Business Security Partner (l5), M&a

Netflix Netflix · Big Tech · United States · Remote · Engineering Operations

This role is for a Business Security Partner focused on Merger & Acquisitions (M&A) technical due diligence at Netflix. The individual will be responsible for assessing the security posture of target acquisition companies, identifying risks, and developing security strategies for integration. The role requires strong security domain knowledge, relationship building, and communication skills, with a focus on enabling business agility while managing risks.

What you'd actually do

  1. Lead security and privacy due diligence process for target acquisitions, including technical architecture reviews, penetration tests, vulnerability assessments, security and privacy evaluations, risk identification and risk prioritization.
  2. Develop the security strategy for each incoming M&A; documenting key details about the target acquisition, technology stack, current security and privacy posture, third-party due diligence results, etc. ahead of deal close to ensure that all members across SPA teams and relevant stakeholders are up-to-speed and understand the acquisition’s security posture.
  3. Conduct threat intelligence for potential incoming target acquisition companies.
  4. Evaluate risks within the acquisition, advise the business on prioritization, and recommend treatment strategies.
  5. Manage long term security and privacy risk management for the subsidiary after active onboarding completes, where applicable; ensuring that critical and high risk security risks are prioritized and mitigated/resolved.

Skills

Required

  • Experience conducting threat intelligence and/or security and privacy due diligence for M&A’s.
  • Breadth across multiple security domains.
  • Strong understanding of information security, risk and data privacy, especially as it applies to Mergers & Acquisitions.
  • Strong technical / development background, as well as the ability to talk through technical implementation.
  • Excellent written and verbal communication skills, with the ability to translate highly complex technical security concepts into business impact for a non-technical audience.
  • Detailed understanding of the legal concepts surrounding M&As.

Nice to have

  • Self-motivated and can proactively seek input.
  • Self-motivated and can deal well with ambiguity, and are selfless when it comes to getting work done and leaning on experts.
  • Experience creating a team that models psychological safety and inclusivity.

What the JD emphasized

  • security posture
  • security and privacy due diligence
  • risk management
  • security strategy