Security Engineer
Job Summary
Job Posting Title:
Security EngineerReq ID:
Job Description:
Department Description:
At Disney were storytellers. We make the impossible possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walts passion was to continuously envision new ways to move audiences around the worlda passion that remains our touchstone in an enterprise that stretches from theme parks resorts and a cruise line to sports news movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences and were constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences enabling business growth and advancing operational excellence.
The Global Information Security (GIS)organization strives to secure the magic by employing best-in-class services to assess prevent detect and respond to cyber threats that present risk to The Walt Disney Company. We enable the business by integrating enterprise and business segment-specific supported services to create a robust efficient and adaptable cybersecurity program. Our key objectives are to:
- Secure the Magic by protecting information systems and platforms.
- Reduce Risk by proactively assessing preventing and detecting to prevent harm to the Company and our Guests.
- Strengthen the business through optimizing execution application and technology used to protect the Company.
- Innovate by investing in core capabilities to enhance operational efficiency.
Team Description:
- The Identity & Access Management (IAM) Directory Services team is responsible for building and operating a secure standardized and automated enterprise identity foundation across The Walt Disney Company. We provide the authoritative directory platforms that enable authentication authorization and access governance for both human and nonhuman identities.
- Our mission is to move identity governance from manual reactive processes to automated policydriven enforcement ensuring identities are secure compliant and healthy by default across their lifecycle. We partner closely with security infrastructure and application teams to eliminate legacy risk reduce operational toil and enable modern cloudfirst identity capabilities at enterprise scale.
What Youll Do:
Directory Platform Engineering & Operations
- Engineer harden and operateenterprise and multidomain Active Directory environmentssupporting critical business workloads.
- LeadActive Directory consolidation and domain rationalizationefforts including enterprise eCommerce and businessunit directories.
- Support RadiantLogics Virtual Directory System operations and enhancements.
- Establish and enforcemultidomain baseline identity security standardsacross environments.
- Implement and matureRBACbased access modelsacross Active Directory.
- Integrate AD withPrivileged Identity Management (PIM)andPrivileged Access Management (PAM)platforms.
- Help with eliminating standing privilege throughgroupbased timebound and JIT access patterns.
- Implement and support synchronization between Active Directory and Entra ID.
- Supportcrosstenant identity governancefor business segments and federated environments.
- Enableautomated human and nonhuman identity governance including monitoring remediation and compliance reporting.
- Reduce directory and tool sprawl while maintaining service reliability and business continuity.
- Mentor and uplift junior engineers; contribute to repeatable engineering patterns and documentation.
Required Qualifications & Skills:
- 8 yearsof handson experience engineering and operatinglargescale Active Directory environments.
- Deep expertise in:
- Active Directory architecture trusts replication DNS PKI
- Multidomain / multiforestdesigns
- AD security hardening and recovery
- Radiant Logics Virtual Directory Services
- Proven experience implementing or supporting:
- RBACPIM andPAM
- Privileged account separation and Tier 0 controls
- Strong troubleshooting skills in complex highly regulated environments.
- Experience working inenterprisescale IAM or directory services teams.
Preferred Qualifications:
- Experience integrating AD withEntra ID / Azure ADin hybrid or cloudfirst environments.
- Familiarity withidentity governance automation nonhuman identity management and continuous compliance.
- Experience supportingcrosstenant or multibusinessunit identity models.
- Background indirectory consolidation legacy system sunset or M&A identity integration.
- Comfort operating in environments withhigh security resilience and audit expectations.
Required Education:
- Bachelors degree in Computer Science Information Systems Software Electrical or Electronics Engineering or comparable field of study and/or equivalent work experience
Engineer harden and operate largescale multidomain Active Directory environments supporting critical business workloads.
Lead Active Directory consolidation and domain rationalization reducing directory sprawl across enterprise eCommerce and business units.
Operate and enhance Virtual Directory services (RadiantLogic) to support federated and multisource identity use cases.
Define implement and enforce baseline identity security standards across complex multidomain environments.
Design and mature RBACbased access models within Active Directory.
Integrate Active Directory with Privileged Identity and Access Management (PIM/PAM) platforms.
Eliminate standing privilege through groupbased timebound justintime (JIT) access patterns.
Implement and sustain Tier 0 security posture including privileged account separation and Privileged Access Workstations (PAW).
Design and operate bidirectional synchronization between Active Directory and Entra ID partnering with cloud identity teams for consistent governance.
Improve identity governance and lifecycle accuracy through authoritative attribute synchronization crosstenant governance automation documentation and mentoring of junior engineers.
Job Posting Segment:
Enterprise Technology and DataJob Posting Primary Business:
Global Information SecurityPrimary Job Posting Category:
Security EngineeringEmployment Type:
Full timePrimary City State Region Postal Code:
Bangalore IndiaAlternate City State Region Postal Code:
Date Posted:
Required Experience:
IC
About Company
The official website for all things Disney: theme parks, resorts, movies, tv programs, characters, games, videos, music, shopping, and more!