Sr Security Engineer
Burbank, CA - USApply Now Apply Later
Job ID 706360BR Location Burbank, California, United States Business Direct-to-Consumer and International Date posted 19/09/2019
Job Summary:The Cyber Security team at Disney Direct To Consumer and International (DCTI) is the cornerstone for ensuring that our guest data is secure when interacting with our applications, products and online systems. We partner with teams across DCTI enabling them to make the strategic decisions they need based on authoritative security risk analysis. We are a team of hackers, advisors/mentors, security focused engineers and guides, ensuring that we find the bugs but also providing practical solutions and guidance to ensure the software is always deployed securely and effectively.
Responsibilities:Ensure that the enterprise is safe and secure:
- Lead Security Engineering initiatives with the ability to work independently
- Building and deploying security infrastructure in cloud environments, leveraging cloud infrastructure for rapid deployment
- Building and enhancing security capability through tooling and automation using open source frameworks
- Understanding operational security needs, such and vulnerability management, monitoring, alerting, forensics, application security, in order to support those initiatives
- Lead the design, implementation, and support of a diverse security infrastructure including NGFW, IDS/IPS, secure web gateways, endpoint security, vulnerability scanners, SIEM and DLP
- Staying current with the latest threat mitigation tools and techniques
- Research and recommend emerging security technologies and tools to address current and future threats
- Partner with DevOps and SRE teams to consult on secure development practices and build security automation into pipelines
- Partner with Risk and Compliance teams to enhance reporting and collection of risk and vulnerability metrics
Drive efficiency improvements by:
- Analyzing processes and toolsets, continuously identify areas for automation and improvement
- Assisting in tools and dashboards development
- Mentoring junior members of staff
- Provide guidance for security remediation to business and IT partners. Speaking the DevOps and SRE team’s language and demonstrating real, practical risk and value
- Being an ambassador for the security team, building relationships with the development teams security specialists to make certain they engage early and often ensuring security is an enabler not a blocker
- Create and maintain documentation as it relates to security designs/configurations, processes, and requirements
- Collaborate with senior management and department leaders to assess near- and long-term security needs
- Participate in security incident response process
- Develop and maintain partnerships with key vendors to ensure that service levels are understood and met
- Ability to research and understand esoteric and custom built infrastructure to determine vulnerabilities and risks in both application and infrastructure layers
- Understanding of cloud based infrastructure components (SDN, compute, SaaS) with specific understanding of the security risks presented in a decentralized off premise environment
- Understanding of vulnerability management in traditional physical infrastructure as well as hyper virtualized and containerized environments
- Strong working knowledge of modern social media presence and the ability to consult on secure interaction with multiple disparate social platforms with regard to privacy, password security and best practices
- Ability to achieve reporting, auditing and analysis goals through automation and scripting (Python, SQL etc.)
- Knowledge of incident response and forensic analysis methods on all major infrastructure platforms, such as servers and firewalls in order to resolve and fully investigate potential breaches or compromises
- Ability to interact and collaborate with a broad range of technical and managerial teams in order to understand and consult on their specific area of expertise with regards to security and risk management
- Thorough understanding of risks presented by partnering with 3rd party entities and the ability to determine and report overall risk for each engagement
- Hands on experience with industry security tools to test and analyze infrastructure and software to identify flaws and risks
- Demonstrated ability to work under pressure
- Comfortable dealing with ambiguity and conflicting priorities
- Strong verbal and written communication skills
- Attention to detail
- Thirst for knowledge and constant learning to stay up to date with the threat landscape
- Ability to work with a wide variety of personalities
- Remains productive while rapidly switching context
About Direct-to-Consumer and International:
Comprised of Disney’s international media businesses and the Company’s various streaming services, the Direct-to-Consumer and International segment aligns technology, content and distribution platforms to expand the Company’s global footprint and deliver world-class, personalized entertainment experiences to consumers around the world. This segment is responsible for The Walt Disney Company’s direct-to-consumer businesses globally, including the ESPN+ sports streaming service, programmed in partnership with ESPN; the upcoming Disney-branded direct-to-consumer streaming service; and the Company’s ownership stake in Hulu. As part of the Direct-to-Consumer and International segment, Disney Streaming Services, developer of the ESPN+ and Disney-branded streaming platforms, oversees all consumer-facing digital technology and products across the Company.
About The Walt Disney Company:
The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise with the following business segments: media networks, parks and resorts, studio entertainment, consumer products and interactive media. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney’s stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.
This position is with Disney Streaming Technology LLC, which is part of a business segment we call Direct-to-Consumer and International.
Disney Streaming Technology LLC is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Disney fosters a business culture where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a rapidly changing world.
Watch Our Jobs
Sign up to receive new job alerts and company information based on your preferences.