Listing Description
About the Role:
The Cloud Security Engineering Manager is a part of the Tubi Infrastructure Engineering team, owning the tools, documents, and procedures for how apps are built and run at Tubi. Members of this team work closely with application developers, engineering leaders, and cross-functional key stakeholders to raise the platform on the quality of our applications through automation and process. The security team guides the organization in applying principles such as least privilege, zero-trust, and continuous risk assessment, meanwhile balancing between risk management, application stability, and streamlined developer workflows.
Responsibilities:
- Liaison with Parent Company Fox Corp
- Maintain communication with our parent company's infosec team
- Ensure adherence to cybersecurity compliance requirements
- Manage expectations and discuss timelines and roadmaps
- Stakeholder Communication
- Engage with key stakeholders within our organization to streamline the implementation of security-related projects
- Facilitate and coordinate efforts for timely upgrades for operating systems, docker images, and application code library versions
- Security Reviews
- Conduct thorough security assessments of engineering changes, ensuring designs adhere to best practices
- Permission Administration
- Identify and deprecate overly broad permissions, while maintaining system stability
- Proactively communicate with affected developers
Your Background:
- 4+ years of experience in a leadership role, directly managing engineers
- 5+ years of Security Engineering
- Experience creating security documentation that clearly describes business needs and a plan of action, while minimizing room for ambiguity
- Experience with project management and project planning with the ability to break down long-term goals into smaller projects and tasks
- 4+ years of experience using AWS (Especially IAM and VPC)
- 4+ years of experience using Linux and shell scripting
- 2+ years of experience using Kubernetes (NetworkPolicy, ClusterRole, and Role)
- Experience with Identity Access Management (Okta) & Secrets Management (Hashicorp Vault)
- 1+ years of experience participating in audits for NIST, SOC2, SOX, GDPR, or CCPA
#LI-Remote #LI-MQ1
Listing Details
- Citizenship: Not Provided
- Incentives: Not Provided
- Education: Not Provided
- Travel: Not Provided
- Telework: Not Provided