Warner Bros. Discovery
Hybrid

VP - Digital Platform Business Info Sec

Sorry, this job was removed at 8:59 a.m. (PST) on Monday, December 2, 2019
Find out who's hiring in Bellevue.
See all Cybersecurity + IT jobs in Bellevue
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Position Summary

The VP, Digital Platform Business Information Security oversees all information security efforts for Discovery’s digital platforms, revenue-generating business systems and applications across the globe.

 

VP is specialized in – and is accountable for – information security issues relevant to Direct-to-Consumer (DTC), customer-facing technologies, Information Security incident management, appropriate protection of user and customer information (e.g. GDPR, CCPA, PCI, SOX), and consumer privacy. VP will drive translation and successful execution of cyber security requirements, and lead resolution of Digital Platform and business-related systems security issues in fast-paced global environments.

 

VP will be heavily involved in evaluating application security technologies and workflows across platforms, including DTC platforms, Discovery’s portfolio of TV Everywhere apps and products, Discovery GO, Motor Trend, PGA streaming services, and the Eurosport Player – Eurosport being the leading provider of locally relevant, premium sports and Home of the Olympic Games across Europe. In addition, VP will have management responsibility for Cloud Security and Data Security SMEs in support of the Digital Platform technology environment.

 

VP will report directly to the SVP & CISO, with a dotted line to the SVP, Global Platform, and will work collaboratively and effectively with Global Information Security team, Broadcast and TVN Business Information Security Offices and infrastructure teams to design and deploy appropriate, risk-based safeguards and technical direction.

Responsibilities

1. Manage Global Application Security / DevSecOps team, in addition to supporting the U.S. and International Digital organizations.
2. Evaluate, manage and support application security technologies, processes and workflows on multiple platforms (e.g., Server/Client, Mobile, Tablet, etc.)
3. Conduct application security risk assessments, analysis, and monitoring 
4. 24x7 on-call availability for Information Security Incident Response issues across the globe as it pertains to DTC Business Systems
5. Ability to manage cyber security risks and threats tied to Discovery’s reputation, exposure and regulatory, technology and data compliance 
6. Develop and execute security assessment test plans, document and present results
7. Review developers’ codes, provide feedback and perform security and risk assessment for consumer-facing applications, services, and future technology 
8. Perform design analysis, review, piloting, and selection of security technologies that meet specified application/business requirements, as needed
9. Identify and define application security requirements and security baselines for the various classes of assets and environments in use at Discovery or its partners
10. Work collaboratively and proactively across the organization (e.g., Technical Architects/Leads, Product managers, Digital Media Program Teams, etc.) to support and remediate security gaps
11. Review Technical Architecture and Delivery for Web and other Client Delivery Platforms
12. Understand and recommend security controls for the rapid development of consumer-facing prototypes to identify technical options and inform architectural approaches
13. Identify and recommend best-of-breed security stack and controls for interactive consumer experiences across web and mobile devices. (i.e., project, customer, and vendor management skills)
14. Engage assigned business lines as the central point-of-contact for information security controls. 
15. Ability to make considered effective decisions, come to sensible conclusions, understand situations, and form objective opinions especially in matters that affect action.
16. Work closely with Global Information Security teams, legal counsel (Privacy/Compliance), IT, Broadcast, Digital teams and Forensics to discuss/communicate incident response findings/analysis/remediation actions and related strategies that best protect the organization and reassure stakeholders.
17. Manage relationships effectively, advocating for business and external customers by engaging in security-related requirements conversations, seeking understanding of control requirements for presenting to IT security solution architects
18. Advocate for the company’s security initiatives and controls deployment. Stays knowledgeable about the company’s technical controls and advocates for the technical security control needed by assigned business.
19. Promote and evangelize the company’s IT and Information Security Policies and Standards. Advise stakeholders on security deviation control alternatives, such as compensating controls, and leads stakeholders through the policy deviation process.

Requirements

* Must be willing and able to travel up to 25% of the time
* 10+ years’ experience in managing Information Security global teams 
* 10+ years’ experience in of cybersecurity architecture/engineering, cloud security, and/or application security (Appsec, Netsec), with a bachelor’s degree or higher in related field 
* Must have high judgment and executive communication (verbal/written) skills
* Strong experience in handling cyber/operational security incidents tied to various attack vectors and stakeholders
* Broad knowledge of IT Security technologies, process, and techniques and a strong understanding of application security leading practices including OWASP and CWE.
* Extensive experience in secure code reviews, business logic assessment, and application security testing 
* Experience deploying cybersecurity solutions in a public cloud environment (IaaS, PaaS, SaaS)
* Familiar with application security tools like BurpSuite Pro, SAST, DAST, Nmap, Metasploit, and Kali Linux, etc. (Experience in 3rd-party testing tools such as Veracode, WhiteHat, etc., is also preferred)
* Experience managing secure coding and software deployment in a variety of current languages (e.g. Python, Node.js, C#, .NET, JavaScript, Go, Ruby, PowerShell, Bash, Scala, SDK and RESTful API design/development). 
* Experience working with Agile development/Scrum methodologies, and incorporation of security requirements into SDLC (CI/CD) with product owners/managers 
* Familiarity with HTML/CSS, JavaScript and UI/UX design and software quality assurance principles
* Excellent knowledge of software and application design and architecture 
* Strong Knowledge of TCP/IP, DNS, HTTP, HTTPS, VPN, SQL and other database technologies
* Experience with Unix/Linux and Windows operating systems in an Active Directory environment
* Experience with endpoint security and SIEM technologies, e.g., Carbon Black, QRadar 
* Experience working in large global environments
* Excellent communication and presentation abilities with great attention to detail
* CISSP, CEH, GWEB, CWAPT, CASS, SCADA, CCSP, CSSLP, CISSP-ISSAP or OSCP certifications are highly desired

* Must have the legal right to work in the United States

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are Warner Bros. Discovery Perks + Benefits

Warner Bros. Discovery Benefits Overview

Warner Bros Discovery offers a comprehensive set of benefits and perks to support employees in their personal and professional lives. Some program highlights include:

• Local medical, dental, and vision programs in many countries around the world.
• On-site wellness and fitness centers across several of our office locations.
• Family support programs. In the U.S., additional services include on-site childcare in certain offices, backup childcare services, family caregiver leave, adoption, surrogacy, and cryopreservation assistance, and more.
• Tools and resources to support the mental wellbeing of our employees and their dependents, including mental health counselors and 24/7 access to free, confidential support through our Employee Assistance Program administrators.
• Products and services to support financial wellbeing including financial planning tools, and a 401(k) savings plan in the U.S.
• Flexible work arrangements around the globe, allowing employees to better balance work and personal commitments.
• Global learning, leadership & organization programs to inspire, equip, and empower our people to thrive. These programs and resources are accessible to everyone at whatever stage they are in their career.

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Employee resource groups
Employee-led culture committees
Hybrid work model
In-person all-hands meetings
Summer hours
Employee awards
Flexible work schedule
Remote work program
Diversity
Documented equal pay policy
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity manifesto
Diversity employee resource groups
Hiring practices that promote diversity
Diversity recruitment program
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Team workouts
Mental health benefits
Transgender health care benefits
Wellness days
Abortion travel benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
Employee stock purchase plan
Performance bonus
Charitable contribution matching
Pay transparency
Child Care & Parental Leave Benefits
Childcare benefits
Generous parental leave
Family medical leave
Adoption Assistance
Company sponsored family events
Fertility benefits
Vacation & Time Off Benefits
Unlimited vacation policy
Paid volunteer time
Sabbatical
Paid holidays
Paid sick days
Flexible time off
Bereavement leave benefits
Company-wide vacation
Office Perks
Commuter benefits
Free snacks and drinks
Company-sponsored happy hours
Onsite office parking
Relocation assistance
Home-office stipend for remote employees
Meditation space
Mother's room
Onsite gym
Professional Development Benefits
Job training & conferences
Tuition reimbursement
Lunch and learns
Promote from within
Mentorship program
Continuing education stipend
Online course subscriptions available
Customized development tracks
Paid industry certifications
Personal development training
Virtual coaching services

More Jobs at Warner Bros. Discovery

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about Warner Bros. DiscoveryFind similar jobs like this