Software Engineer, DevSecOps

Englewood Cliffs, NEW JERSEY, United States

Applications have closed

Company Description

We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our theme parks and consumer experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, MSNBC, CNBC, NBC Sports, Telemundo, NBC Local Stations, Bravo, USA Network, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through Universal Filmed Entertainment Group and Universal Studio Group, and have world-renowned theme parks and attractions through Universal Destinations & Experiences. NBCUniversal is a subsidiary of Comcast Corporation. 

Here you can be your authentic self. As a company uniquely positioned to educate, entertain and empower through our platforms, Comcast NBCUniversal stands for including everyone. Our Diversity, Equity and Inclusion initiatives, coupled with our Corporate Social Responsibility work, is informed by our employees, audiences, park guests and the communities in which we live. We strive to foster a diverse, equitable and inclusive culture where our employees feel supported, embraced and heard. Together, we’ll continue to create and deliver content that reflects the current and ever-changing face of the world.   

Job Description

The Software Engineer, DevSecOps will be part of a team designed to help enable our Engineering Experience group to shift-left with a security first mindset in how we engineer software at NBCU. The candidate will work with engineering teams to bring secure-by-default tools and cloud components across our engineering culture, and alignment with our corporate cyber team. We are dedicated to make secure software development a part of the mindset of every engineer at NBCU.

The capabilities we are building will aide with providing easy, templated solutions that create paved roads to go from account creation to code repositories to production that include, but not limited to:

  • Secure testing of code in CI/CD Pipelines
  • Secure testing of edge-based API Gateways
  • Knowledge of scanning tools for secrets in various developer toolchains, such as Jira, Confluence, Atlassian
  • Automation and creation of blueprints to align with secure cloud building blocks into solutions for various cloud providers
  • Educate engineering teams to help provide alignment with corporate cyber policies to ensure that security is part of a highly DevOps oriented and multi-cloud environment
  • Performance, code quality, security and privacy templating to increase adoption with a focus on all types of cloud environments from compute to serverless.

Responsibilities 

  • Work as part of a team of application security, cloud security, and software engineers who will build and monitor paved roads that can deliver frictionless experience and allow all product engineering teams to work in a secure manner by default.
  • Partner with the security champions program by working across software engineering who can embed with areas of the product where help is needed
  • Help ensure that security is part of a highly DevOps oriented and multi-cloud environment
  • Help drive the development of our internal developer portal with security first mindset.
  • Consult, educate, and empower engineers as they build & ship innovative software.
  • Research, prototype and develop solutions in support of the adoption of new technologies and architecture.
  • Gather regular feedback about developer experience, ensuring security is an enabler, not a roadblock or gate.
  • Engage with engineers throughout the company to learn about pain points, and work alongside a technical lead to define and prioritize solutions.
  • Establish and maintain partnerships within the organization and internal customers to determine roadmap features 

Qualifications

  • 3+ years of relevant work experience
  • Understanding of Application Lifecycle Management tools, threat models, Continuous Integration, Continuous Deployment, Version Control, Testing Frameworks with an eye on DevSecOps
  • A passion for embedding security expertise within other areas of the business and product security functions within a product or cloud-native company
  • Understanding of public cloud services (AWS/Azure/GCP) and fundamental components like Compute/Virtual Machines, Serverless, Storage, Databases, Identity and User Management, etc.
  • Ability to write technical documentation (platform architecture, strategy, engineering etc.) 
  • Demonstrated leadership skills in a fast-paced, team-driven environment.
  • Grasp the big picture, while still delivering on the details
  • Are passionate about building products that engineers love and believe in the true outcome of DevOps that includes security
  • Ability to handle multiple competing priorities in a fast-paced environment
  • Excellent verbal and written communication and presentation skills

Desired Characteristics:

  • Experience driving the adoption of security tools through self-service pipelines 
  • Demonstrated ability to conceive, manage, and complete project deliverables  
  • A good communicator who can inspire their team to help them understand the mission

This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $105,000 - $140,000

Additional Information

NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law. NBCUniversal will consider for employment qualified applicants with criminal histories in a manner consistent with relevant legal requirements, including the City of Los Angeles Fair Chance Initiative For Hiring Ordinance, where applicable.

If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations in the US by calling 1-818-777-4107 and in the UK by calling +44 2036185726.

Tags: APIs Application security Automation AWS Azure CI/CD Cloud Confluence DevOps DevSecOps GCP Jira Privacy Product security Strategy

Perks/benefits: Equity / stock options Health care Insurance Medical leave

Region: North America
Country: United States
Job stats:  9  2  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.