Sr. Security Specialist (Automation and Orchestration)
Burbank, CA - USApply NowApply Later
Job ID 764197BR Location Burbank, California, United States Business The Walt Disney Company (Corporate) Date posted Aug. 07, 2020
Job Summary:The Global Information Security (GIS) group provides services and solutions to protect the value and use of Disney’s information through risk evaluation, collaboration, standardization, enforcement, and education across the enterprise. We protect the brand and reputation while enabling and supporting business objectives. GIS teams are located in Seattle, Burbank, and Orlando.
In order to ensure that our services keep TWDC secure, we follow an ongoing, iterative process, including continued reevaluation of our services over time to address emerging threats as well as changes in business and technology. This process includes:
- Analysis of known and emerging threats to determine risks against TWDC assets
- Creation, maintenance, governance and communication of security policies and standards across TWDC
- Assessment and audit of compliance against the security policies and standards
- Assurance that TWDC assets are effectively managed and monitored to meet TWDC security criteria
The Global Information Security Automation & Orchestration (GISAO) Team addresses a variety of use cases from information security stakeholders at The Walt Disney Company. GISAO engineers solutions that increase business agility, reduce costs, optimize resources, and manage the complexity associated with information security tools and processes at scale.
GISAO designs and develops enterprise-class automation and deals with a wide variety of inter-disciplinary use cases from Enterprise Vulnerability Management, Cloud Security, Identity and Access Management, Penetration Testing and Endpoint Security. The ability to adapt, improvise, and improve constantly is a key feature of GISAO team members.
GISAO leverages a broad set of tools to accomplish their security automation objectives. Technologies include HP Operations Orchestrator, Rundeck, Python, AWS services (Lambda, RDS, S3, EC2), Elasticsearch, Kibana, Tableau and StreamSets. Our automation sources data from, and provides integration to/from products such as Qualys, Tenable, McAfee EPO, Tanium, Trend AV, Symantec DLP, AWS, Azure, GCP, Axonius, Kenna, IBM QRadar, Splunk, ServiceNow, and more.
The GISAO Sr. Security Specialist exists to maintain and enhance the cybersecurity analytics platform and develop automation of security workflows across a variety of tools and platforms. GISOA consults with security process and tool owners across the company, architects solutions which will maximize efficiency, effectiveness, and coverage, develops, implements and maintains operational availability of data and automation routines. The GISAO Sr Security Specialist’s success is measured by the number of hours and dollars saved, and amount of risk reduced for GIS and Information Security Stakeholders.
The GISAO Team spans the entire solution delivery lifecycle, from requirements through operations and maintenance. Within that breadth, this role is focused on data architecture, data management, data profiling, ETL development, and design, administration, and maintenance of database stores (MS-SQL).
- Collect, analyze and collaboratively solution use cases brought to GISAO by Information Security Stakeholders
- Develop, test, document and maintain solutions delivered; focused on relational store design and ETL, development, and maintenance, but inclusive of other systems and data automation.
- Manage timelines, expectations, documentation and delivery of solutions as assigned
- Support GIS Automation & Orchestration Operations Team by diagnosing, troubleshooting, and providing operational support.
- Data Management and data architecture, including source system analysis, ETL design, schema design, data profiling and data quality for an enterprise-scale cybersecurity analytics platform.
- Automation & orchestration of use cases, addressing initial requirements through final delivery of code and infrastructure.
- Engineering data integration, data presentation and automation of security workflows, including feature development, testing, deployment, operations automation and monitoring.
- Compiling use case reviews, structuring development work into tasks, and creating other technical documentation aligned with functions defined by the use case.
- Managing the hand-off of developed and delivered solutions to tier I operational support.
- Demonstrating advanced technical proficiency in support of those functions, including tool proficiency (can analyze, configure, assist in deployment, operate), coding, technical development and implementation.
- Engineering solutions utilizing the selected GISAO tools and platforms, including ASW services (Lambda, RDS, S3 and EC2), Python, MSSQL Server, Elasticsearch, Kibana, and Tableau.
- Providing situation based support, using in-depth knowledge of TWDC technologies and policies, to ensure systems are delivered in accordance with and are aligned with Company security requirements, e.g., architecture assessments, secure development training, conducting RTOs, etc.
- 5 or more years of experience in a combination of software engineering, data engineering, technical operations or security engineering
- Data warehousing, analytics, risk management or security architecture experience are a plus
- Skilled in the use of:
- AWS Lambda, S3, EC2 and S3
- RESTful API’s
- One or more ETL tools such as StreamSets, Informatica, Pentaho
- One or more reporting tools such as Kibana, Tableau, Power BI
- Database schema design
- Data analysis techniques
- Development support tools such as GitHub/GitLab and Jira
- Machine learning, Snowflake, data catalog tools such as Alation, Informatica EDC
- Licenses / Training
- AWS Certified Developer, CISSP a plus
Required EducationBA/BS in Computer Science or appropriate work experience
Preferred EducationMS Computer Science Preferred
About The Walt Disney Company (Corporate):
At Disney Corporate you can see how the businesses behind the Company’s powerful brands come together to create the most innovative, far-reaching and admired entertainment company in the world. As a member of a corporate team, you’ll work with world-class leaders driving the strategies that keep The Walt Disney Company at the leading edge of entertainment. See and be seen by other innovative thinkers as you enable the greatest storytellers in the world to create memories for millions of families around the globe.
About The Walt Disney Company:
The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise with the following business segments: media networks, parks and resorts, studio entertainment, consumer products and interactive media. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney’s stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.
This position is with Disney Worldwide Services, Inc., which is part of a business segment we call The Walt Disney Company (Corporate).
Disney Worldwide Services, Inc. is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Disney fosters a business culture where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a rapidly changing world.