The Walt Disney Company Logo

The Walt Disney Company

Staff Content Security Engineer

Job Posted 7 Days Ago Posted 7 Days Ago
Be an Early Applicant
Hybrid
Glendale, CA
139K-186K Annually
Senior level
Hybrid
Glendale, CA
139K-186K Annually
Senior level
The Staff Content Security Engineer will lead comprehensive Site Security assessments, analyze vendor compliance, and validate security protocols for The Walt Disney Studios. Responsibilities include creating secure configurations, drafting compliance questionnaires, and performing risk analysis. The role involves collaboration with third-party vendors, addressing security matters, and optimizing assessment workflows through proof-of-concepts.
The summary above was generated by AI

The Content Security Staff Engineer reports into the Sr Manager of the Content Site Security program at The Walt Disney Studios based in Glendale, CA. The modern filmmaking process is highly complex with dependencies on an entire eco-system of 3rd party strategic partners, suppliers and vendors. This program provides assessment, consulting and advisory services to ensure the entire supply chain remains robust and resilient and allows The Walt Disney Studios' to securely create films, features and series seen across the world.
Responsibilities:

  • Run end-to-end Site Security assessments, specifically:
    • Contacting vendors to schedule and scope assessments
    • Understand the filmmaking process and various vendor workflows
    • Executing the assessment
    • Assess vendor against a set of over 300+ security controls
    • Identify intentional or unintentional misrepresentation of security compliance
    • Perform detailed inspection and analytics on various IT infrastructure configuration ranging from network, storage, endpoint devices, and cloud-based assets
    • Perform real-time validation against attestation and documentation provided by the vendor
    • Identifying risk areas and corresponding test procedure associated with each service type, content workflow, and underlying infrastructure
    • Analyze assessment findings and document risks accordingly
    • Documenting assessment result, accurately and precisely communicating requirements, and publishing the completed report
    • Reviewing and negotiating vendor proposed mitigation plans and timelines
    • Validating remediation implementation to ensure identified risks have been adequately addressed
  • Contribute to Content Security's control framework which includes:
    • Writing controls that secure both physical and digital assets.
    • Drafting questions for Content Security's questionnaire that help evaluate a vendor's compliance to each control.
    • Creating applicability matrix for each new control.
    • Writing test guidance to effectively identify non-compliant implementations.
  • Contribute to secure configuration guides used to assess and lockdown a variety of technologies used by vendors including virtual sets and virtual headsets
  • Run proof-of-concepts to help optimize the assessment workflow, this includes testing new processes and tools designed to drive efficiency with our assessment methodology
  • Travel to offsite locations to address content security matters
  • Follow the progress of productions and deal with last minute requests such as the assessment of ADR locations used for last minute production needs


Basic Qualifications:

  • Bachelor's degree and/or equivalent work experience
  • 7 years of experience in information security and/or the following areas: security architecture, security engineering, production or network storage engineering, mobile device remote deployment and management, cybersecurity incident investigations, experience with cloud technologies
  • Ability to travel up to 25% domestically and/or internationally, as needed
  • Advanced knowledge of cloud security and infrastructure environments for popular cloud providers (AWS, Azure, GCP)
  • Prior experience in an architecture, development, engineering, or senior technical role
  • Experience providing product ownership for solutions supporting the Media & Entertainment industry
  • Ability to work in a highly distributed matrixed environment
  • Ability to adapt to new technologies and trends
  • Strong communication (written and verbal, including presentation) and listening skills
  • Strong documentation skills
  • Experience in technical project management/leading large scale technology initiatives
  • Strong analytical, organizational and decision-making skills
  • Strong negotiation skills
  • Broad technology expertise with application, system integration, data, and/or infrastructure knowledge
    • Storage solutions (e.g., SAN, NAS, encrypted storage devices, cloud cache and storage buckets)
    • Digital file transfer tools (e.g., Aspera, Signiant)
    • Centralized secure configuration of Linux, Windows, and Mac based servers and endpoints
    • Directory Services (e.g., Active Directory, Open Directory, LDAP)
    • Device management (e.g., Microsoft InTune, Jamf, Puppet, Ansible)
    • Change and patch management solutions (e.g., SCCM, Munki, PDQ Deploy)
    • OS hardening best practices for both servers and workstations
    • Endpoint protection and Data Loss Prevention solutions
  • Strong understanding of secure network principles of perimeter devices, servers, and workstations
    • Working knowledge of configuring and maintaining firewalls and network switching / routing devices (e.g., Palo Alto, Sonicwall, Fortinet, Brocade, Cisco, HP)
    • LAN, WAN, TCP/IP connectivity and security protocols (Point-to-Point, MPLS, VPN)
    • Network architecture and layer 2 and Layer 3 routing principles
    • Network authentication standards
  • Strong understanding of Infrastructure as a Service (IaaS) and Infrastructure as Code (IaC)
  • Expert knowledge in cloud security auditing tools
  • Working knowledge of configuring and maintaining cloud compute and storage nodes
  • Provisioning and deprovisioning cloud tenants
  • Working knowledge of Virtual Private Cloud (VPC) network access control lists
  • Working knowledge of Web Application Firewalls (WAFs)
  • Vulnerability scanning, SIEM and common methods of exploiting vulnerabilities
  • Computer investigation processes and techniques


Preferred Qualifications:

  • Degree in the following fields: Computer Science, Information Systems, IT Engineering, or a related field.
  • CISSP, CISA/CISM, or CEH designations
  • Knowledge of studio IT systems, including production and post-productions environments
  • Knowledge of feature film production and post-production industries, services, and workflows (e.g., DI, editing, visual/audio effects, encoding, on-set support)
  • Knowledge of Zero Trust Network Access (ZTNA)


The hiring range for this position in Glendale, CA is $138,900 to $186,200 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

Top Skills

Ansible
Aspera
AWS
Azure
Brocade
Cisco
Fortinet
GCP
Hp
JAMF
Linux
macOS
Microsoft Intune
Munki
Palo Alto
Pdq Deploy
Puppet
Sccm
Signiant
Sonicwall
Windows

The Walt Disney Company San Francisco, California, USA Office

The Bay Area is center stage for Disney Pixar, Lucasfilm Ltd. and more. Our technologists are in the heart of Silicon Valley and spearheading our movies, shows and more that are out of this world.

Similar Jobs at The Walt Disney Company

5 Days Ago
Hybrid
Glendale, CA, USA
139K-186K Annually
Senior level
139K-186K Annually
Senior level
AdTech • Digital Media • News + Entertainment
The Staff Content Security Engineer at The Walt Disney Studios will be responsible for leading AI security initiatives, assessing risks in AI-enabled applications, and collaborating with cross-functional teams to integrate security practices. The role involves mentoring junior team members and managing time effectively between application/cloud security and AI security tasks.
7 Hours Ago
Hybrid
Oakland, CA, USA
177K-230K Annually
Senior level
177K-230K Annually
Senior level
AdTech • Digital Media • News + Entertainment
The Senior Network Engineer will architect, implement, and maintain network infrastructure, ensuring stability and enhancing creative workflows while mentoring junior team members.
Top Skills: AristaArubaIpv6JuniperPalo Alto NetworksVMware
4 Days Ago
Hybrid
Burbank, CA, USA
126K-170K Annually
Senior level
126K-170K Annually
Senior level
AdTech • Digital Media • News + Entertainment
The Senior Security Engineer, Red Team Operations executes simulated cyberattacks, identifies vulnerabilities, provides expertise to junior members, and enhances security posture.
Top Skills: BashBurpC#C/C++Cobalt StrikeJavaMetasploitMimikatzNessusPerlPHPPowershellPythonRuby

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account