DevSecOps Engineer II - NBC Sports Next
Orlando, FL, United States
NBCUniversal
Company Description
We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our theme parks and consumer experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, MSNBC, CNBC, NBC Sports, Telemundo, NBC Local Stations, Bravo, USA Network, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through Universal Filmed Entertainment Group and Universal Studio Group, and have world-renowned theme parks and attractions through Universal Destinations & Experiences. NBCUniversal is a subsidiary of Comcast Corporation.
Here you can be your authentic self. As a company uniquely positioned to educate, entertain and empower through our platforms, Comcast NBCUniversal stands for including everyone. Our Diversity, Equity and Inclusion initiatives, coupled with our Corporate Social Responsibility work, is informed by our employees, audiences, park guests, and the communities in which we live. We strive to foster a diverse, equitable, and inclusive culture where our employees feel supported, embraced, and heard. Together, we’ll continue to create and deliver content that reflects the current and ever-changing face of the world.
At NBC Sports Next is where sports and technology intersect. We’re a division of NBC Sports and home to all NBCUniversal digital applications in golf and youth & recreational sports. We equip more than 30MM players, coaches, athletes, sports administrators and fans in 40 countries with more than 25 sports solution products, including SportsEngine, the largest youth sports club, league and team management platform; GolfNow, the leading online tee time marketplace and provider of golf course operations technology; and GolfPass the ultimate golf membership that connects golfers to exclusive video content, discounts on tee times and equipment, and more.
At NBC Sports Next we’re fueled by our mission to innovate, create larger-than-life events, and connect with sports fans through technology that provides the ultimate in immersive experiences.
Come join us as we work together as one team to innovate and deliver what’s Next.
Job Description
The DevSecOps Engineer II role will be responsible for NBCSports Next Operations services infrastructure. This role will be critical in NBCSports Next to enhance our security posture. This position will require 24x7 support availability. Some travel may be required for this position.
In this role you’ll be responsible to ensure security, automation, and supportability into our system architecture. You’ll be building and supporting automation business initiatives to enhance our compliance across multiple security frameworks. This position will work to take compliance objectives and create automation tasks around completion of those objectives.
- Contribute to developing an automation strategy for executing a comprehensive PCI DSS technical assessment program.
- Work with internal teams to ensure security is shifted left in the build and design phase.
- Develop innovative solutions by implementing state of the art prevention, response, and detection capabilities.
- Drive innovation and automation to increase security of CI/CD pipelines.
- Excellent communication skills. This role will be working with domestic and international teams to achieve the goals of the organization. This role may also require communications with executive leadership.
- Monitor and respond to security incidents and alerts, perform Root Cause Analysis, and recommend appropriate measure for future mitigation.
- Maintain an active role in supporting and defining new security policies.
- Perform vulnerability checks to ensure system security and compliance.
- Utilize programming languages like Java, Python, Node JS, TypeScript, SQL, Ruby, Go and/or container orchestration services such as Docker and Kubernetes, CM tools such as Ansible and Terraform.
Qualifications
All candidates must meet minimum qualifications below:
- 5+ years of Windows systems administration skills including patching and Active Directory
- 5+ years of Linux systems administration skills
- 2+ years of Cloud computing experience in one of AWS/Azure/GCP
- 2+ years supporting embedded security scanning in GitHub, GitLab, or other CI/CD tools
- Experience with Python web frameworks
- Experience with centralized logging stacks such as Splunk or Kibana
Desired qualifications are below:
- Experienced in DevOps principles and practices
- Infrastructure as Code experience with Terraform or CloudFormation
- Cloud orchestration tooling such as AWS Systems Manager; or equivalent in Azure or GCP
- Public Cloud experience in AWS, Azure or GCP; specifically: securing perimeters, IAM least privilege, preventing lateral movement, orchestrating zero-downtime patching, and security best practices
- Experience using WAF solutions such as AWS WAF, Cloudflare, Akamai Kona etc.
- Experience authoring and troubleshooting scripts in languages such as: PowerShell, Bash, Python, or Go.
- Experience demonstrating co-workers or contractors on security tasks
- Proficient in ticketing and work management solutions such as Jira and ServiceNow.
- Contributing to and using our GitHub Pull Request-centred development pipeline as we continuously deliver value to our customers.
- Experience with deploying compliance objectives into a CI/CD pipeline.
Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.
Additional Information
NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law. NBCUniversal will consider for employment qualified applicants with criminal histories in a manner consistent with relevant legal requirements, including the City of Los Angeles Fair Chance Initiative For Hiring Ordinance, where applicable.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations by emailing AccessibilitySupport@nbcuni.com.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Active Directory Ansible Automation AWS Azure Bash CI/CD Cloud Cloudflare Compliance DevOps DevSecOps Docker GCP GitHub IAM Java Jira Kubernetes Linux Node.js PCI DSS PowerShell Python Ruby Splunk SQL Strategy Terraform TypeScript Windows
Perks/benefits: Fitness / gym Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open IT Security Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open o365 Security Architect jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open CISM-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open EDR-related jobs