
Security Engineer
- Seattle, WA
- $109,500-146,800 per year
- Permanent
- Full-time
- Secure the Magic by protecting information systems and platforms.
- Reduce Risk by proactively assessing, preventing, and detecting to prevent harm to the Company and our Guests.
- Strengthen the business through optimizing execution, application, and technology used to protect the Company.
- Innovate by investing in core capabilities to enhance operational efficiency.
- Design and architect security solutions for the business.
- Build and setup security solutions to specifications.
- Process and prioritize security assessment reports
- Evaluate designs and request and how well they conform to security controls
- Design and maintain security controls for applications and infrastructure
- Implement WAF configurations, network segregation, and device security
- Understand and audit device security configurations and standards.
- Enhance security monitoring and detection systems
- Conduct security training and awareness programs
- Identifying current and emerging technology issues including security trends, vulnerabilities and threats
- Conduct security investigations
- Sourcing and implementing new security solutions to better protect the organization
- Conducting proactive research to analyze security weaknesses and recommend appropriate strategies
- Drive optimization of security tool deployments and introduce scalable processes across Cyber Security capabilities.
- Drive collaboration with other Information Security team members across the broad spectrum of information security programs
- Designs, develops, and implements platforms needed to host Applications.
- Proficiency in scripting languages like Python, Bash, and Powershell.
- Experience with Opensearch, PostgreSQL, and other data storage platforms.
- Minimum 3+ years of hands-on experience in security engineering or SRE with security focus, proficiency in at least two of the following domains: Implementing and automating security controls, Contributing to issue response and remediation, building or maintaining observability or security solutions.
- Minimum 1+ years of practical experience working with cloud platforms and services in public cloud environments (e.g., AWS, Azure, Google Cloud Platform), including implementation of native cloud security controls, managing IAM roles and permissions.
- Minimum 1+ years of practical experience managing a cyber security tool such as endpoint detection, vulnerability scanning, firewalls, SIEM or pentesting experience
- Familiarity with cloud computing, Linux administration, and TCP/IP protocols
- Experience with NIST and CIS security benchmarks
- Experience working in a dedicated security team building or managing security tools and processes.
- Ability to build and maintain security tools and services.
- Sharp analytical skills to troubleshoot complex platform issues and understand service inter-dependencies ·
- Proven ability to work effectively across technical, security and on-technical teams ·
- Consistent drive to enhance processes, automation and reliability ·
- Able to manage multiple priorities effectively
- Experience with project management and collaboration tools (e.g., Jira, Confluence, Miro, SharePoint, etc.)
- AWS/GCP/Azure Certified DevOps Engineer, CISSP, NET+, Security+
- Bachelor's degree in Computer Science, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience