Sr Sec Specialist, Sec Eng Auto & Orch
Seattle, WA - USApply Now Apply Later
Job ID 733514BR Location Orlando, Florida, United States; Seattle, Washington, United States Business The Walt Disney Company (Corporate) Date posted Dec. 18, 2019
Job Summary:At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences — and we’re constantly looking for new ways to enhance and protect these exciting experiences.
The Global Information Security (GIS) group provides services and solutions to protect the value and use of Disney’s information through risk evaluation, collaboration, standardization, enforcement, and education across the enterprise. We protect the brand and reputation while enabling and supporting business objectives. GIS teams are located in Seattle, Burbank, and Orlando.
In order to ensure that our services keep TWDC secure, we follow an ongoing, iterative process, including continued reevaluation of our services over time to address emerging threats as well as changes in business and technology. This process includes:
- Analysis of known and emerging threats to determine risks against TWDC assets
- Creation, maintenance, governance and communication of security policies and standards across TWDC
- Assessment and audit of compliance against the security policies and standards
- Assurance that TWDC assets are effectively managed and monitored to meet TWDC security criteria
Using a variety of tools and platforms, the Global Information Security Automation & Orchestration (GISAO) Team takes on use cases from Information Security Stakeholders at The Walt Disney Company, crafting solutions that increase business agility, reduce costs, optimize resources, and manage the complexity associated with Information Security tools and processes. GISAO tracks the value we return to TWDC and commits to returning time and money savings back to the organization each year.
GISAO has established a set of standard practices, platforms, and tools used for these activities, but remains philosophically agnostic when it comes to specific technologies. If we come across a new practice, platform, or tool that will achieve our goals, and we know we can support it ongoing at an Enterprise-Class level, we will implement it. GISAO maintains Enterprise-Class automation implementations, and deals with a wide variety of inter-disciplinary use cases from Enterprise Vulnerability Management to Cloud Inventory & Security to Endpoint Security. The ability to adapt, improvise, and improve constantly is a key feature of GISAO team members, as we interact weekly with many aspects of Global Information Security and beyond.
Currently, GISAO is invested in HP Operations Orchestrator, AWS technologies (Lambda, RDS, S3, and EC2), Elasticsearch, Kibana, Tableau and StreamSets. We interact with data and functionality from Security tools such as Qualys, McAfee EPO, Tanium, Prisma, Palo Alto, Retina, Trend AV, AWS APIs, Lumeta, IBM QRadar, Splunk, ServiceNow, and more.
- Provides situation based support, using in-depth knowledge of TWDC technology, to ensure systems are designed in accordance with and are aligned with Company security requirements; includes architecture assessments, secure development training, and conducting RTOs
- Develops technical monitoring, assessment and response solutions that meet current specifications
- Reviews and presents reports (e.g., penetration test results, incident response metrics, forensics, network monitoring metrics), position papers, assessment recaps to team (peers) and next level of leadership within team
- Exhibits advanced technological expertise and leadership of activities related to:
- Developing creating infrastructure solutions in SQL, AWS RDS, AWS EC2, AWS Lambda, Python, Elasticsearch.
- Performing automated ETL of diverse data sources in SQL, JSON, Flat files, XLS, and retrieved from a variety of source locations, including WebAPIs, S3, and OneDrive
- Developing Automation & Orchestration use cases from initial requirements through final delivery of code and infrastructure. Inclusive of Agile Management of workload
- Intaking new use cases, and green-field designing solutions for those use cases, managing expectations of use case owners and assuring their understanding of exactly how automation will change the way they work
- Targeting those Information Security use cases likely to have the greatest impact on business agility, reduction of costs, optimization of resources, or managing of complexity
- Developing technical monitoring, assessment and response solutions for Automation Solutions
- Compiling use case reviews, structuring development work into tasks, and creating other technical documentation aligned with functions defined by the use case
- Managing the hand-off of developed and delivered use cases to operational support
- Demonstrating advanced technical proficiency in support of those functions, including tool proficiency (can analyze, configure, assist in deployment), coding, technical development and implementation
- Designing the Architecture of GISAO Tools, Platforms, and Processes for maximum efficiency, effectiveness, and coverage
- 5 years of experience working with SQL, Python, JSON, XML, AWS RDS, EC2, and Lambda
- 8 years of experience working with highly heterogeneous ETL and business analytics systems. If specific to security, that’s a plus
- All Basic plus ELK Stack and StreamSets
- BA/BS in business or computer science or appropriate work experience
About The Walt Disney Company (Corporate):
At Disney Corporate you can see how the businesses behind the Company’s powerful brands come together to create the most innovative, far-reaching and admired entertainment company in the world. As a member of a corporate team, you’ll work with world-class leaders driving the strategies that keep The Walt Disney Company at the leading edge of entertainment. See and be seen by other innovative thinkers as you enable the greatest storytellers in the world to create memories for millions of families around the globe.
About The Walt Disney Company:
The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise with the following business segments: media networks, parks and resorts, studio entertainment, consumer products and interactive media. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney’s stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.
This position is with Disney Worldwide Services, Inc., which is part of a business segment we call The Walt Disney Company (Corporate).
Disney Worldwide Services, Inc. is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Disney fosters a business culture where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a rapidly changing world.
Watch Our Jobs
Sign up to receive new job alerts and company information based on your preferences.