Sr Content Security Engineer

Disney Disney · Media · Glendale, CA +1

This role focuses on application and infrastructure security within the media and entertainment industry, specifically protecting film and episodic content from leaks. It involves leading security reviews, conducting assessments, investigating incidents, integrating secure-by-design principles, and developing automation for security checks. The role requires strong cybersecurity experience, cloud security knowledge, and the ability to present security risks to various stakeholders. While AI is mentioned in the context of content usage reviews, the core function of the role is not AI/ML development or research.

What you'd actually do

  1. Lead application and infrastructure security reviews for content management, editorial, and production platforms.
  2. Conduct security assessments and provide actionable recommendations for internal tools and third-party vendor solutions.
  3. Serve as a technical partner for production technologists, platform owners, and engineering teams.
  4. Investigate incidents and findings with appropriate follow-up documentation and recommendations.
  5. Integrate secure-by-design principles into new workflows, including remote collaboration and cloud-based editing.

Skills

Required

  • cybersecurity
  • application security
  • cloud security
  • infrastructure security
  • security assessments
  • AWS
  • GCP
  • Azure
  • IAM
  • networking
  • compute
  • CI/CD pipelines
  • APIs
  • containerized environments
  • Media & Entertainment security use cases
  • problem-solving
  • communication
  • documentation

Nice to have

  • Security+
  • AWS SAA
  • GCP ACE
  • pentest
  • redteam
  • tiger team
  • blue team
  • product security
  • security software engineer

What the JD emphasized

  • Must have at least 5 years of experience in cybersecurity roles, with emphasis on application, cloud, or infrastructure security.
  • Must have proven ability to conduct security assessments and deliver clear, actionable guidelines & results to technical and non-technical teams.
  • Must have strong understanding of cloud security services across AWS, GCP, or Azure, including IAM, networking, and compute.
  • Product security
  • Security engineering
  • Pentest
  • Redteam/ Tiger Team/Blue team
  • Cloud security engineering
  • Security software engineer