Product Security Engineer Specialist

Warner Bros Discovery Warner Bros Discovery · Media · Burbank, CA +1 · Technology

This role focuses on Product Security Engineering, ensuring the adoption and deployment of security controls within the product lifecycle. It involves collaborating with development teams, defining security processes, and engaging with the Application Security team. The role requires familiarity with common vulnerabilities, cloud security best practices, and security testing tools. While the role mentions familiarity with generative AI tools, its core function is product security, not AI development.

What you'd actually do

  1. Support the expansion of Product Security programs by contributing to security architecture engagement strategies, scalable product threat modeling, and the implementation of product security technical initiatives
  2. Assist in developing and delivering security roadmap plans, ensuring initiatives are completed successfully and on time with high quality.
  3. Help establish and enforce security standards, policies, and best practices for product development teams, ensuring compliance with industry regulations and customer expectations (PCI, GDPR, CCPA, etc.)
  4. Collaborate with product, engineering, and business stakeholders to identify and prioritize security risks and requirements, providing guidance and support on security architecture, design, testing, and remediation.
  5. Contribute to the development and implementation of security metrics and dashboards to measure and report on the security posture and performance of products and platforms.

Skills

Required

  • Experience in product security, application security, or cloud security
  • Understanding of consumer behavior and expectations regarding digital services
  • Proven track record of leading and managing security projects in a fast-paced, dynamic, and agile environment
  • Extensive experience in secure code reviews, business logic assessments and application security testing
  • Deep understanding of network, data, and cloud security principles
  • Expert knowledge of security principles, standards, and best practices, such as OWASP, NIST, ISO, etc.
  • Experience in deploying cyber security solutions in public cloud environments (IaaS, PaaS, SaaS)
  • Strong technical skills and hands-on experience with security tools and technologies, such as web application firewalls, vulnerability scanners, penetration testing tools, encryption, authentication, etc.
  • Excellent communication and presentation skills
  • Experience in implementing and leading DevSecOps initiatives, frameworks, and tools
  • Experience with Agile development/Scrum methodologies and incorporation of security requirements into SDLC (CI/CD)
  • Experience in securing cloud environments and services on AWS, GCP, and Azure, using automation and CI/CD pipelines.
  • Experiencing in managing programs supporting secure code and software deployments in various languages (Python, Node.js, C#, .NET, JavaScript, Go, Ruby, GraphQL, SDK, and RESTful API design/development).

Nice to have

  • Familiarity with generative AI tools (e.g., copilots, LLM-based assistants). Ability to write clear prompts and evaluate AI-generated results. Understanding AI limitations (hallucinations, bias, data sensitivity). Experience integrating AI APIs or models.
  • Experience in the media and entertainment industry, or with direct-to-consumer products and platforms
  • CISSP, CEH, GPEN, or OSCP certifications

What the JD emphasized

  • Must work a hybrid schedule (3 days onsite)
  • 5+ years of experience in information security, with at least 3 years of experience in product security, application security, or cloud security.