Security Engineer - Security Architecture and Engineering

Disney Disney · Media · Burbank, CA +4

Security Engineer focused on designing and evaluating secure architecture solutions for Disney's global technology ecosystem, with a specific emphasis on assessing and securing AI/ML implementations by identifying threats and recommending mitigations. The role also involves evaluating emerging cybersecurity technologies and conducting threat modeling.

What you'd actually do

  1. Design and drive secure architecture solutions that protect Disney’s global technology ecosystem, developing reference architectures and patterns that scale across applications, cloud platforms, and enterprise services.
  2. Lead and influence secure design decisions by partnering with engineers, architects, and business stakeholders to embed security early in the solution lifecycle using secure-by-design and secure-by-default principles.
  3. Evaluate emerging cybersecurity technologies through Disney’s Security Solution Review Process, conducting deep technical assessments and shaping enterprise adoption strategies for next-generation capabilities.
  4. Assess and secure AI/ML implementations across the enterprise, performing risk-based evaluations to identify threats such as model manipulation, data leakage, and adversarial attacks, and recommending practical mitigation strategies.
  5. Conduct advanced threat modeling and architecture risk assessments, leveraging internal incident data and external threat intelligence to proactively identify gaps and strengthen enterprise defenses.

Skills

Required

  • 3+ years of experience in Security Architecture & Engineering
  • design and evaluate secure solutions in complex enterprise environments
  • 3+ years of experience securing workloads and services in public cloud environments (e.g., AWS, Azure, Google Cloud Platform)
  • implementing native cloud security controls, identity and access management, and secure configuration of cloud services
  • Experience securing modern cloud-native architectures, including containers, serverless technologies, and infrastructure-as-code

Nice to have

  • AI/ML implementations
  • model manipulation
  • data leakage
  • adversarial attacks
  • threat modeling
  • architecture risk assessments
  • Zero Trust Architecture
  • cloud-native security
  • distributed system protection
  • enterprise security configuration standards
  • NIST
  • CIS
  • ISO 27001

What the JD emphasized

  • on-site at least 4 days per week

Other signals

  • Assess and secure AI/ML implementations
  • risk-based evaluations to identify threats such as model manipulation, data leakage, and adversarial attacks
  • recommending practical mitigation strategies
  • Evaluate emerging cybersecurity technologies