Skip to Main Content
EN
The Walt Disney Company. Be you. Be here. Be part of the story.

Be Part of the Story

Staff Security Engineer - Security Architecture & Engineering (Project Hire)

申請 稍後繼續申請 Job ID 10069072 職位地點 格倫代爾, 加利福尼亚州, 美國 有意工作的公司 The Walt Disney Company (Corporate) 張貼日期 2024/04/29

此職位倡議遙距工作模式,即表示員工將會持續遙距工作,公司不會在指定地點為其分配工作間。

工作概要:

We are defenders of the magic, waging an epic battle to ­­­­­­safeguard our franchises, protect our people, and ensure the world’s most admired entertainment company is not impacted by cybersecurity threats. The Walt Disney Company is scouring the known talent universe to find security engineers desiring to join our Studios Cyber Team. This position builds and operates systems that provide stay-secure capabilities to our Studio customers. We are partners in protecting Disney’s highly respected portfolio including Marvel Studios, Pixar Animation Studios, Lucasfilm, Disney Live Action Films, Walt Disney Animation Studios, Searchlight Pictures, and 20th Century Studios.

To exceed the expectations of our versatile, creative partners, we need highly motivated, professionals who are passionate about finding new ways to deliver best-in-class cybersecurity capabilities. The Staff Security Engineer - Security Architecture & Engineering role is part of a team that is responsible for validating our content creation and delivery platforms, services, applications, workflows, and websites are designed and implemented to the highest security standards. You will be responsible for assisting in the secure design and analysis of on-premise and cloud-based infrastructure and applications where studio content is produced. This is a deeply technical role, requiring a solid grasp and experience implementing a variety of cloud infrastructure solutions and services, as well as network security, identity, cyber security, privileged access, and related technologies, using solid design principles.

Areas of Responsibilities

  • Conduct security architecture and design reviews of high-impact applications including both internally developed applications and 3rd party managed applications.
  • Lead in-depth security assessments of sophisticated workflows spanning multiple applications, performing and/or coordinating multiple security assessment workstreams such as threat modeling, penetration testing, DAST scanning, and code review.
  • Review output from Dynamic Application Security Testing (DAST) tools and provide feedback on results.
  • Evaluate the security posture of cloud environments through manual review and automated tooling. Review output from Cloud Security Posture Management (CSPM) tools. Provide guidance to stakeholders on approaches to remediating identified issues.
  • Conduct hands-on security testing of web, mobile applications and cloud-based services. Be capable of identifying traditional application-level issues such as injection, authentication, and misconfiguration vulnerabilities, but also identify vulnerabilities that lead to bypass of security controls.
  • Participate in proof of concepts and other technical evaluations of technologies, designs, and solutions and provide security requirements and recommendations.
  • Serve as a point of escalation/mentor for junior engineers, and provide guidance on the use of DAST, SAST, CSPM tools, and application/cloud security standard methodologies. Participate in the evaluation of security tools used across the organization.

Basic Qualifications

  • Minimum of 7+ years of experience in cybersecurity and cloud infrastructure engineering/architecture.
  • In-depth knowledge of public clouds such as AWS, Azure, and GCP. Experience with securing AWS workloads is required.
  • Proven ability to analyze and assess complicated application architectures and workflows to identify risk.
  • Significant penetration testing experience and offensive capabilities in key focus areas including web applications, mobile applications, networks, cloud, and infrastructure.
  • Basic knowledge of content security controls such as DRM, and visible and forensic watermarking is required.
  • Detailed understanding of network technologies including routers, switches, load balancers, firewalls, proxies, etc.
  • Familiarity with CI/CD principals, tools, and services. Hands-on experience implementing SAST, DAST, and SCA tooling is a plus.
  • Experience securing a microservice environment, along with demonstrable knowledge of container technologies such as Kubernetes and Docker and securing such environments.

Preferred Qualifications

  • One or more current security-related certifications (e.g., CISSP, SANS GIAC, etc.)
  • One or more cloud security certifications (AWS, Azure, GCP, CCSP).
  • Consistent track record of driving application security assessments for an organization.

Education

  • Bachelor’s degree in Computer Science, Computer Engineering, or related technical field, and/or equivalent work experience, or significant experience and progress towards professional credentials.

This is an estimated 30-month project hire placement with no guarantee of permanent placement.

#DISNEYTECH


The hiring range for this position in California is $136,038 - $182,490 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

其他資訊:

DISNEYTECH


關於 The Walt Disney Company (Corporate):

在 The Walt Disney Company (Corporate),你會看到公司強大品牌背後各業務如何融會交流,建構出全球最創新、影響深遠和備受尊崇的娛樂公司。作為企業團隊的一份子,你將會與推動策略以讓The Walt Disney Company穩佔娛樂界頂尖地位的世界精英領袖一同工作。與其他具有創新精神的思想家惺惺相惜,同時讓這個世界上最偉大的故事敍述家為全球各地千百萬家庭締造回憶。

關於 The Walt Disney Company:

Walt Disney Company 連同其子公司和聯營公司,是領先的多元化國際家庭娛樂和媒體企業,其業務主要涉及三個範疇:Disney Entertainment、ESPN 及 Disney Experiences。Disney 在 1920 年代的起步之初,只是一間卡通工作室,至今已成為娛樂界的翹楚,並昂然堅守傳承,繼續為家庭中每位成員創造世界一流的故事與體驗。Disney 的故事、人物與體驗傳遍世界每個角落,深入人心。我們在 40 多個國家/地區營運業務,僱員及演藝人員攜手協力,創造全球和當地人們都珍愛的娛樂體驗。

這個職位隸屬於 Disney Worldwide Services, Inc., 其所屬的業務部門是 The Walt Disney Company (Corporate)

Disney Worldwide Services, Inc. 是提供平等機會的僱主。申請人將獲考慮聘僱,而不分種族、膚色、宗教、性別、年齡、國籍、性取向、性別身份、殘疾、受保護退伍軍人身份或聯邦、州份或地方法律所禁止的任何其他基礎。Disney 培養商業文化,所有人的想法和決策都有助我們發展、創新、創造最好的故事,並與瞬息萬變的世界息息相關。

申請 稍後繼續申請