At Disney, we're storytellers making the impossible possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader, with a mission to continuously envision new ways to move audiences worldwide. The Enterprise Technology team delivers technology solutions that align with business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation.
As a Senior Security Engineer within the Security Research and Testing (SRT) team, you'll be responsible for conducting advanced cybersecurity testing across Disney Experiences (DX) systems, including cruise ships, theme park attractions, resorts, and commerce platforms. You'll apply your expertise to identify, assess, and report vulnerabilities across a broad spectrum of technologies and environments.
The role requires strong adversarial testing capabilities and situational awareness, working collaboratively on complex testing engagements that support critical guest and operational systems. You'll be performing penetration testing, developing and executing advanced cybersecurity testing strategies, and safeguarding DX's digital ecosystems against malicious threats.
Key responsibilities include conducting hands-on testing to identify exploitable weaknesses, guiding application and system owners in implementing security controls, and effectively communicating findings to stakeholders. You'll work closely with developers, system administrators, and other security teams to remediate vulnerabilities and strengthen the overall security posture.
The ideal candidate will have at least 5 years of experience in Red Team Testing or similar fields, strong understanding of security and network concepts, and the ability to identify risks and develop appropriate mitigation plans. Experience with cloud security concepts (Azure, GCP, AWS) and AI security testing is a plus.
Join our team at Disney's Enterprise Technology organization, where you'll be part of securing the magic by protecting information systems and platforms, reducing risk through proactive assessment and detection, and innovating core security capabilities to enhance operational efficiency.