Security Engineer - Security Assurance

59 Minutes ago • 3 Years + • Cyber Security

Job Summary

Job Description

The Security Engineer - Security Assurance will join the Disney Experience (DX) Security Research & Testing (SRT) team. Responsibilities include evaluating system and application configurations to identify misconfigurations, conducting compliance checks against security standards (CIS Benchmarks, NIST, TWDC policies), reviewing firewall, server, and endpoint configurations, analyzing configurations for vulnerabilities, using automated tools and scripts for detection, performing manual and automated security testing, simulating attacks, documenting findings in detailed reports, communicating results to stakeholders, and working with IT teams to implement fixes. The role also involves developing and maintaining security configuration baselines and proactively recommending configuration adjustments to mitigate risks.
Must have:
  • 3+ years IT security testing experience
  • Penetration Testing, Adversarial Testing, Red Team Testing experience
  • System hardening testing for Windows, Linux, macOS
  • Experience with Cloud Solutions (Azure, GCP, AWS) and SaaS
  • Knowledge of network devices and secure configurations
Good to have:
  • OffSec or other advanced security certifications
  • Major cloud provider platform certification
  • Security accreditation (CISSP, GCIH, CISM, GSEC, CEH, etc.)

Job Details

Job Summary:

Who We Are


At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences — and we’re constantly looking for new ways to enhance these exciting experiences.

The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.

The Global Information Security (GIS) organization strives to secure the magic by employing best-in-class services to assess, prevent, detect, and respond to cyber threats that present risk to The Walt Disney Company. We enable the business by integrating enterprise and business segment-specific supported services to create a robust, efficient, and adaptable cybersecurity program. Our key objectives are to:

  • Secure the Magic by protecting information systems and platforms.

  • Reduce Risk by proactively assessing, preventing, and detecting to prevent harm to the Company and our Guests.

  • Strengthen the business through optimizing execution, application, and technology used to protect the Company.

  • Innovate by investing in core capabilities to enhance operational efficiency.

Team Description

The Security Research and Testing (SRT) team specializes in simulating real-world cyberattacks to uncover vulnerabilities and evaluate the effectiveness of Disney Experiences (DX) and Disney Corporate (Corp) technology systems' security measures. By mimicking tactics used by malicious actors, the SRT team provides critical insights into potential weaknesses. They work closely with both technology and business teams across DX and Corp to analyze findings, strengthen security policies, and recommend targeted improvements to address gaps in infrastructure, processes, and training, ensuring a robust and resilient security posture.  

What You Will Do

We are hiring!  We need a Security Engineer – Security Assurance to join our Disney Experience (DX) Security Research & Testing (SRT) Team!

Responsibilities:

  • Evaluate system and application configurations to identify security misconfigurations. 

  • Conduct compliance checks against security standards: CIS Benchmarks, NIST, and TWDC policies. 

  • Review firewall, server, and endpoint configurations to ensure alignment with security policies. 

  • Analyze configurations to identify potential vulnerabilities such as open ports, weak encryption, or default credentials. 

  • Use automated tools and scripts to detect misconfigurations and vulnerabilities. 

  • Perform manual and automated testing of security settings on systems, applications, and networks. 

  • Simulate attacks or misuses to test the resilience of configurations. 

  • Document findings in detailed reports, including identified issues, potential impacts, and remediation recommendations. 

  • Communicate results to stakeholders, including technical and non-technical audiences. 

  • Provide recommendations to address misconfigurations and improve security posture. 

  • Work with IT teams to implement fixes and validate corrective actions. 

  • Assist in developing and maintaining security configuration baselines and standards.  

  • Proactively recommend adjustments to configurations to mitigate risks. 

Must Have

  • Minimum of 3+ years of related IT security testing experience such as Penetration Testing, Adversarial Testing, Red Team Testing

  • Experience conducting comprehensive cyber security testing of technology solutions within large-scale, complex, and dynamic IT environments.

  • Proficient in system hardening testing for operating systems (Windows, Linux, macOS).

  • Experience with Cloud Solutions (Azure, GCP, AWS) and Software as a Service (SaaS) solution.

  • Knowledge of network devices (routers, switches, firewalls) and their secure configurations, and configuration management & auditing tools.

  • Understanding of security frameworks and standards (NIST, CIS, etc.)

Nice to Have

  • OffSec or other advanced security testing certifications

  • Major cloud provider platform certification (e.g. AWS Solution Architect, Google Cloud Engineer, Microsoft Solution Architect, etc.) 

  • Security accreditation (e.g., CISSP, GCIH, CISM, GSEC, CEH, etc.) 

Education

  • Bachelor’s degree in Computer Science, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience

#DISNEYTECH

#LI-JP4

Similar Jobs

Ubisoft - Tech Lead in Detection and Response

Ubisoft

Montreal, Quebec, Canada (On-Site)
4 Weeks ago
N-iX - Senior Manual QA Engineer (Big Data)

N-iX

Ukraine (Remote)
13 Hours ago
PwC - IN-Senior Associate –D365 CRM Technical_MS Dynamics_Advisory_Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
2 Months ago
Barracuda Networks  Inc  - Information Security Engineer

Barracuda Networks Inc

Bengaluru, Karnataka, India (On-Site)
2 Months ago
ION - Network Security Engineer

ION

Collecchio, Emilia-Romagna, Italy (Hybrid)
4 Months ago
Saviynt - Product Manager, Non-human Identities

Saviynt

El Segundo, California, United States (Remote)
4 Months ago
ION - SOC Manager

ION

Noida, Uttar Pradesh, India (On-Site)
4 Months ago
PwC - Risk Assurance-IT Senior Associate

PwC

Makati, Metro Manila, Philippines (On-Site)
4 Months ago
Rush Street Interactive - Threat Intelligence Analyst

Rush Street Interactive

Serbia (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Hitachi - Microsoft Dynamics 365 CE Developer (Offshore Delivery - Sustained Engineering)

Hitachi

Bengaluru, Karnataka, India (Remote)
4 Months ago
ByteDance - Senior Software Engineer - IaaS AI Infra

ByteDance

San Jose, California, United States (On-Site)
1 Day ago
IO Interactive - Lead Online Programmer

IO Interactive

Brighton And Hove, England, United Kingdom (Hybrid)
1 Month ago
The Walt Disney Company - Software Engineer, Test

The Walt Disney Company

Emeryville, California, United States (On-Site)
3 Months ago
Tencent - Senior Big Data Solution Architect

Tencent

Singapore (On-Site)
1 Month ago
Trend Micro - (Sr.) Cloud Backend Engineer

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago
GoTo Group - Lead Software Engineer - Engineering Platforms

GoTo Group

Bengaluru, Karnataka, India (On-Site)
3 Months ago
N-iX - Middle .NET FullStack Engineer

N-iX

Ukraine (Remote)
14 Hours ago
Microsoft - Principal Engineering Manager

Microsoft

Hyderabad, Telangana, India (On-Site)
1 Month ago
Luxoft - BI Developer (SSIS and SSAS)

Luxoft

Gurugram, Haryana, India (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Orlando, Florida, United States

Riot Games - Manager, Software Engineering - VALORANT, Live Design

Riot Games

Los Angeles, California, United States (On-Site)
3 Months ago
Scientific Games  - Facilities Maintenance Tech

Scientific Games

Alpharetta, Georgia, United States (On-Site)
2 Months ago
Epic Games - Product Management Director

Epic Games

Cary, North Carolina, United States (On-Site)
2 Weeks ago
My Fitness Pal - Product Design Director

My Fitness Pal

United States (Remote)
1 Month ago
Microsoft - Research Intern - AI, Machine Learning, Statistics

Microsoft

Cambridge, Massachusetts, United States (On-Site)
1 Month ago
Fluence - Chief Battery Energy Storage System (BESS) Engineer

Fluence

Arlington, Virginia, United States (Hybrid)
4 Months ago
ByteDance - Senior Software Engineer, Global Payment Data Privacy

ByteDance

San Jose, California, United States (On-Site)
3 Months ago
Axinous - Sr. Staff ML Engineer

Axinous

San Jose, California, United States (Hybrid)
1 Month ago
Microsoft - Senior Researcher – Artificial Intelligence

Microsoft

Redmond, Washington, United States (On-Site)
1 Month ago
Nintendo - Contract - Associate Environment Artist

Nintendo

Redmond, Washington, United States (Hybrid)
3 Weeks ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

ION - Platform Security Analyst

ION

Milan, Lombardy, Italy (On-Site)
4 Months ago
PwC - IN-Senior Associate__SAP GRC_ITRA_Advisory_  Gurgaon/Mumbai/Bangalore

PwC

Gurugram, Haryana, India (On-Site)
4 Months ago
PwC - FY25 - Talent Pool - Consulting - Associate

PwC

Jakarta, Jakarta, Indonesia (On-Site)
4 Months ago
PwC - OT/Supply Chain/Manufacturing Security Director

PwC

Zürich, Zurich, Switzerland (On-Site)
4 Months ago
PwC - ETIC, GCP/Oracle Cloud Engineer - Manager

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
4 Months ago
Palo Alto Networks - Domain Consultant - Security Operations Transformation

Palo Alto Networks

New York, New York, United States (Remote)
3 Months ago
ByteDance - Senior Software Engineer, Global Payment Security

ByteDance

San Jose, California, United States (On-Site)
3 Months ago
ION - Network Security Engineer

ION

Italy (Hybrid)
4 Months ago

Get notifed when new similar jobs are uploaded

About The Company

From classic animated features and exhilarating theme park attractions to cutting edge sports coverage, and the hottest shows on television, The Walt Disney Company has been making magic since 1923, creating unforgettable stories that connect with audiences around the world. And we’re just getting started!

The key to our success…. The Cast, Crew, Imagineers and Employees who honor Disney’s rich legacy by stretching the bounds of imagination to create the never-before-seen, bringing unparalleled entertainment experiences to people of all ages. Begin a career that delivers unparalleled creative content and experiences to audiences around the world and just imagine the stories you could be part of…

What is #LifeAtDisney like? It’s a series of magical moments with cast members and employees developing and telling our stories in the most innovative ways. Whether it’s a day spent as a Disney VoluntEAR, or celebrating the release of a new interactive experience, retail product or movie, our days are filled with the knowledge that we are creating entertainment experiences the whole family can enjoy. Follow @DisneyCareers on Facebook, Twitter and Instagram for a peek behind-the-curtain, and discover how you could connect to a world of stories with Disney!

London, England, United Kingdom (On-Site)

Glendale, California, United States (On-Site)

Kissimmee, Florida, United States (On-Site)

Bristol, Connecticut, United States (On-Site)

New York, New York, United States (On-Site)

Anaheim, California, United States (On-Site)

Glendale, California, United States (On-Site)

Celebration, Florida, United States (On-Site)

Winter Garden, Florida, United States (Remote)

Santa Monica, California, United States (On-Site)

View All Jobs

Get notified when new jobs are added by The Walt Disney Company

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug