Skip to main content

Staff Security Engineer - Security Architecture & Engineering

Apply Now
Job ID 10069072 Location Glendale, California, United States Business The Walt Disney Company (Corporate) Date posted Apr. 29, 2024 This role is considered remote, which means the employee will work remotely on an ongoing basis and will not have an assigned workspace at a Company designated location.

Job Summary:

We are defenders of the magic, waging an epic battle to ­­­­­­safeguard our franchises, protect our people, and ensure the world’s most admired entertainment company is not impacted by cybersecurity threats. The Walt Disney Company is scouring the known talent universe to find security engineers desiring to join our Studios Cyber Team. This position builds and operates systems that provide stay-secure capabilities to our Studio customers. We are partners in protecting Disney’s highly respected portfolio including Marvel Studios, Pixar Animation Studios, Lucasfilm, Disney Live Action Films, Walt Disney Animation Studios, Searchlight Pictures, and 20th Century Studios.

To exceed the expectations of our versatile, creative partners, we need highly motivated, professionals who are passionate about finding new ways to deliver best-in-class cybersecurity capabilities. The Staff Security Engineer - Security Architecture & Engineering role is part of a team that is responsible for validating our content creation and delivery platforms, services, applications, workflows, and websites are designed and implemented to the highest security standards. You will be responsible for assisting in the secure design and analysis of on-premise and cloud-based infrastructure and applications where studio content is produced. This is a deeply technical role, requiring a solid grasp and experience implementing a variety of cloud infrastructure solutions and services, as well as network security, identity, cyber security, privileged access, and related technologies, using solid design principles.

Areas of Responsibilities

  • Conduct security architecture and design reviews of high-impact applications including both internally developed applications and 3rd party managed applications.
  • Lead in-depth security assessments of sophisticated workflows spanning multiple applications, performing and/or coordinating multiple security assessment workstreams such as threat modeling, penetration testing, DAST scanning, and code review.
  • Review output from Dynamic Application Security Testing (DAST) tools and provide feedback on results.
  • Evaluate the security posture of cloud environments through manual review and automated tooling. Review output from Cloud Security Posture Management (CSPM) tools. Provide guidance to stakeholders on approaches to remediating identified issues.
  • Conduct hands-on security testing of web, mobile applications and cloud-based services. Be capable of identifying traditional application-level issues such as injection, authentication, and misconfiguration vulnerabilities, but also identify vulnerabilities that lead to bypass of security controls.
  • Participate in proof of concepts and other technical evaluations of technologies, designs, and solutions and provide security requirements and recommendations.
  • Serve as a point of escalation/mentor for junior engineers, and provide guidance on the use of DAST, SAST, CSPM tools, and application/cloud security standard methodologies. Participate in the evaluation of security tools used across the organization.

Basic Qualifications

  • Minimum of 7+ years of experience in cybersecurity and cloud infrastructure engineering/architecture.
  • In-depth knowledge of public clouds such as AWS, Azure, and GCP. Experience with securing AWS workloads is required.
  • Proven ability to analyze and assess complicated application architectures and workflows to identify risk.
  • Significant penetration testing experience and offensive capabilities in key focus areas including web applications, mobile applications, networks, cloud, and infrastructure.
  • Basic knowledge of content security controls such as DRM, and visible and forensic watermarking is required.
  • Detailed understanding of network technologies including routers, switches, load balancers, firewalls, proxies, etc.
  • Familiarity with CI/CD principals, tools, and services. Hands-on experience implementing SAST, DAST, and SCA tooling is a plus.
  • Experience securing a microservice environment, along with demonstrable knowledge of container technologies such as Kubernetes and Docker and securing such environments.

Preferred Qualifications

  • One or more current security-related certifications (e.g., CISSP, SANS GIAC, etc.)
  • One or more cloud security certifications (AWS, Azure, GCP, CCSP).
  • Consistent track record of driving application security assessments for an organization.

Education

  • Bachelor’s degree in Computer Science, Computer Engineering, or related technical field, and/or equivalent work experience, or significant experience and progress towards professional credentials.

#DISNEYTECH


The hiring range for this position in California is $136,038 - $182,490 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

About The Walt Disney Company (Corporate):

At Disney Corporate you can see how the businesses behind the Company’s powerful brands come together to create the most innovative, far-reaching and admired entertainment company in the world. As a member of a corporate team, you’ll work with world-class leaders driving the strategies that keep The Walt Disney Company at the leading edge of entertainment. See and be seen by other innovative thinkers as you enable the greatest storytellers in the world to create memories for millions of families around the globe.

About The Walt Disney Company:

The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise that includes three core business segments: Disney Entertainment, ESPN, and Disney Experiences. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney’s stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.

This position is with Disney Worldwide Services, Inc., which is part of a business we call The Walt Disney Company (Corporate).

Disney Worldwide Services, Inc. is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, disability, protected veteran status or any other basis prohibited by federal, state or local law. Disney fosters a business culture where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a rapidly changing world.

DISABILITY ACCOMMODATION FOR EMPLOYMENT APPLICATIONS

The Walt Disney Company and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers including individuals with disabilities and veterans with disabilities. If you have a disability and believe you need a reasonable accommodation in order to search for a job opening or apply for a position, email Candidate.Accommodations@Disney.com with your request. This email address is not for general employment inquiries or correspondence. We will only respond to those requests that are related to the accessibility of the online application system due to a disability.

Sign up to receive the latest news and company information

Be you. Be here. Be part of story.

Global Opportunities

US & Canada

The Walt Disney Company entertains, informs and inspires people around the globe through the power of unparalleled storytelling, reflecting the iconic brands, creative minds and innovative technologies that make ours the world’s premier entertainment company.

Search All US & Canada Jobs

LATAM

The Walt Disney Company Latin America is the leading family entertainment company in Latin America and has been present in the region since the 1940’s when Walt Disney traveled to Brazil, Argentina and Peru.

Search All Latin America Jobs

EMEA

Disney EMEA aims to drive growth, innovation and brand affinity across an extremely diverse collection of countries with a team of over 6,000 employees operating in 59 markets with offices in 29 countries.

Search All EMEA Jobs

India

The Walt Disney Company entertains, informs and inspires people around the globe through the power of unparalleled storytelling, reflecting the iconic brands, creative minds and innovative technologies that make ours the world’s premier entertainment company.

Search All India Jobs

APAC

For over 70 years, The Walt Disney Company has been entertaining consumers in Asia Pacific – and enriching people’s lives. Today’s consumer can discover new branded experiences in many ways and in many markets across the APAC region.

Search All APAC Jobs
nighttime view of the Spaceship Earth attraction at Walt Disney World in Florida

The Walt Disney Company is a global community of unparalleled storytellers, creative minds, and innovative technologies, with offices located across the globe.

Sign Up for Job Alerts

Get the latest job opportunities as they become available.

Watch Our Jobs

Sign up to receive the latest news and company information based on your preferences. An asterisk indicates a required field.

Interested InSelect a job category from the list of options. Select a location from the list of options. Finally, click “Add” to create your job alert.

By clicking "Submit", you agree to our Terms of Use (opens in new window) and acknowledge that you have read our Privacy Policy (opens in new window).

By clicking "Submit", you agree to our Terms of Use (opens in new window) and acknowledge that you have read our Privacy Policy (opens in new window). If I have elected to receive marketing messages or newsletters, I may withdraw my consent for these marketing messages at any time.

By clicking "Submit", you agree to our Terms of Use (opens in new window) and acknowledge that you have read our Privacy Policy (opens in new window), Cookies Policy (opens in new window) and EU Privacy Rights (opens in new window).

How we use your personal information and your rights:

  1. Your personal information is controlled by The Walt Disney Company Limited of 3 Queen Caroline Street, London, W6 9PE, United Kingdom.
  2. When you visit or shop with Disney or use any Disney product, service or mobile application, other members of The Walt Disney Company Family of Companies may also use your information to provide you these services, personalise your experience and send you service related updates and communications.
  3. You have a number of rights including the right to request access to, change, or remove your personal information, or to change your marketing preferences (including withdrawing your consent at any time.) Please see our Privacy Policy (opens in new window) to learn more about managing your marketing preferences or deleting your account.
  4. Our Data Protection Officer can be contacted by emailing: dataprotection@disney.co.uk.
  5. You have a right to lodge a complaint with the UK Information Commissioner's Office: https://ico.org.uk/ (opens in new window).
  6. For more information about Disney's data collection and use practices please read Disney's Privacy Policy (opens in new window).

By clicking "Submit", you agree to our Terms of Use (opens in new window) and acknowledge that you have read our Privacy Policy (opens in new window) and Collection Statement (opens in new window).

For more information about our general data collection, use, and practices, including how to manage your preferences, please read our Privacy Policy (opens in new window). I have read and agree to the Terms of Use (opens in new window).