At a Glance
- Tasks: Join our team to secure Disney's digital assets and enhance product security.
- Company: Disney is a global leader in entertainment and technology, creating unforgettable experiences.
- Benefits: Enjoy competitive pay, bonuses, and comprehensive benefits including medical and financial perks.
- Why this job: Be part of a dynamic team that safeguards beloved Disney products and innovates in cybersecurity.
- Qualifications: 3+ years in cybersecurity, programming skills in Python, and strong collaboration abilities required.
- Other info: Remote work options may be available; join us in protecting the magic!
The predicted salary is between 78000 - 108000 £ per year.
Who We Are:
At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences — and we’re constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.
The Global Information Security (GIS) organization strives to secure the magic by employing best-in-class services to assess, prevent, detect, and respond to cyber threats that present risk to The Walt Disney Company. We enable the business by integrating enterprise and business segment-specific supported services to create a robust, efficient, and adaptable cybersecurity program. Our key objectives are to:
-
Secure the Magic by protecting information systems and platforms.
-
Reduce Risk by proactively assessing, preventing, and detecting to prevent harm to the Company and our Guests.
-
Strengthen the business through optimizing execution, application, and technology used to protect the Company.
-
Innovate by investing in core capabilities to enhance operational efficiency.
Team Description:
The Product Security Team at The Walt Disney Company is dedicated to safeguarding the digital assets and intellectual property of one of the world\’s most beloved entertainment companies. Our team plays a crucial role in ensuring the security and integrity of Disney\’s diverse range of products and services, which span across theme parks, resorts, cruise lines, sports, news, movies, and various other businesses.
We are a dynamic and collaborative team that partners with engineering teams across the enterprise. Our mission is to mitigate technical risk by identifying vulnerabilities in Disney products, providing education to engineering teams on remediation techniques, and collaborating with other security teams to ensure the protection of our guests.
Our team is responsible for conducting security assessments, managing customer interactions, and developing security solutions that align with Disney\’s business strategies. We leverage cutting-edge technology and innovative approaches to enhance consumer experiences, enable business growth, and advance operational excellence.
What You Will Do:
We Are Hiring! We need a Security Engineer – Product Security to join our Team!
Responsibilities of Role:
-
Manage and develop security partnerships with existing and new businesses of the TWDC to continually educate technology teams on reducing risk and integrating security into their product development.
-
Collaborate with engineers and information security teams to address security risks and provide mitigation recommendations within the Software Development Lifecycle (SDLC).
-
Support security assurance audits of our Product Security testing to help internal and external customers navigate and validate security compliance.
-
Perform activities such as security testing reviews with teams, product demos and trainings, and building documentation to help enable engineering teams to test their products and release with security embedded into their SDLC.
-
Regularly interact with internal and external customers on security-related projects and operational tasks. Design, build and deploy automation to scale the orchestration of security testing across all TWDC applications and platforms.
Must Have:
-
Minimum 3+ years of experience in cybersecurity, application security, or related information technology disciplines.
-
Programming/scripting skills with a language such as Python to automate work.
-
Proven experience collaborating with teams on security and building trust through delivery and data.
-
Strong understanding of at least two of the following security testing principles and practices, such as SAST, SCA, DAST, API, Mobile and Penetration testing.
-
Excellent communication and collaboration skills.
-
Ability to work in a fast paced, dynamic environment.
Nice To Have:
-
Experience with security tooling and methodologies
-
Experience integrating security checks into CI/CD pipelines or penetration testing.
-
Experience with SBOMs and the security of the software supply chain.
-
Familiarity with cloud security principles and technologies.
-
Relevant certifications such as: GWAPT, OSWE, BSCP, CompTIA Security+ are highly desirable.
Education:
Bachelor’s degree in Computer Science, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience.
#DISNEYTECH
The hiring range for this position in Burbank, California is $104,600 – $140,200 per year and in Seattle, Washington is $109,500 – $146,800 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered. #J-18808-Ljbffr
Security Engineer - Product Security employer: Disney Cruise Line - The Walt Disney Company
Contact Detail:
Disney Cruise Line - The Walt Disney Company Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Engineer - Product Security
✨Tip Number 1
Familiarise yourself with Disney's core values and mission. Understanding how the company integrates technology with storytelling can help you align your answers during interviews, showcasing your passion for both security and the entertainment industry.
✨Tip Number 2
Network with current employees or alumni who work at Disney, especially in the Global Information Security team. They can provide insights into the company culture and specific challenges faced by the Product Security Team, which can be invaluable during your application process.
✨Tip Number 3
Stay updated on the latest trends in cybersecurity, particularly those relevant to application security and the entertainment sector. Being able to discuss recent developments or case studies during your interview can demonstrate your expertise and enthusiasm for the role.
✨Tip Number 4
Prepare to discuss your experience with security testing principles like SAST, DAST, and API testing. Be ready to share specific examples of how you've implemented these practices in previous roles, as this will show your practical knowledge and problem-solving skills.
We think you need these skills to ace Security Engineer - Product Security
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Security Engineer - Product Security position. Tailor your application to highlight relevant experience in cybersecurity and application security.
Highlight Relevant Experience: In your CV and cover letter, emphasise your 3+ years of experience in cybersecurity, particularly any work related to security testing principles like SAST, DAST, or penetration testing. Use specific examples to demonstrate your skills.
Showcase Technical Skills: Mention your programming or scripting skills, especially in Python, as well as any experience with security tooling and methodologies. This will show that you have the technical expertise needed for the role.
Communicate Effectively: Since excellent communication and collaboration skills are essential for this role, ensure your application reflects your ability to work with teams. Use clear and concise language, and consider including examples of successful collaborations in your past roles.
How to prepare for a job interview at Disney Cruise Line - The Walt Disney Company
✨Understand the Company Culture
Before your interview, take some time to research The Walt Disney Company’s values and culture. Understanding their commitment to innovation and collaboration will help you align your answers with their mission and demonstrate that you're a good fit for the team.
✨Showcase Your Technical Skills
Be prepared to discuss your experience in cybersecurity and application security. Highlight specific projects where you've implemented security testing principles like SAST or DAST, and be ready to explain how you used programming languages like Python to automate processes.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think of examples where you've identified vulnerabilities or collaborated with engineering teams to mitigate risks, and be ready to walk the interviewer through your thought process.
✨Emphasise Communication and Collaboration
Since the role involves working closely with various teams, highlight your communication and collaboration skills. Share examples of how you've built trust with colleagues and successfully navigated security-related projects, showcasing your ability to work in a dynamic environment.