Skip to Main Content
EN
Rechercher des emplois
The Walt Disney Company. Be you. Be here. Be part of the story.

Be Part of the Story

Staff Security Engineer - Security Architecture & Engineering (Project Hire)

Postuler maintenant Postuler ultérieurement Job ID 10069072 Emplacement Glendale, Californie, États-Unis Entreprise The Walt Disney Company (Corporate) Date de publication 29/04/2024

Ce rôle est considéré comme un poste à distance, ce qui signifie que l’employé(e) travaillera à distance de manière continue et qu’il n’aura pas d’espace de travail attribué à un endroit désigné par la Société.

Résumé du poste:

We are defenders of the magic, waging an epic battle to ­­­­­­safeguard our franchises, protect our people, and ensure the world’s most admired entertainment company is not impacted by cybersecurity threats. The Walt Disney Company is scouring the known talent universe to find security engineers desiring to join our Studios Cyber Team. This position builds and operates systems that provide stay-secure capabilities to our Studio customers. We are partners in protecting Disney’s highly respected portfolio including Marvel Studios, Pixar Animation Studios, Lucasfilm, Disney Live Action Films, Walt Disney Animation Studios, Searchlight Pictures, and 20th Century Studios.

To exceed the expectations of our versatile, creative partners, we need highly motivated, professionals who are passionate about finding new ways to deliver best-in-class cybersecurity capabilities. The Staff Security Engineer - Security Architecture & Engineering role is part of a team that is responsible for validating our content creation and delivery platforms, services, applications, workflows, and websites are designed and implemented to the highest security standards. You will be responsible for assisting in the secure design and analysis of on-premise and cloud-based infrastructure and applications where studio content is produced. This is a deeply technical role, requiring a solid grasp and experience implementing a variety of cloud infrastructure solutions and services, as well as network security, identity, cyber security, privileged access, and related technologies, using solid design principles.

Areas of Responsibilities

  • Conduct security architecture and design reviews of high-impact applications including both internally developed applications and 3rd party managed applications.
  • Lead in-depth security assessments of sophisticated workflows spanning multiple applications, performing and/or coordinating multiple security assessment workstreams such as threat modeling, penetration testing, DAST scanning, and code review.
  • Review output from Dynamic Application Security Testing (DAST) tools and provide feedback on results.
  • Evaluate the security posture of cloud environments through manual review and automated tooling. Review output from Cloud Security Posture Management (CSPM) tools. Provide guidance to stakeholders on approaches to remediating identified issues.
  • Conduct hands-on security testing of web, mobile applications and cloud-based services. Be capable of identifying traditional application-level issues such as injection, authentication, and misconfiguration vulnerabilities, but also identify vulnerabilities that lead to bypass of security controls.
  • Participate in proof of concepts and other technical evaluations of technologies, designs, and solutions and provide security requirements and recommendations.
  • Serve as a point of escalation/mentor for junior engineers, and provide guidance on the use of DAST, SAST, CSPM tools, and application/cloud security standard methodologies. Participate in the evaluation of security tools used across the organization.

Basic Qualifications

  • Minimum of 7+ years of experience in cybersecurity and cloud infrastructure engineering/architecture.
  • In-depth knowledge of public clouds such as AWS, Azure, and GCP. Experience with securing AWS workloads is required.
  • Proven ability to analyze and assess complicated application architectures and workflows to identify risk.
  • Significant penetration testing experience and offensive capabilities in key focus areas including web applications, mobile applications, networks, cloud, and infrastructure.
  • Basic knowledge of content security controls such as DRM, and visible and forensic watermarking is required.
  • Detailed understanding of network technologies including routers, switches, load balancers, firewalls, proxies, etc.
  • Familiarity with CI/CD principals, tools, and services. Hands-on experience implementing SAST, DAST, and SCA tooling is a plus.
  • Experience securing a microservice environment, along with demonstrable knowledge of container technologies such as Kubernetes and Docker and securing such environments.

Preferred Qualifications

  • One or more current security-related certifications (e.g., CISSP, SANS GIAC, etc.)
  • One or more cloud security certifications (AWS, Azure, GCP, CCSP).
  • Consistent track record of driving application security assessments for an organization.

Education

  • Bachelor’s degree in Computer Science, Computer Engineering, or related technical field, and/or equivalent work experience, or significant experience and progress towards professional credentials.

This is an estimated 30-month project hire placement with no guarantee of permanent placement.

#DISNEYTECH


The hiring range for this position in California is $136,038 - $182,490 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

Informations Supplémentaires:

DISNEYTECH



Sur The Walt Disney Company (Corporate):

Chez Disney Corporate, vous verrez comment les secteurs d’activités qui animent les marques puissantes de la société se rassemblent pour former la société de divertissement la plus novatrice, développée et admirée au monde. En tant que membre d’une équipe d’entreprise, vous travaillerez avec les leaders de classe mondiale qui mettent au point les stratégies qui permettent à The Walt Disney Company de rester à la pointe du divertissement. Collaborez avec d’autres penseurs novateurs pour permettre aux meilleurs conteurs de créer des souvenirs pour des millions de familles du monde entier.

Sur The Walt Disney Company:

The Walt Disney Company, ainsi que ses filiales et sociétés affiliées, forme l’une des principales entreprises internationales diversifiées de divertissement familial et de médias. Elle comprend trois secteurs d'activités essentiels : Disney Entertainment, ESPN et Disney Experiences. Depuis ses modestes débuts en tant que studio de dessins animés dans les années 1920 jusqu’à son statut de référence actuel dans le secteur du divertissement, Disney poursuit fièrement sa tradition de création d’histoires et d’expériences exceptionnelles pour tous les membres de la famille. Les histoires, les personnages et les expériences de Disney touchent les consommateurs et les visiteurs du monde entier. À travers nos activités présentes dans plus de 40 pays, nos employés et cast members collaborent pour créer des expériences de divertissement appréciées à la fois au niveau universel et local.

Le poste est rattaché à Disney Worldwide Services, Inc. , qui fait partie d’une entreprise que nous appelons The Walt Disney Company (Corporate).

Disney Worldwide Services, Inc. est un employeur qui souscrit au principe d’égalité des chances à l’emploi. Les candidat(e)s seront pris(es) en considération pour l’emploi sans considération de race, de couleur, de religion, de sexe, d’âge, d’origine nationale, d’orientation sexuelle, d’identité sexuelle, de handicap, de statut d’ancien combattant protégé ou de toute autre base interdite par la loi fédérale, étatique ou locale. Disney favorise une culture commerciale où les idées et décisions de tous et toutes nous aident à grandir, innover, créer les meilleures histoires et être pertinents dans un monde en évolution rapide.

Postuler maintenant Postuler ultérieurement

Abonnez-vous à nos alertes d'offres d'emploi

Inscrivez-vous pour recevoir de nouvelles alertes d’emploi et des informations sur notre société selon vos préférences.

Specify LocationsSélectionnez une catégorie parmi la liste proposée. Sélectionnez ensuite parmi les lieux proposés. Enfin, cliquez sur "Ajouter" pour créer votre alerte.