Staff Content Security Engineer

2 Months ago • 7 Years + • Cyber Security • $138,900 PA - $186,200 PA

Job Summary

Job Description

The Staff Content Security Engineer at The Walt Disney Studios is responsible for conducting end-to-end site security assessments of vendors involved in the filmmaking process. This includes contacting vendors, understanding workflows, executing assessments against 300+ security controls, identifying misrepresentations, inspecting IT infrastructure, validating compliance, documenting findings, and communicating requirements. The role also involves contributing to the Content Security control framework by writing controls, drafting questionnaires, creating applicability matrices, and writing test guidance. Additional responsibilities include running proof-of-concepts, traveling to offsite locations, and addressing last-minute requests. The ideal candidate will possess advanced knowledge of cloud security, experience in media & entertainment, strong communication and analytical skills, and a broad technology expertise encompassing various systems and security tools.
Must have:
  • 7+ years in InfoSec/related fields
  • Cloud security expertise (AWS, Azure, GCP)
  • Media & Entertainment experience
  • Security assessments & vulnerability analysis
  • Strong communication & documentation skills
  • Travel up to 25%
Good to have:
  • CISSP, CISA/CISM, CEH
  • Studio IT systems knowledge
  • Zero Trust Network Access (ZTNA) knowledge
Perks:
  • Bonus
  • Long-term incentive units
  • Full range of medical, financial, and other benefits

Job Details

Job Summary:

The Content Security Staff Engineer reports into the Sr Manager of the Content Site Security program at The Walt Disney Studios based in Glendale, CA. The modern filmmaking process is highly complex with dependencies on an entire eco-system of 3rd party strategic partners, suppliers and vendors. This program provides assessment, consulting and advisory services to ensure the entire supply chain remains robust and resilient and allows The Walt Disney Studios' to securely create films, features and series seen across the world.

Responsibilities:

  • Run end-to-end Site Security assessments, specifically:
    • Contacting vendors to schedule and scope assessments
    • Understand the filmmaking process and various vendor workflows
    • Executing the assessment
    • Assess vendor against a set of over 300+ security controls
    • Identify intentional or unintentional misrepresentation of security compliance
    • Perform detailed inspection and analytics on various IT infrastructure configuration ranging from network, storage, endpoint devices, and cloud-based assets
    • Perform real-time validation against attestation and documentation provided by the vendor
    • Identifying risk areas and corresponding test procedure associated with each service type, content workflow, and underlying infrastructure
    • Analyze assessment findings and document risks accordingly
    • Documenting assessment result, accurately and precisely communicating requirements, and publishing the completed report
    • Reviewing and negotiating vendor proposed mitigation plans and timelines
    • Validating remediation implementation to ensure identified risks have been adequately addressed
  • Contribute to Content Security’s control framework which includes:
    • Writing controls that secure both physical and digital assets.
    • Drafting questions for Content Security’s questionnaire that help evaluate a vendor’s compliance to each control.
    • Creating applicability matrix for each new control.
    • Writing test guidance to effectively identify non-compliant implementations.
  • Contribute to secure configuration guides used to assess and lockdown a variety of technologies used by vendors including virtual sets and virtual headsets
  • Run proof-of-concepts to help optimize the assessment workflow, this includes testing new processes and tools designed to drive efficiency with our assessment methodology  
  • Travel to offsite locations to address content security matters 
  • Follow the progress of productions and deal with last minute requests such as the assessment of ADR locations used for last minute production needs

Basic Qualifications:

  • Bachelor’s degree and/or equivalent work experience
  • 7 years of experience in information security and/or the following areas: security architecture, security engineering, production or network storage engineering, mobile device remote deployment and management, cybersecurity incident investigations, experience with cloud technologies
  • Ability to travel up to 25% domestically and/or internationally, as needed
  • Advanced knowledge of cloud security and infrastructure environments for popular cloud providers (AWS, Azure, GCP)
  • Prior experience in an architecture, development, engineering, or senior technical role
  • Experience providing product ownership for solutions supporting the Media & Entertainment industry
  • Ability to work in a highly distributed matrixed environment
  • Ability to adapt to new technologies and trends
  • Strong communication (written and verbal, including presentation) and listening skills
  • Strong documentation skills
  • Experience in technical project management/leading large scale technology initiatives
  • Strong analytical, organizational and decision-making skills
  • Strong negotiation skills
  • Broad technology expertise with application, system integration, data, and/or infrastructure knowledge
    • Storage solutions (e.g., SAN, NAS, encrypted storage devices, cloud cache and storage buckets)
    • Digital file transfer tools (e.g., Aspera, Signiant)
    • Centralized secure configuration of Linux, Windows, and Mac based servers and endpoints
    • Directory Services (e.g., Active Directory, Open Directory, LDAP)
    • Device management (e.g., Microsoft InTune, Jamf, Puppet, Ansible)
    • Change and patch management solutions (e.g., SCCM, Munki, PDQ Deploy)
    • OS hardening best practices for both servers and workstations
    • Endpoint protection and Data Loss Prevention solutions
  • Strong understanding of secure network principles of perimeter devices, servers, and workstations
    • Working knowledge of configuring and maintaining firewalls and network switching / routing devices (e.g., Palo Alto, Sonicwall, Fortinet, Brocade, Cisco, HP)
    • LAN, WAN, TCP/IP connectivity and security protocols (Point-to-Point, MPLS, VPN)
    • Network architecture and layer 2 and Layer 3 routing principles
    • Network authentication standards 
  • Strong understanding of Infrastructure as a Service (IaaS) and Infrastructure as Code (IaC)
  • Expert knowledge in cloud security auditing tools
  • Working knowledge of configuring and maintaining cloud compute and storage nodes
  • Provisioning and deprovisioning cloud tenants
  • Working knowledge of Virtual Private Cloud (VPC) network access control lists
  • Working knowledge of Web Application Firewalls (WAFs)
  • Vulnerability scanning, SIEM and common methods of exploiting vulnerabilities
  • Computer investigation processes and techniques

Preferred Qualifications:

  • Degree in the following fields:  Computer Science, Information Systems, IT Engineering, or a related field.
  • CISSP, CISA/CISM, or CEH designations
  • Knowledge of studio IT systems, including production and post-productions environments
  • Knowledge of feature film production and post-production industries, services, and workflows (e.g., DI, editing, visual/audio effects, encoding, on-set support)
  • Knowledge of Zero Trust Network Access (ZTNA)


 


The hiring range for this position in Glendale, CA is $138,900 to $186,200 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

Similar Jobs

Thales - IVVQ Engineer

Thales

Singapore (On-Site)
1 Month ago
Ion - Senior DevSecOps Engineer, Italy

Ion

Collecchio, Emilia-Romagna, Italy (On-Site)
8 Months ago
Nium - Senior DevOps Engineer

Nium

Malta (Hybrid)
11 Months ago
NewGlobe - Senior DevOps Engineer

NewGlobe

Lisbon, Lisbon, Portugal (Hybrid)
1 Month ago
Thousand Eyes - Senior Site Reliability Engineer, Infrastructure

Thousand Eyes

San Francisco, California, United States (On-Site)
1 Month ago
PwC - Financial Sector Information Protection Consultant

PwC

Amsterdam, North Holland, Netherlands (Hybrid)
5 Months ago
Tencent - Security Software Engineer I

Tencent

California, United States (On-Site)
4 Months ago
PwC - Cyber Security Strategy Manager

PwC

Amsterdam, North Holland, Netherlands (Hybrid)
5 Months ago
bytedance - Site Reliability Engineer, SealSuite

bytedance

Singapore (On-Site)
2 Months ago
Larian Studios - Lead Security & Network Engineer

Larian Studios

Guildford, England, United Kingdom (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

zeta - Sr. Site Reliability Engineer

zeta

Bengaluru, Karnataka, India (On-Site)
8 Months ago
Coda - Infra-Ops Engineer

Coda

Jakarta, Indonesia (Hybrid)
7 Months ago
Thales - IVVQ Engineer

Thales

Singapore (On-Site)
1 Month ago
Synechron - Murex Support Lead

Synechron

Pune, Maharashtra, India (On-Site)
1 Month ago
Zurora - Site Reliability Engineer

Zurora

Costa Rica (Hybrid)
1 Month ago
AccelData - DevOps Engineer

AccelData

Bengaluru, Karnataka, India (On-Site)
1 Year ago
Motorola solutions - Redhat Openshift Virtualization Administrator

Motorola solutions

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Hitachi - Azure Developer

Hitachi

Hyderabad, Telangana, India (Remote)
8 Months ago
WebMD - Site Reliability Engineer

WebMD

Boise, Idaho, United States (On-Site)
1 Month ago
Ziff Davis - Senior Systems Administrator

Ziff Davis

Guadalajara, Jalisco, Mexico (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Glendale, California, United States

Apple - US Manager

Apple

Austin, Texas, United States (On-Site)
1 Month ago
DailyWire - Camera Assistant

DailyWire

Nashville, Tennessee, United States (On-Site)
1 Month ago
Dynamis Inc - Junior Military Analyst

Dynamis Inc

Alexandria, Virginia, United States (On-Site)
1 Month ago
Notion - Design Engineer

Notion

New York, United States (On-Site)
1 Month ago
Axon - Senior Manager, Billing Compliance

Axon

Denver, Colorado, United States (Hybrid)
1 Month ago
DraftKings - HR Systems Analyst (Time & Attendance)

DraftKings

United States (Remote)
3 Weeks ago
bytedance - Machine Learning Scientist Graduate (Scaling AI for Biology (AI-for-Science))

bytedance

Seattle, Washington, United States (On-Site)
2 Months ago
Jane Street - Food Service Equipment Specialist

Jane Street

New York, United States (On-Site)
1 Month ago
Divensi - LiDAR Analyst/GIS

Divensi

Bellevue, Washington, United States (On-Site)
8 Years ago
Apple - Physical Design Engineer

Apple

Cupertino, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - Salesforce Technical Lead (Manager)

PwC

Makati, Metro Manila, Philippines (Hybrid)
9 Months ago
Rockstar Games - Director of Security Operations

Rockstar Games

New York, New York, United States (On-Site)
3 Months ago
PwC - ETIC, Cybersecurity Cloud Security - Manager

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
9 Months ago
PwC - Senior Consultant en Cybersécurité GRC | CDI | H/F

PwC

Neuilly-sur-Seine, Île-de-France, France (On-Site)
9 Months ago
PwC - Information Protection Senior Manager

PwC

Amsterdam, North Holland, Netherlands (Hybrid)
7 Months ago
PwC - Workday - Senior Consultant-  Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
9 Months ago
Ion - Senior Security Architect

Ion

Italy (On-Site)
8 Months ago
Ion - Cyber Product Owner, Italy

Ion

Italy (Hybrid)
8 Months ago
NVIDIA - Senior Networking Security Research Architect

NVIDIA

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
5 Months ago
Saviynt - Senior Principal Software Engineer - Privileged Access Management (PAM)

Saviynt

El Segundo, California, United States (Hybrid)
8 Months ago

Get notifed when new similar jobs are uploaded

About The Company

From classic animated features and exhilarating theme park attractions to cutting edge sports coverage, and the hottest shows on television, The Walt Disney Company has been making magic since 1923, creating unforgettable stories that connect with audiences around the world. And we’re just getting started!

The key to our success…. The Cast, Crew, Imagineers and Employees who honor Disney’s rich legacy by stretching the bounds of imagination to create the never-before-seen, bringing unparalleled entertainment experiences to people of all ages. Begin a career that delivers unparalleled creative content and experiences to audiences around the world and just imagine the stories you could be part of…

What is #LifeAtDisney like? It’s a series of magical moments with cast members and employees developing and telling our stories in the most innovative ways. Whether it’s a day spent as a Disney VoluntEAR, or celebrating the release of a new interactive experience, retail product or movie, our days are filled with the knowledge that we are creating entertainment experiences the whole family can enjoy. Follow @DisneyCareers on Facebook, Twitter and Instagram for a peek behind-the-curtain, and discover how you could connect to a world of stories with Disney!

Mumbai, Maharashtra, India (On-Site)

London, England, United Kingdom (Hybrid)

San Francisco, California, United States (On-Site)

Île-de-France, France (On-Site)

Glendale, California, United States (On-Site)

Glendale, California, United States (On-Site)

Anaheim, California, United States (On-Site)

Glendale, California, United States (Remote)

Glendale, California, United States (Remote)

Burbank, California, United States (On-Site)

View All Jobs

Get notified when new jobs are added by The Walt Disney Company

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug