Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Platform Security Engineer (DevOps) - NBC Sports Next image - Rise Careers
Job details

Platform Security Engineer (DevOps) - NBC Sports Next - job 1 of 6

Company Description

We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our theme parks and consumer experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, MSNBC, CNBC, NBC Sports, Telemundo, NBC Local Stations, Bravo, USA Network, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through Universal Filmed Entertainment Group and Universal Studio Group, and have world-renowned theme parks and attractions through Universal Destinations & Experiences. NBCUniversal is a subsidiary of Comcast Corporation.

Comcast NBCUniversal has announced its intent to create a new publicly traded company ('SpinCo') comprised of most of NBCUniversal's cable television networks, including USA Network, CNBC, MSNBC, Oxygen, E!, SYFY and Golf Channel along with complementary digital assets Fandango, Rotten Tomatoes, GolfNow, GolfPass, and SportsEngine. The well-capitalized company will have significant scale as a pure-play set of assets anchored by leading news, sports and entertainment content. The spin-off is expected to be completed during 2025.

As a company uniquely positioned to educate, entertain and empower through our platforms, Comcast NBCUniversal stands for including everyone. Our Diversity, Equity and Inclusion initiatives, coupled with our Corporate Social Responsibility work, is informed by our employees, audiences, park guests and the communities in which we live. We strive to foster a diverse, equitable and inclusive culture where our employees feel supported, embraced and heard. Together, we'll continue to create and deliver content that reflects the current and ever-changing face of the world.

NBC Sports Next is where sports and technology intersect. We’re fueled by our mission to innovate, create larger-than-life events and connect with sports fans through technology. We’re a subdivision of NBC Sports and home to leading technology platforms and digital applications for Youth & Recreational Sports; Golf; and Emerging Media.   

At NBC Sports Next, we equip more than 30MM players, coaches, athletes, sports administrators and fans in 40 countries with more than 25 sports solution products, including SportsEngine, the largest youth sports club, league and team management platform; SportsEngine Play, the first ever streaming service for youth and amateur sports, GolfNow, the leading online tee time marketplace and provider of golf course operations technology; and GolfPass the ultimate golf membership that connects golfers to exclusive content, tee time credits, instructional content and more.   

Job Description

As a Platform Security Engineer, you’ll play a pivotal role in securing our engineering ecosystem by developing capabilities, services, and automation that balance speed, scalability, and compliance. You’ll lead the DevSecOps roadmap, shaping the future of secure cloud infrastructure and enabling teams to innovate with confidence. This hands-on role emphasizes AWS security, CI/CD security, and security automation, empowering our teams to deliver secure software at scale and quickly remediate issues if they arise. If you’re passionate about building scalable, secure cloud solutions and driving security excellence, we want to talk to you! This role is remote and may require some travel.

Job Description

  • Lead Security Efforts on the Platform: Drive and deliver security solutions across AWS cloud, container security (ECS/Kubernetes), CICD, and secure cloud-native architectures while ensuring compliance with standards such as PCI-DSS, ISO27001, SOC 2, NIST 800-53, and COPPA.
  • Enhance Secure CI/CD: Build and enhance security related platform capabilities, involving CI/CD pipelines, infrastructure, reusable templates, and automation, enabling teams to deploy rapidly and securely at scale.
  • Standardize Secure Patterns: Design and implement reusable patterns that promote security best practices and compliance across all engineering teams.
  • Advance Secure Software Delivery: Promote secure delivery practices by embedding security in the build and design phases, emphasizing fast feedback, observability, and operational excellence.
  • Collaborate Cross-Functionally: Work closely with SecOps, platform teams, and engineering teams, fostering knowledge sharing and ensuring alignment on security goals and solutions.
  • Strengthen Security Posture: Assess and improve existing security standards, practices, and controls to reduce vulnerabilities and enhance the organization’s security posture.
  • Drive Compliance Automation: Develop automation strategies to enforce regulatory controls and ensure continuous compliance with industry standards.
  • Support Incident Response: Collaborate on incident monitoring and response, conduct Root Cause Analysis, and recommend measures for future mitigation.
    Leverage Key Tools and Skills: Utilize AWS cloud knowledge, Terraform, and Python to develop secure solutions that balance security objectives with developer productivity and business goals.
  • Communicate Effectively: Deliver clear security updates, document solutions thoroughly, demo and communicate effectively with diverse stakeholders, including engineering teams and executive leadership.

Qualifications

Required Experience:

  • AWS Expertise: 2+ years of hands-on experience with AWS, with a strong focus on IAM best practices and securing common AWS resources (e.g., EC2, S3, RDS) in production public facing environments.
  • Linux Proficiency: Minimum of 4 years of experience managing and securing Linux systems.
  • Security Automation & Tooling: 2+ years of experience implementing security automation and integrating security tooling (e.g., SEIM, SAST/DAST, WIZ/ORCA, or other).
  • Automation/Scripting: 2+ years of experience with Python for automation and scripting in a security/DevSecOps context. 
  • Git and GitOps: Practical experience and comfortable using Git and automated workflows for developing code securely.
  • Web Security Knowledge: Familiarity with web security best practices, including DNS, firewalls, secure APIs, and database security (e.g., PostgreSQL, MySQL).
  • Cloud Security: Proven ability to secure cloud environments, including implementing and managing security controls, auditing, and monitoring.
  • Communication & Collaboration: Exceptional written and verbal communication skills with the ability to explain complex security concepts to technical and non-technical audiences.
  • Track Record of Solutions: Demonstrated ability to identify and address security challenges, delivering effective solutions through collaboration and leadership.

Preferred Qualifications:

  • Regulated Environments: Experience working in environments with complex compliance requirements (e.g., PCI-DSS, SOC 2, ISO27001).
  • AWS Certifications: Relevant certifications such as AWS Certified Security – Specialty or AWS Certified Solutions Architect.
  • Web Security & Threat Detection: Hands-on experience with WAFs (e.g., AWS WAF, Cloudflare) and centralized logging stacks (e.g., Splunk, Kibana).
  • DevSecOps Expertise: Strong understanding of secure CI/CD practices and integrating compliance objectives into pipelines.
  • Infrastructure as Code (IaC): Experience with Terraform or CloudFormation for managing secure infrastructure.
  • Security Mentorship: Proven ability to mentor engineers and share security knowledge effectively.

Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.

Additional Information

As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.  

If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations by emailing [email protected].

Although you'll be hired as an NBCU employee, your employment and the responsibilities associated with this job likely will transition to SpinCo in the future. By joining at this pivotal time, you'll be a part of this exciting company as it takes shape.

For LA County and City Residents Only:  NBCUniversal will consider for employment  qualified applicants with criminal histories, or arrest or conviction records, in a manner  consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.

NBCUniversal Glassdoor Company Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
NBCUniversal DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of NBCUniversal
NBCUniversal CEO photo
Jeff Shell
Approve of CEO

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Platform Security Engineer (DevOps) - NBC Sports Next, NBCUniversal

Join the innovative team at NBC Sports Next as a Platform Security Engineer (DevOps)! In this dynamic role, you will be at the forefront of securing our engineering ecosystem, developing cutting-edge capabilities and automation that strike the perfect balance between speed, scalability, and compliance. Your focus will be on AWS security, CI/CD security, and security automation, enabling our teams to deliver secure software rapidly and efficiently. As you lead our DevSecOps roadmap, you'll help shape the future of our secure cloud infrastructure. If you are passionate about building robust, scalable cloud solutions and keen on driving security excellence, we’d love to chat! With a focus on secure cloud architecture and compliance with industry standards like PCI-DSS and ISO27001, you get to collaborate cross-functionally with SecOps and engineering teams, advancing security practices and enhancing our overall security posture. The role is fully remote, giving you flexibility, though some travel may be necessary. If you're ready to join a company that encompasses the excitement of sports, technology, and teamwork, then Eastern Kentucky amenities are waiting for you as we strive to innovate and connect with millions of sports fans worldwide.

Frequently Asked Questions (FAQs) for Platform Security Engineer (DevOps) - NBC Sports Next Role at NBCUniversal
What are the key responsibilities of a Platform Security Engineer at NBC Sports Next?

As a Platform Security Engineer at NBC Sports Next, you will be leading security efforts across AWS cloud, enhancing CI/CD pipeline security, standardizing secure patterns, and driving compliance automation. Your role involves close collaboration with multiple teams to ensure best practices and advocate for a security-first culture in all engineering processes. You’ll also be assessing existing security standards and strengthening our security posture, aligning with regulatory controls such as PCI-DSS and ISO27001.

Join Rise to see the full answer
What qualifications are needed for the Platform Security Engineer role at NBC Sports Next?

To be successful as a Platform Security Engineer at NBC Sports Next, candidates should have a minimum of 2 years of hands-on AWS experience, strong Linux proficiency, knowledge in security automation and tooling, and experience with Python scripting for automation in a security context. A good understanding of CI/CD practices and web security best practices is essential. Strong communication skills to articulate complex security concepts to diverse stakeholders are also critical.

Join Rise to see the full answer
What tools and technologies do Platform Security Engineers at NBC Sports Next use?

Platform Security Engineers at NBC Sports Next utilize a wide array of tools and technologies in their daily tasks. Key tools include AWS services for secure cloud environments, Terraform for infrastructure as code, and various security tools such as SEIM and SAST/DAST for automation and monitoring. Proficiency in Git and GitOps practices is also important for securely developing and deploying code.

Join Rise to see the full answer
Is the Platform Security Engineer position at NBC Sports Next fully remote?

Yes, the Platform Security Engineer position at NBC Sports Next is designated as fully remote. This means you can contribute from your home office, offering flexibility and a better work-life balance. However, some travel may still be required depending on project needs and collaboration with other teams.

Join Rise to see the full answer
How does NBC Sports Next ensure compliance with security standards for the Platform Security Engineer role?

NBC Sports Next emphasizes compliance by embedding security practices into the development lifecycle, specifically through the implementation of frameworks like PCI-DSS, ISO27001, and SOC 2. As a Platform Security Engineer, you'll be directly involved in enhancing compliance automation, assessing security controls, and ensuring continuous adherence to these standards while promoting secure coding and deployment practices.

Join Rise to see the full answer
Common Interview Questions for Platform Security Engineer (DevOps) - NBC Sports Next
How do you approach security in a CI/CD pipeline as a Platform Security Engineer?

In a CI/CD pipeline, I prioritize embedding security at every stage. This means integrating security testing tools early in the build process, ensuring proper access controls, and automating compliance checks. I would also advocate for regular training and knowledge sharing among teams to ensure everyone understands secure coding practices and the importance of security in continuous delivery.

Join Rise to see the full answer
Can you describe your experience with AWS security best practices?

Absolutely! My experience with AWS security involves implementing IAM best practices, such as least privilege access, configuring VPC security groups, and utilizing AWS services like IAM roles, KMS for encryption, and CloudTrail for monitoring. I ensure that security is integral to our cloud infrastructure by performing regular audits and proactively managing vulnerabilities in our AWS environments.

Join Rise to see the full answer
What do you consider the most critical aspects of container security?

The most critical aspects of container security include proper image vulnerability scanning, ensuring containers run with least privilege, and monitoring for unusual activity. I also focus on using trusted base images and employing runtime security measures to detect and prevent compromises during operation. Adhering to established security frameworks helps in maintaining robust container security.

Join Rise to see the full answer
How do you stay updated with the latest security threats and trends?

I stay updated on the latest security threats by following prominent cybersecurity blogs, subscribing to threat intelligence feeds, and attending relevant webinars and conferences. Engaging with the security community through forums and professional networks also helps me stay informed about emerging threats and new security practices.

Join Rise to see the full answer
Describe a time you had to respond to a security incident.

In a previous role, I was part of an incident response team that addressed a data breach. I led the investigation, analyzed logs to identify the vector of the attack, and coordinated with various stakeholders to contain the breach. We developed a remediation plan that included patching vulnerabilities and enhancing monitoring capabilities to prevent future incidents. This experience taught me the importance of swift action and clear communication during a security crisis.

Join Rise to see the full answer
What strategies do you use for communication with non-technical stakeholders regarding security issues?

When communicating with non-technical stakeholders, I focus on simplifying complex security concepts into easily understandable terms. I rely on analogies and visuals to explain the potential risks and their impacts on the organization. Moreover, I ensure that discussions are tailored to the audience’s level of understanding and emphasize the urgency and importance of security measures.

Join Rise to see the full answer
How do you incorporate security into the software development lifecycle?

I incorporate security into the software development lifecycle by promoting a DevSecOps culture where security is considered at every phase. This includes conducting threat modeling during planning, implementing security testing in CI/CD pipelines, and facilitating regular security reviews. I also advocate for continuous training for developers on secure coding practices.

Join Rise to see the full answer
What are some security automation tools you've implemented in previous roles?

In previous roles, I have implemented tools such as OWASP ZAP for dynamic application security testing, Terraform for infrastructure as code, and various SIEM tools for monitoring security events. Automation solutions help streamline security processes such as compliance checks and vulnerability scanning, enhancing overall security posture significantly.

Join Rise to see the full answer
What is your understanding of compliance standards like SOC 2 and ISO27001?

SOC 2 is focused on the controls relevant to security, availability, processing integrity, confidentiality, and privacy while ISO27001 outlines the requirements for establishing an information security management system (ISMS). Both frameworks emphasize risk management and continuous improvement in security practices, which I believe are crucial in maintaining a security-first approach in any organization.

Join Rise to see the full answer
What’s your process for mentoring engineers on security best practices?

My process for mentoring engineers on security best practices involves conducting hands-on training sessions, sharing resources and guides, and encouraging them to adopt a security mindset. I promote regular discussions on security challenges they face and addressing them collectively, fostering a culture where everyone feels responsible for security and confident in their knowledge.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 6 days ago

Explore hands-on Data Science opportunities with NBCUniversal, where interns can engage in meaningful work for the 2025-2026 academic year.

Photo of the Rise User
NBCUniversal Hybrid 30 Rockefeller Center, New York, NY 10112, USA
Posted 6 days ago

Explore a dynamic internship with NBCUniversal's Product Management team, engaging in innovative projects across media and technology.

UBC Hybrid UBC Vancouver Campus
Posted 13 days ago

The UBC Sauder School of Business is looking for a Business Technology Analyst to enhance their business processes through technology-driven solutions.

Credence is looking for a Senior Cloud Network Engineer to join its team, providing technology solutions for federal defense and health organizations.

Join Allied Consultants as a Senior Web Administrator to lead web design and content management initiatives in a hybrid work environment.

Photo of the Rise User
Sectigo Remote Ottawa, ON, Canada
Posted 6 days ago

Join Sectigo as a Database Administrator, where you'll lead management of critical database systems in a hybrid work environment.

Photo of the Rise User
Posted 11 days ago

Become a vital part of Visa's Cyber Security team as a Sr. Cybersecurity Engineer, driving innovation in IAM processes through advanced technologies.

Photo of the Rise User

Seeking an experienced Site Reliability Engineer to join our dynamic team and optimize our Cloud and Big Data platforms.

Photo of the Rise User

Become a key player at Flutter as IT Affiliation Associate Manager, where you'll develop innovative solutions for a dynamic iGaming market.

Photo of the Rise User
Posted 6 days ago

Join Peraton as a Cyberspace Intelligence Analyst, where you will play a vital role in supporting national security through advanced cyber operations at Fort Meade, MD.

We are in business to create and deliver content so compelling it entertains, informs and shapes our world. We believe that the talent, creativity and diversity of our people are our greatest resources. We take our business seriously, but do no...

2430 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 11, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
X
Someone from OH, Cleveland just viewed Lead / Senior Analyst - SAP HCM at Xcellink Pte Ltd
Photo of the Rise User
57 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
Someone from OH, Akron just viewed Accounting Co-Op at VEGA Americas
R
Someone from OH, Cincinnati just viewed Director, Payroll Tax at Ryan
Photo of the Rise User
13 people applied to Intern/Co-op-4 at GE
P
Someone from OH, Columbus just viewed Data Science for Smart Agriculture- Part-Time at PSU
Photo of the Rise User
Someone from OH, Cincinnati just viewed Brand Management & Partnerships Assistant at LAIKA
Photo of the Rise User
Someone from OH, Athens just viewed Senior Multimedia Artist, Design & Creative at RepRisk AG
Photo of the Rise User
62 people applied to Cyber Crime Analyst at TEKsystems
H
Someone from OH, Rocky River just viewed Training Manager at Hotel Bardo Savannah
F
Someone from OH, Columbus just viewed VP of Communications at Freedom Together Foundation
Photo of the Rise User
Someone from OH, Columbus just viewed Chief Organizational Communication Officer at Providence
Photo of the Rise User
Someone from OH, Cuyahoga Falls just viewed SEASONER at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Bilingual Care Manager, Telephonic RN at Humana
Photo of the Rise User
Someone from OH, Columbus just viewed Talent Business Partner at Red Bull
Photo of the Rise User
Someone from OH, Brunswick just viewed Sanitation Team Member at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Talent Acquisition Specialist at Beghou Consulting
C
Someone from OH, Middletown just viewed Operations Analyst at Core Specialty Insurance
A
Someone from OH, Strongsville just viewed Graphic Design Intern at Anvil NorthWest