Security Engineer
工作概要:
Department Description:
At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences — and we’re constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.
The Global Information Security (GIS) organization strives to secure the magic by employing best-in-class services to assess, prevent, detect, and respond to cyber threats that present risk to The Walt Disney Company. We enable the business by integrating enterprise and business segment-specific supported services to create a robust, efficient, and adaptable cybersecurity program. Our key objectives are to:
- Secure the Magic by protecting information systems and platforms.
- Reduce Risk by proactively assessing, preventing, and detecting to prevent harm to the Company and our Guests.
- Strengthen the business through optimizing execution, application, and technology used to protect the Company.
- Innovate by investing in core capabilities to enhance operational efficiency.
Team Description:
- The Identity & Access Management (IAM) – Directory Services team is responsible for building and operating a secure, standardized, and automated enterprise identity foundation across The Walt Disney Company. We provide the authoritative directory platforms that enable authentication, authorization, and access governance for both human and non‑human identities.
- Our mission is to move identity governance from manual, reactive processes to automated, policy‑driven enforcement, ensuring identities are secure, compliant, and healthy by default across their lifecycle. We partner closely with security, infrastructure, and application teams to eliminate legacy risk, reduce operational toil, and enable modern, cloud‑first identity capabilities at enterprise scale.
What You’ll Do:
Directory Platform Engineering & Operations
- Engineer, harden, and operate enterprise and multidomain Active Directory environments supporting critical business workloads.
- Lead Active Directory consolidation and domain rationalization efforts, including enterprise, eCommerce, and business‑unit directories.
- Support RadiantLogic’s Virtual Directory System operations and enhancements.
- Establish and enforce multi‑domain baseline identity security standards across environments.
- Implement and mature RBAC‑based access models across Active Directory.
- Integrate AD with Privileged Identity Management (PIM) and Privileged Access Management (PAM) platforms.
- Help with eliminating standing privilege through group‑based, time‑bound, and JIT access patterns.
- Implement and support synchronization between Active Directory and Entra ID.
- Support cross‑tenant identity governance for business segments and federated environments.
- Enable automated human and non‑human identity governance, including monitoring, remediation, and compliance reporting.
- Reduce directory and tool sprawl while maintaining service reliability and business continuity.
- Mentor and uplift junior engineers; contribute to repeatable engineering patterns and documentation.
Required Qualifications & Skills:
- 8+ years of hands‑on experience engineering and operating large‑scale Active Directory environments.
- Deep expertise in:
- Active Directory architecture, trusts, replication, DNS, PKI
- Multi‑domain / multi‑forest designs
- AD security hardening and recovery
- Radiant Logic’s Virtual Directory Services
- Proven experience implementing or supporting:
- RBAC, PIM, and PAM
- Privileged account separation and Tier 0 controls
- Strong troubleshooting skills in complex, highly regulated environments.
- Experience working in enterprise‑scale IAM or directory services teams.
Preferred Qualifications:
- Experience integrating AD with Entra ID / Azure AD in hybrid or cloud‑first environments.
- Familiarity with identity governance automation, non‑human identity management, and continuous compliance.
- Experience supporting cross‑tenant or multi‑business‑unit identity models.
- Background in directory consolidation, legacy system sunset, or M&A identity integration.
- Comfort operating in environments with high security, resilience, and audit expectations.
Required Education:
- Bachelor’s degree in Computer Science, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience
Engineer, harden, and operate large‑scale, multi‑domain Active Directory environments supporting critical business workloads.
Lead Active Directory consolidation and domain rationalization, reducing directory sprawl across enterprise, eCommerce, and business units.
Operate and enhance Virtual Directory services (RadiantLogic) to support federated and multi‑source identity use cases.
Define, implement, and enforce baseline identity security standards across complex, multi‑domain environments.
Design and mature RBAC‑based access models within Active Directory.
Integrate Active Directory with Privileged Identity and Access Management (PIM/PAM) platforms.
Eliminate standing privilege through group‑based, time‑bound, just‑in‑time (JIT) access patterns.
Implement and sustain Tier 0 security posture, including privileged account separation and Privileged Access Workstations (PAW).
Design and operate bi‑directional synchronization between Active Directory and Entra ID, partnering with cloud identity teams for consistent governance.
Improve identity governance and lifecycle accuracy through authoritative attribute synchronization, cross‑tenant governance, automation, documentation, and mentoring of junior engineers.
關於The Walt Disney Company (Corporate):
在 The Walt Disney Company (Corporate),你會看到公司強大品牌背後各業務如何融會交流,建構出全球最創新、影響深遠和備受尊崇的娛樂公司。作為企業團隊的一份子,你將會與推動策略以讓The Walt Disney Company穩佔娛樂界頂尖地位的世界精英領袖一同工作。與其他具有創新精神的思想家惺惺相惜,同時讓這個世界上最偉大的故事敍述家為全球各地千百萬家庭締造回憶。
關於 The Walt Disney Company:
Walt Disney Company 連同其子公司和聯營公司,是領先的多元化國際家庭娛樂和媒體企業,其業務主要涉及三個範疇:Disney Entertainment、ESPN 及 Disney Experiences。Disney 在 1920 年代的起步之初,只是一間卡通工作室,至今已成為娛樂界的翹楚,並昂然堅守傳承,繼續為家庭中每位成員創造世界一流的故事與體驗。Disney 的故事、人物與體驗傳遍世界每個角落,深入人心。我們在 40 多個國家/地區營運業務,僱員及演藝人員攜手協力,創造全球和當地人們都珍愛的娛樂體驗。
這個職位隸屬於 Disney (India) Private Limited,其所屬的業務部門是 The Walt Disney Company (Corporate)。
欲了解更多關於 Disney 針對應徵者使用 AI 的政策 請按此。
遇到技術問題?查看常見問題以尋求協助。
招聘流程
-
您的故事從哪裡開始?
探索 Disney 職位空缺和 The Life at Disney 網誌,了解華特迪士尼公司有待發掘的所有精彩機會。
-
迪士尼的故事裏,有你更精彩成就迪士尼故事
有許多不同品牌和業務可供探索。當您找到適合您的機會後,請填寫您的申請,進行下一步。
-
下一章
申請後,您將收到一封電子郵件,讓您可存取應徵者控制面板。建立您的登入資料,並確保經常檢視您的控制面板,以查看申請進度。
探索此地點 印度
The Walt Disney Company 運用精采故事的非凡力量,為世界各地獻上頂級娛樂、豐富資訊及靈感啟發,締造出使我們成為全球頂尖娛樂公司的知名品牌、創意理念及創新科技。
相關工作
我們的文化
相關內容
-
-
多元、公平與包容 文化與價值觀 員工故事 工作與創新 學生及應屆畢業生 Life at Disney: Hong Kong Disneyland Resort -
工作機會 員工故事 學生及應屆畢業生 A Dream to Perform Comes True for a Disney Intern at Hong Kong Disneyland -
-
工作機會 員工故事 學生及應屆畢業生 A Dream to Perform Comes True for a Disney Intern at Hong Kong Disneyland -
-
員工故事 學生及應屆畢業生 From Disney Internships to Beyond: Meet Three Hong Kong Disneyland Resort Cast Members Making an Impact -
員工故事 學生及應屆畢業生 Disney Internships Lead to Magical Friendships and Careers at Hong Kong Disneyland Resort -
-
-
事業發展 員工故事 Disney Cruise Line’s leadership team in The Bahamas on growth, building careers, and making magic -
登記收取職缺通知
即時收到最新的工作機會的資訊。
分享
連結會在新分頁中開啟。