Senior Security Specialist, Security Architecture & Engineering
Burbank, CA - USApply NowApply Later
Job ID 764295BR Location Burbank, California, United States Business The Walt Disney Company (Corporate) Date posted Aug. 12, 2020
Job Summary:At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences — and we’re constantly looking for new ways to enhance and protect these exciting experiences.
The Global Information Security (GIS) group provides services and solutions to protect the value and use of Disney’s information through risk evaluation, collaboration, standardization, enforcement, and education across the enterprise. We protect the brand and reputation while enabling and supporting business objectives. GIS teams are located in Seattle, Burbank, and Orlando.
In order to ensure that our services keep TWDC secure, we follow an ongoing, iterative process, including continued reevaluation of our services over time to address emerging threats as well as changes in business and technology. This process includes:
- Analysis of known and emerging threats to determine risks against TWDC assets
- Creation, maintenance, governance and communication of security policies and standards across TWDC
- Assessment and audit of compliance against the security policies and standards
- Assurance that TWDC assets are effectively managed and monitored to meet TWDC security criteria
The IT Security Architecture & Engineering team develops and guides technology risk management in collaboration with teams across the company to enable responsive, secure and cost effective solutions. We are a highly versatile and technical team, gleaning from network engineering, application security, architecture, risk assessment and control alignment. We are a team of security pros that are here to:
- Evaluate solutions and architectures to assess qualitative and quantitative risk
- Identify solutions to reduce risk and enhance our prevention and detection capabilities
- Conduct Threat Modeling
Responsibilities:The Sr. Security Specialist, Security Architecture and Engineering is responsible for evaluating a myriad of deployment scenarios (e.g. on-prem, cloud, hybrid), services, models and technology to ensure they are secure and compliant across the Walt Disney Company (TWDC). This role is highly versatile and technical, gleaning from heavy network engineering, application security and DevSecOps.
- Provides situation based support, using in-depth knowledge of TWDC technology, to ensure systems are designed in accordance with and are aligned with Company security requirements; includes architecture assessments, secure development training, and conducting RTOs
- Creates, reviews and presents reports, position papers, assessment recaps to team (peers) and next level of leadership within team
- Executes advanced risk and threat analysis activities, leveraging learnings from external and internal cyber trends and incidents
- Develops and documents technical solutions that meet specifications and impact future developments (position papers, process flows, requirements, data flows, mapping to controls)
- Identifies, selects, develops and documents architecture artifacts (reference architectures, standards, policies, reusable designs, best practices) across data protection topics
- Researches, learns and assesses new technologies
- Leads discussions, assessments, tracking and overall reporting of technology security risks
- Documents issues, solutions and project status
- Understands business drivers and processes to evaluate risk and recommend solutions with a balanced result
- Promotes awareness of applicable security policies and standards
- Assists with the maintenance of metrics and scorecards in support of the information security program
- Compiles technical documentation
- Executes security assessments
- Consults on technology implementations
- CISSP, CCSP, AWS Certified Public Cloud Architect, MCSE cloud, VMWare VCP6 cloud, EMCCA cloud computing Architect or GIAC)
- 5 years of experience with 3 or more areas including: public cloud, secure application development, virtual network big data, elastic compute, cloud security
- 1-3 years of practical cloud information security experience
- 5-8 years in IT and/or in this specific role
- Experience in information management and information technology security design and implementation
- Demonstrated experience with security event logs from Windows, Unix, intrusion detection systems, network, and remote access solutions
- Experience managing IDS / IPS / firewall systems in distributed/hybrid cloud environment
- Demonstrated experience in creating conceptual, logical and physical security diagrams, Thorough understanding of vulnerabilities and countermeasures.
- Information Security technology/compliance experience.
- Detailed understanding of TCP/IP and related communication protocols, Windows authentication mechanisms (Kerberos, NTLM, AD), networking technologies, software defined computing, containerization, routing and switching, big data, elastic compute, and risk analysis and risk management methodologies
- Ability to manage multiple priorities and work effectively in a fast-paced, high volume, results driven environment
- Excellent written and verbal communication skills including reporting
- This will require practical use and understanding of advanced security protocols and standards, and solid knowledge of information security principles and practices as well as latest scalable technologies (hard and soft)
- Has participated in complex initiatives or projects simultaneously, e.g.major/complex security assessments
- Has identified problems, presented recommended responses, gained agreement on approach and led development of solutions
- Has taken initiative to evolve SIPOCs, RACIs, Risk Metrics and Operational Metrics as appropriate
- Has prepared and presented highly effective presentations to TWDC technology teams and senior leadership
- Has identified efficiency and effectiveness gaps in existing services/processes, driven consensus on new approach, and led execution/operationalization of new approach
- Peer Relationships
- Political Savvy
- Understanding Others
- Intellectual Horsepower
- Technical Learning
- Comfort Around Higher
- Dealing with Ambiguity
- Presentation Skills
- Learning on the Fly
- Interpersonal Savvy
- Decision Quality
- Process Management
- Integrity and Trust
- Personal Learning
Required EducationBA/BS in Business or Computer Science or appropriate work experience
Preferred EducationMasters or other advanced degree preferred
About The Walt Disney Company (Corporate):
At Disney Corporate you can see how the businesses behind the Company’s powerful brands come together to create the most innovative, far-reaching and admired entertainment company in the world. As a member of a corporate team, you’ll work with world-class leaders driving the strategies that keep The Walt Disney Company at the leading edge of entertainment. See and be seen by other innovative thinkers as you enable the greatest storytellers in the world to create memories for millions of families around the globe.
About The Walt Disney Company:
The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise with the following business segments: media networks, parks and resorts, studio entertainment, consumer products and interactive media. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney’s stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.
This position is with Disney Worldwide Services, Inc., which is part of a business segment we call The Walt Disney Company (Corporate).
Disney Worldwide Services, Inc. is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Disney fosters a business culture where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a rapidly changing world.