Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Platform Security Engineer (DevOps) - NBC Sports Next image - Rise Careers
Job details

Platform Security Engineer (DevOps) - NBC Sports Next - job 5 of 6

Company Description

We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our theme parks and consumer experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, MSNBC, CNBC, NBC Sports, Telemundo, NBC Local Stations, Bravo, USA Network, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through Universal Filmed Entertainment Group and Universal Studio Group, and have world-renowned theme parks and attractions through Universal Destinations & Experiences. NBCUniversal is a subsidiary of Comcast Corporation.

Comcast NBCUniversal has announced its intent to create a new publicly traded company ('SpinCo') comprised of most of NBCUniversal's cable television networks, including USA Network, CNBC, MSNBC, Oxygen, E!, SYFY and Golf Channel along with complementary digital assets Fandango, Rotten Tomatoes, GolfNow, GolfPass, and SportsEngine. The well-capitalized company will have significant scale as a pure-play set of assets anchored by leading news, sports and entertainment content. The spin-off is expected to be completed during 2025.

As a company uniquely positioned to educate, entertain and empower through our platforms, Comcast NBCUniversal stands for including everyone. Our Diversity, Equity and Inclusion initiatives, coupled with our Corporate Social Responsibility work, is informed by our employees, audiences, park guests and the communities in which we live. We strive to foster a diverse, equitable and inclusive culture where our employees feel supported, embraced and heard. Together, we'll continue to create and deliver content that reflects the current and ever-changing face of the world.

NBC Sports Next is where sports and technology intersect. We’re fueled by our mission to innovate, create larger-than-life events and connect with sports fans through technology. We’re a subdivision of NBC Sports and home to leading technology platforms and digital applications for Youth & Recreational Sports; Golf; and Emerging Media.   

At NBC Sports Next, we equip more than 30MM players, coaches, athletes, sports administrators and fans in 40 countries with more than 25 sports solution products, including SportsEngine, the largest youth sports club, league and team management platform; SportsEngine Play, the first ever streaming service for youth and amateur sports, GolfNow, the leading online tee time marketplace and provider of golf course operations technology; and GolfPass the ultimate golf membership that connects golfers to exclusive content, tee time credits, instructional content and more.   

Job Description

As a Platform Security Engineer, you’ll play a pivotal role in securing our engineering ecosystem by developing capabilities, services, and automation that balance speed, scalability, and compliance. You’ll lead the DevSecOps roadmap, shaping the future of secure cloud infrastructure and enabling teams to innovate with confidence. This hands-on role emphasizes AWS security, CI/CD security, and security automation, empowering our teams to deliver secure software at scale and quickly remediate issues if they arise. If you’re passionate about building scalable, secure cloud solutions and driving security excellence, we want to talk to you! This role is remote and may require some travel.

Job Description

  • Lead Security Efforts on the Platform: Drive and deliver security solutions across AWS cloud, container security (ECS/Kubernetes), CICD, and secure cloud-native architectures while ensuring compliance with standards such as PCI-DSS, ISO27001, SOC 2, NIST 800-53, and COPPA.
  • Enhance Secure CI/CD: Build and enhance security related platform capabilities, involving CI/CD pipelines, infrastructure, reusable templates, and automation, enabling teams to deploy rapidly and securely at scale.
  • Standardize Secure Patterns: Design and implement reusable patterns that promote security best practices and compliance across all engineering teams.
  • Advance Secure Software Delivery: Promote secure delivery practices by embedding security in the build and design phases, emphasizing fast feedback, observability, and operational excellence.
  • Collaborate Cross-Functionally: Work closely with SecOps, platform teams, and engineering teams, fostering knowledge sharing and ensuring alignment on security goals and solutions.
  • Strengthen Security Posture: Assess and improve existing security standards, practices, and controls to reduce vulnerabilities and enhance the organization’s security posture.
  • Drive Compliance Automation: Develop automation strategies to enforce regulatory controls and ensure continuous compliance with industry standards.
  • Support Incident Response: Collaborate on incident monitoring and response, conduct Root Cause Analysis, and recommend measures for future mitigation.
    Leverage Key Tools and Skills: Utilize AWS cloud knowledge, Terraform, and Python to develop secure solutions that balance security objectives with developer productivity and business goals.
  • Communicate Effectively: Deliver clear security updates, document solutions thoroughly, demo and communicate effectively with diverse stakeholders, including engineering teams and executive leadership.

Qualifications

Required Experience:

  • AWS Expertise: 2+ years of hands-on experience with AWS, with a strong focus on IAM best practices and securing common AWS resources (e.g., EC2, S3, RDS) in production public facing environments.
  • Linux Proficiency: Minimum of 4 years of experience managing and securing Linux systems.
  • Security Automation & Tooling: 2+ years of experience implementing security automation and integrating security tooling (e.g., SEIM, SAST/DAST, WIZ/ORCA, or other).
  • Automation/Scripting: 2+ years of experience with Python for automation and scripting in a security/DevSecOps context. 
  • Git and GitOps: Practical experience and comfortable using Git and automated workflows for developing code securely.
  • Web Security Knowledge: Familiarity with web security best practices, including DNS, firewalls, secure APIs, and database security (e.g., PostgreSQL, MySQL).
  • Cloud Security: Proven ability to secure cloud environments, including implementing and managing security controls, auditing, and monitoring.
  • Communication & Collaboration: Exceptional written and verbal communication skills with the ability to explain complex security concepts to technical and non-technical audiences.
  • Track Record of Solutions: Demonstrated ability to identify and address security challenges, delivering effective solutions through collaboration and leadership.

Preferred Qualifications:

  • Regulated Environments: Experience working in environments with complex compliance requirements (e.g., PCI-DSS, SOC 2, ISO27001).
  • AWS Certifications: Relevant certifications such as AWS Certified Security – Specialty or AWS Certified Solutions Architect.
  • Web Security & Threat Detection: Hands-on experience with WAFs (e.g., AWS WAF, Cloudflare) and centralized logging stacks (e.g., Splunk, Kibana).
  • DevSecOps Expertise: Strong understanding of secure CI/CD practices and integrating compliance objectives into pipelines.
  • Infrastructure as Code (IaC): Experience with Terraform or CloudFormation for managing secure infrastructure.
  • Security Mentorship: Proven ability to mentor engineers and share security knowledge effectively.

Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.

Additional Information

As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.

If you are a qualified individual with a disability or a disabled veteran and require support throughout the application and/or recruitment process as a result of your disability, you have the right to request a reasonable accommodation. You can submit your request to [email protected].

For LA County and City Residents Only:  NBCUniversal will consider for employment
qualified applicants with criminal histories, or arrest or conviction records, in a manner
consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance
Initiative For Hiring Ordinance, the Los Angeles' County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.

NBCUniversal Glassdoor Company Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
NBCUniversal DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of NBCUniversal
NBCUniversal CEO photo
Jeff Shell
Approve of CEO

Average salary estimate

$105000 / YEARLY (est.)
min
max
$80000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Platform Security Engineer (DevOps) - NBC Sports Next, NBCUniversal

Join NBC Sports Next as a Platform Security Engineer (DevOps) and play a crucial role in safeguarding our engineering environment! In this exciting position, you’ll have the chance to develop capabilities, services, and automation that fuse speed, scalability, and compliance. Your expertise will be instrumental in leading the DevSecOps roadmap, shaping secure cloud infrastructures, and empowering teams to innovate confidently. Emphasizing AWS security, CI/CD security, and security automation, you will help deliver secure software rapidly while ensuring that any potential issues are quickly resolved. You’ll actively engage with cross-functional teams, making security an integral part of every step from build to implementation. If you’re passionate about crafting secure, scalable cloud solutions and have a knack for driving security excellence, we’re eager to meet you! This position is fully remote, allowing you to collaborate with a diverse group of professionals while potentially requiring occasional travel. At NBC Sports Next, you’ll not only enhance your skills and knowledge but also contribute to our mission of transforming sports experiences through technology. Apply today to embark on this exciting journey with us!

Frequently Asked Questions (FAQs) for Platform Security Engineer (DevOps) - NBC Sports Next Role at NBCUniversal
What are the primary responsibilities of a Platform Security Engineer at NBC Sports Next?

As a Platform Security Engineer at NBC Sports Next, you will be responsible for leading security efforts on the platform, enhancing secure CI/CD practices, and promoting secure software delivery. This involves implementing security solutions across AWS, managing container security, and ensuring compliance with industry standards like PCI-DSS and ISO27001. Collaboration with SecOps and engineering teams is essential for achieving security goals effectively.

Join Rise to see the full answer
What qualifications are required for the Platform Security Engineer position at NBC Sports Next?

To qualify for the Platform Security Engineer role at NBC Sports Next, candidates should have over 2 years of hands-on AWS experience, proficiency in managing Linux systems, and a solid background in security automation and tooling. Additionally, expertise with scripting languages, particularly Python, along with familiarity in web security best practices and cloud security protocols is crucial for success in this role.

Join Rise to see the full answer
How does NBC Sports Next ensure compliance in their security practices for the Platform Security Engineer role?

At NBC Sports Next, compliance is achieved by implementing security solutions that meet and maintain standards such as PCI-DSS, SOC 2, and NIST 800-53. The Platform Security Engineer will develop automation strategies to enforce these regulatory controls continuously and ensure that all teams adhere to security best practices across the engineering ecosystem.

Join Rise to see the full answer
What tools and skills are essential for a Platform Security Engineer at NBC Sports Next?

A Platform Security Engineer at NBC Sports Next must be proficient in using AWS cloud tools, Terraform, and Python for automation and security purposes. Familiarity with Git and GitOps practices, along with knowledge of web application firewalls (WAFs) and logging stacks, will also be beneficial for effective security management and compliance.

Join Rise to see the full answer
Is this Platform Security Engineer position remote, and does it require travel?

Yes, the Platform Security Engineer position at NBC Sports Next is fully remote, which allows employees to work from their preferred location. However, candidates should be open to potential travel for team meetings or events as needed.

Join Rise to see the full answer
Common Interview Questions for Platform Security Engineer (DevOps) - NBC Sports Next
Can you describe your experience with AWS security best practices?

In answering this question, emphasize your hands-on experience with AWS, detailing specific services you've secured such as EC2, S3, and IAM roles. Discuss how you applied best practices and the impact of these measures on your previous projects.

Join Rise to see the full answer
What security automation tools have you implemented in previous roles?

Share examples of security automation tools you’ve utilized, such as SEIM, SAST, or DAST. Discuss your experience in integrating these tools into CI/CD pipelines and the benefits realized in your previous projects.

Join Rise to see the full answer
How do you approach vulnerability assessments and remediation?

Discuss your systematic approach to identifying vulnerabilities through regular security assessments. Talk about the methodologies you use, tools you prefer, and how you prioritize remediation based on the severity of the vulnerabilities found.

Join Rise to see the full answer
What steps do you take to ensure secure software delivery?

Highlight your practices such as embedding security during the design phase and implementing rapid feedback loops through collaboration with developers. Provide specific examples of how you’ve improved software delivery timelines while maintaining security.

Join Rise to see the full answer
Can you explain your experience with incident response and root cause analysis?

In your response, illustrate instances where you’ve actively participated in incident response efforts. Describe the process you followed for conducting root cause analyses and any improvements implemented post-incident.

Join Rise to see the full answer
What are the regulatory compliance requirements you are familiar with?

Discuss your knowledge of compliance frameworks like PCI-DSS, SOC 2, and ISO27001. Explain your experience in helping organizations meet these requirements and how you stay updated with evolving compliance standards.

Join Rise to see the full answer
How do you effectively communicate complex security concepts to non-technical stakeholders?

Share strategies you use to simplify complex security concepts, such as using analogies or visual aids. Provide examples where your communication led to improved understanding and alignment on security goals within your organization.

Join Rise to see the full answer
What is your experience with using Terraform or similar tools for IaC?

Discuss your proficiency with infrastructure as code (IaC) tools like Terraform. Provide examples of how you’ve used it to manage secure infrastructures and improve deployment consistency.

Join Rise to see the full answer
Can you give an example of a challenging security issue you faced and how you resolved it?

Share a specific case where you encountered a significant security challenge. Discuss your analysis, the steps you took to resolve the issue, and the outcomes of your actions.

Join Rise to see the full answer
What are the key components of a secure CI/CD pipeline?

Talk about essential elements like automated security testing, infrastructure code scanning, and audit logging. Explain how each component contributes to the overall security posture of software development in a CI/CD workflow.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
NBCUniversal Hybrid Universal City, Texas, United States
Posted 21 hours ago

Become a key member of NBCUniversal’s Finance Systems team, driving innovative solutions and enhancements in financial operations.

Photo of the Rise User
NBCUniversal Remote 904 Sylvan Ave, Englewood Cliffs, NEW JERSEY
Posted 21 hours ago

NBC Sports is on the lookout for a skilled Desk Editor to oversee digital content management across various sports events and properties.

Photo of the Rise User
Posted 2 days ago

Ciena is on the lookout for a dynamic Security Outreach Lead to establish strategic partnerships and elevate our cybersecurity efforts.

ngc Hybrid United States-Maryland-Baltimore
Posted 9 days ago

Join Northrop Grumman as a PC Network Support Technician to deliver technical support for computer networks and systems.

GDIT Remote Any Location / Remote
Posted 4 days ago

GDIT seeks a Cloud Systems Administrator to enhance cloud operations and support user needs in a remote role.

Photo of the Rise User

Join HPD Tech as a Project Administrator Specialist to coordinate IT projects and support housing initiatives in New York City.

RahrBSG Hybrid Shakopee, Minnesota
Posted 6 days ago

Become a pivotal member of RahrBSG as an Enterprise Architect, driving technology strategies for a leading craft beverage industry partner.

Photo of the Rise User
Posted 2 days ago

Become a key player at Visa Inc. as a Sr. Site Reliability Engineer, focusing on critical application support and Big Data technologies.

Photo of the Rise User
Posted 9 days ago

Join Manulife as a Senior IT Business Analyst to enhance data security and management practices across Asia.

Photo of the Rise User
American Express Remote Phoenix, Arizona, United States
Posted 5 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Lead Agile practices and foster collaboration as a Senior Agile Champion at American Express, driving impactful software solutions.

We are in business to create and deliver content so compelling it entertains, informs and shapes our world. We believe that the talent, creativity and diversity of our people are our greatest resources. We take our business seriously, but do no...

2010 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 2, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!