and automated tooling. Review output from Cloud Security Posture Management (CSPM) tools. Provide guidance to stakeholders on approaches to remediating identified issues.

    Conduct hands-on security testing of web, mobile applications and cloud-based services.

    Be capable of identifying traditional application-level issues such as injection, authentication, and misconfiguration vulnerabilities, but also identify vulnerabilities that lead to bypass of security controls.


    Participate in proof of concepts and other technical evaluations of technologies, designs, and solutions and provide security requirements and recommendations.


    Serve as a point of escalation/mentor for junior engineers, and provide guidance on the use of DAST, SAST, CSPM tools, and application/cloud security standard methodologies.

    Participate in the evaluation of security tools used across the organization.

    Basic Qualifications

    Minimum of 7+ years of experience in cybersecurity and cloud infrastructure engineering/architecture.

    In-depth knowledge of public clouds such as AWS, Azure, and GCP. Experience with securing AWS workloads is required.

    Proven ability to analyze and assess complicated application architectures and workflows to identify risk.


    Significant penetration testing experience and offensive capabilities in key focus areas including web applications, mobile applications, networks, cloud, and infrastructure.

    Basic knowledge of content security controls such as DRM, and visible and forensic watermarking is required.

    Detailed understanding of network technologies including routers, switches, load balancers, firewalls, proxies, etc.

    Familiarity with CI/CD principals, tools, and services. Hands-on experience implementing SAST, DAST, and SCA tooling is a plus.


    Experience securing a microservice environment, along with demonstrable knowledge of container technologies such as Kubernetes and Docker and securing such environments.

    Preferred Qualifications

    One or more current security-related certifications (e.g., CISSP, SANS GIAC, etc.)

    One or more cloud security certifications (AWS, Azure, GCP, CCSP).

    Consistent track record of driving application security assessments for an organization.

    Education


    Bachelor's degree in Computer Science, Computer Engineering, or related technical field, and/or equivalent work experience, or significant experience and progress towards professional credentials.

    T his is an estimated 30-month project hire placement with no guarantee of permanent placement.

    #DISNEYTECH

    The hiring range for this position in California is $136,038 - $182,490 per year.

    The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills, and experience among other factors.

    A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.


    Job ID:

    Location:
    Glendale,California


    Job Posting Company:
    The Walt Disney Company (Corporate)


    The Walt Disney Company and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers including individuals with disabilities and veterans with disabilities.

    If you have a disability and believe you need a reasonable accommodation in order to search for a job opening or apply for a position, email with your request.

    This email address is not for general employment inquiries or correspondence.

    We will only respond to those requests that are related to the accessibility of the online application system due to a disability.



  • NovaWorks Duarte, United States

    ETC is an international high-tech company whose main business is the development, manufacturing, and installation of gas centrifuges for uranium enrichment. ETC also supplies its customers with aluminum piping and provides project management, plant design, and engineering service ...


  • The Walt Disney Company (Corporate) Glendale, United States

    We are defenders of the magic, waging an epic battle to safeguard our franchises, protect our people, and ensure the world's most admired entertainment company is not impacted by cybersecurity threats. The Walt Disney Company is scouring the known talent universe to find security ...


  • Omega Dynamics Inglewood, United States

    The Thüga SmartService GmbH with around 300 employees is a subsidiary of Thüga AG, the largest municipal utility association in Germany. We are a strategic partner for the digitalization of municipal utilities, municipalities, and industry. · The energy industry is in motion. And ...


  • The Walt Disney Company Glendale, United States

    We are defenders of the magic, waging an epic battle to ­­­­­­safeguard our franchises, protect our people, and ensure the world's most admired entertainment company is not disrupted by cybersecurity threats. The Walt Disney Company is scouring the known talent universe to find s ...

  • Bold Business

    Security Engineer

    1 week ago


    Bold Business Los Angeles, United States

    Job Description · Job DescriptionSummary: · We are looking for a Security Engineer who will be responsible for designing, implementing, and maintaining security solutions to protect our organization's systems, networks, and data from cyber threats. The ideal candidate will have a ...

  • Bold Business

    Security Engineer

    17 hours ago


    Bold Business Los Angeles, United States

    Summary: · We are looking for a Security Engineer who will be responsible for designing, implementing, and maintaining security solutions to protect our organization's systems, networks, and data from cyber threats. The ideal candidate will have a strong background in informatio ...

  • Dropbox

    Security Engineer

    1 week ago


    Dropbox Los Angeles, United States

    Company Description · Dropbox is a special place where we are all seeking to fulfill our mission to design a more enlightened way of working. We're looking for innovative talent to join us on our journey. The words shared by our founders at the start of Dropbox still ring true t ...

  • Bold Business

    Security Engineer

    1 week ago


    Bold Business Los Angeles, United States

    Job Description · Job DescriptionSummary: · We are looking for a Security Engineer who will be responsible for designing, implementing, and maintaining security solutions to protect our organization's systems, networks, and data from cyber threats. The ideal candidate will have a ...

  • Splice

    Security Engineer

    1 week ago


    Splice Los Angeles, United States

    Job Description · Job DescriptionWHO WE ARE: · We are a producers playground, delivering music creators the tools they need to bring their ideas to life. With a massive, industry-leading catalog of licensed samples, paired with powerful AI, and access to affordable plugins and D ...

  • StubHub

    Security Engineer

    1 week ago


    StubHub Los Angeles, United States

    StubHub is on a mission to redefine the live event experience on a global scale. Whether someone is looking to attend their first event or their hundredth, we're here to delight them all the way from the moment they start looking for a ticket until they step through the gate. The ...

  • Bold Business

    Security Engineer

    1 week ago


    Bold Business Los Angeles, United States Temporary

    Summary: · We are looking for a Security Engineer who will be responsible for designing, implementing, and maintaining security solutions to protect our organization's systems, networks, and data from cyber threats. The ideal candidate will have a strong background in information ...


  • Cornerstone Consutling & Technology Los Angeles, United States

    Security Engineer for ITS Security - LA METRO · Share this job as a link in your status update to LinkedIn. · Job Title · Security Engineer for ITS Security - LA METRO · Location · Category · Information Technology · Job Type · Full-time · Experienced (Non-Manager) · Education · ...


  • Cornerstone Transportation Consulting Los Angeles, United States

    Job Description · Job DescriptionProject Description: · This project entails providing cybersecurity staff augmentation services to Metro's Information Security Department for two years. The assigned resource will support various core functions within the department, focusing on ...


  • ManTech Altadena, United States

    Secure our Nation, Ignite your Future · Become an integral part of a diverse team while working at an Industry Leading Organization, where our employees come first. At ManTech , you'll help protect our national security while working on innovative projects that offer opportunitie ...


  • ManTech International Altadena, United States

    Secure our Nation, Ignite your Future Become an integral part of a diverse team while working at an Industry Leading Organization, where our employees come first. At ManTech, you'll help protect our national security while working on innovative projects that offer opportunities f ...


  • Themesoft Inc. Los Angeles, United States

    Role: Information Security Engineer · Location: Multiple Locations - TX, IA, NC, OH, MN, MO · Job Description: · Required 10+ years of total experience · • 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the foll ...


  • Incode Technologies Los Angeles, United States

    The Opportunity · We seek a trustworthy and proactive · Staff Security Engineer · as the technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection ...


  • SummitHR Los Angeles, United States

    Job Description · Job DescriptionResponsibilities · As a Cyber Security Engineer, you will have the opportunity to jump-start and lead the application security team as part of our engineering group. We are looking for highly skilled security experts who can handle the end to end ...


  • Venstar Inc. Los Angeles, United States

    Senior Software Security Engineer · This position requires an experienced software security engineer who specializes in IoT devices and AWS Cloud technologies to join the Venstar Cloud Engineering Team. You will be responsible of the efforts to develop and enhance the connect sof ...


  • Glocomms Los Angeles, United States

    Glocomms is partnered with an industry-leading media platform seeking to bring on · a talented and experienced Senior Security Engineer to join its growing Payments technology team. The ideal candidate will have a Bachelor's or Master's degree in Computer Science, Information Se ...