Skip to main content

Staff Application Security Engineer - Content Security

Apply NowApply Later Job ID 946491BR Location Burbank, California, United States Business The Walt Disney Studios Date posted May 23, 2022 Flex Type Hybrid Preferred, Remote Possible

- This role is considered hybrid, which means the employee will work a portion of their time on-site from a Company designated location and the remainder of their time remotely. A remote opportunity may be possible for qualified candidates under certain circumstances and, if granted, the employee would work remotely on an ongoing basis.

Job Summary:

The Walt Disney Studios includes Lucasfilm, Pixar, Walt Disney Animation, 20th Century Studio, Searchlight, Walt Disney Pictures, and Marvel Studios. The Content Security team supports these banners in protecting content creation through effective problem-solving, authentic partnerships, and technical expertise. Our team drives towards goals that include A) fostering a culture of content security B) eliminating the risk of content leaks and C) tailoring security solutions to meet our partners’ needs. Our clients are the Studios, and we assess the applications, vendors, and sites that the banners use to create their world-class content.

Do you love moviemaking and the thrill in the fast-paced environment of a movie studio? Do you understand technology and geek out over innovating to find solutions to complex problems? Can you partner across a complex ecosystem to work with both technical and non-technical oriented people to get the job done? Do you love sprinting up the learning curve to develop new skills and capabilities?

The Content Security Staff Engineer reports to the Senior Manager of Application and Cloud Security at The Walt Disney Studios. This role is part of the team that is responsible for ensuring that the applications, services, and platforms utilized for content creation have the requisite secure design, implementation, features, and functionality required to protect Disney Studios’ pre-release content. This is highly a technical role, requiring a strong understanding and experience implementing a variety of network security, identity, cyber security, privileged access, and related technologies, while incorporating secure design principles.

Responsibilities:

  • You will be responsible for leading Content Security (CS) assessments of applications, services, and platforms ensuring that the Appsec, Cloudsec, and CS features and functionality are sufficient.
  • You will act as a technical thought leader, as well as a trusted advisor to Studios partners for secure application design, development and configuration, secure cloud architecture design and implementation, and content security feature and functionality capabilities.
  • You, along with your peers, will perform research to stay ahead of the curve on content security products, services, technologies, and capabilities, and ensure that best of breed solutions are implemented whenever possible.
  • You will be expected to maintain current knowledge of security threats and vulnerabilities that could impact products and their technology stack components and help product teams identify solutions that meet security requirements.
  • You will be expected to contribute to and write policies and procedures around Content, Application, and Cloud Security.
  • You will partner with Studios’ technology teams, including, but not limited to: Networking, Architecture, and Engineering to ensure content security requirements are consistently implemented.
  • You will mentor and learn from peers within the larger Content Security Organization.
  • You will lead cross-functional troubleshooting of complex issues with the pertinent teams, as required.

Basic Qualifications:

Must have:
  • 7+ years of experience in secure software and/or cloud development, design, and architecture background and experience.
  • Hands on experience with software development experience.
  • Excellent understanding of web applications, web servers, frameworks, and protocols with respect to application development and cloud deployment.
  • Deep understanding for the need and appropriate use of application security testing tools like SAST, DAST, IAST and Open-Source Vulnerability Scanning and the identified findings and remediation.
  • Experience at least three of the following areas:
    • Encryption
    • Identity and Access Management
    • Securing Containers
    • Key management
    • Digital Rights Management (DRM)
    • Visual Watermarking
    • Forensic Watermarking
    • Web Application Firewall (WAF)
    • Cloud Access Security Broker (CASB)
  • Excellent presentation and written/verbal communication skills.
  • Experience in leading large-scale technology initiatives.
  • Technical documentation and artifact creation.
  • Excellent leadership and teamwork skills.
  • Strong problem solving and analytical skills.
  • Self-motivated and able to work independently.
  • Strong ability to influence people, teams, and organizations.

Preferred Qualifications:

  • Ability to effectively present and tailor communication of security threats and risks to a variety of audiences.
  • Experience with threat modelling.
  • Hands on penetration testing experience.
  • Experience with CheckMarx, Snyk, Fortify, BurpSuite, ZAP, SQLMap, SonarQube, Grabber, Invicti (Netsparker), Kali Linux, Arachni, Iron Wasp, Wapiti, MobSF, etc.
  • Experience with development tools: Jenkins, Artifactory, Github, Gitlab, Swaggerhub, Postman, etc.
  • Significant penetration testing experience including web applications, mobile applications, networks, cloud infrastructure.

Required Education

Bachelor's degree in Computer Science, Information Systems, Cybersecurity, IT Engineering, or equivalent industry experience.

Additional Information:

DISNEYTECH

#LI-AS3

About The Walt Disney Studios:

For over 95 years, The Walt Disney Studios has been the foundation on which The Walt Disney Company was built. Today it brings quality movies, episodic storytelling, music, and stage plays to consumers throughout the world. The Walt Disney Studios encompasses a collection of respected film studios, including Disney, Walt Disney Animation Studios, Pixar Animation Studios, Marvel Studios, Lucasfilm, 20th Century Studios, and Searchlight Pictures. It is also home to Disney Theatrical Productions, producer of world-class stage shows.

About The Walt Disney Company:

The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise with the following business segments: media networks, parks and resorts, studio entertainment, consumer products and interactive media. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney’s stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.

This position is with Walt Disney Pictures, which is part of a business we call The Walt Disney Studios.

Walt Disney Pictures is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Disney fosters a business culture where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a rapidly changing world.

Apply NowApply Later

Watch Our Jobs

Sign up to receive new job alerts and company information based on your preferences.

For Disney Job Alerts to work, JavaScript must be enabled in your browser.