Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Platform Security Engineer - NBC Sports Next image - Rise Careers
Job details

Platform Security Engineer - NBC Sports Next - job 1 of 2

Company Description

We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our theme parks and consumer experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, MSNBC, CNBC, NBC Sports, Telemundo, NBC Local Stations, Bravo, USA Network, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through Universal Filmed Entertainment Group and Universal Studio Group, and have world-renowned theme parks and attractions through Universal Destinations & Experiences. NBCUniversal is a subsidiary of Comcast Corporation.

Here you can be your authentic self. As a company uniquely positioned to educate, entertain and empower through our platforms, Comcast NBCUniversal stands for including everyone. Our Diversity, Equity and Inclusion initiatives, coupled with our Corporate Social Responsibility work, is informed by our employees, audiences, park guests and the communities in which we live. We strive to foster a diverse, equitable and inclusive culture where our employees feel supported, embraced and heard. Together, we’ll continue to create and deliver content that reflects the current and ever-changing face of the world.

SPORTS NEXT

NBC Sports Next is where sports and technology intersect. We’re fueled by our mission to innovate, create larger-than-life events and connect with sports fans through technology. We’re a subdivision of NBC Sports and home to leading technology platforms and digital applications for Youth & Recreational Sports; Golf; and Emerging Media.  

At NBC Sports Next, we equip more than 30MM players, coaches, athletes, sports administrators and fans in 40 countries with more than 25 sports solution products, including SportsEngine, the largest youth sports club, league and team management platform; SportsEngine Play, the first ever streaming service for youth and amateur sports, GolfNow, the leading online tee time marketplace and provider of golf course operations technology; and GolfPass the ultimate golf membership that connects golfers to exclusive content, tee time credits, instructional content and more.  

GOLF

Golf fuses the team behind products and services like GolfNow, TeeOff and GolfPass, which better connects golfers and golf facilities around the world through innovative solutions like cloud-based golf course management and SmartPlay contactless technology and services that create optimum golfing experiences. 

Job Description

As a Platform Security Engineer, you’ll play a pivotal role in securing our engineering ecosystem by developing capabilities, services, and automation that balance speed, scalability, and compliance. You’ll lead the DevSecOps roadmap, shaping the future of secure cloud infrastructure and enabling teams to innovate with confidence. This hands-on role emphasizes AWS security, CI/CD security, and security automation, empowering our teams to deliver secure software at scale and quickly remediate issues if they arise. If you’re passionate about architecting scalable, secure cloud solutions and driving security excellence, we want to talk to you! This role is remote and may require some travel.

Job Description

  • Lead Security Efforts on the Platform: Drive and deliver security solutions across AWS cloud, container security (ECS/Kubernetes), CICD, and secure cloud-native architectures while ensuring compliance with standards such as PCI-DSS, ISO27001, SOC 2, NIST 800-53, and COPPA.
  • Enhance Secure CI/CD: Build and enhance security related platform capabilities, involving CI/CD pipelines, infrastructure, reusable templates, and automation, enabling teams to deploy rapidly and securely at scale.
  • Standardize Secure Patterns: Design and implement reusable patterns that promote security best practices and compliance across all engineering teams.
  • Advance Secure Software Delivery: Promote secure delivery practices by embedding security in the build and design phases, emphasizing fast feedback, observability, and operational excellence.
  • Collaborate Cross-Functionally: Work closely with SecOps, platform teams, and engineering teams, fostering knowledge sharing and ensuring alignment on security goals and solutions.
  • Strengthen Security Posture: Assess and improve existing security standards, practices, and controls to reduce vulnerabilities and enhance the organization’s security posture.
  • Drive Compliance Automation: Develop automation strategies to enforce regulatory controls and ensure continuous compliance with industry standards.
  • Support Incident Response: Collaborate on incident monitoring and response, conduct Root Cause Analysis, and recommend measures for future mitigation.
    Leverage Key Tools and Skills: Utilize AWS cloud knowledge, Terraform, and Python to develop secure solutions that balance security objectives with developer productivity and business goals.
  • Communicate Effectively: Deliver clear security updates, document solutions thoroughly, demo and communicate effectively with diverse stakeholders, including engineering teams and executive leadership.

Qualifications

Required Experience:

  • AWS Expertise: 2+ years of hands-on experience with AWS, with a strong focus on IAM best practices and securing common AWS resources (e.g., EC2, S3, RDS) in production public facing environments.
  • Linux Proficiency: Minimum of 4 years of experience managing and securing Linux systems.
  • Security Automation & Tooling: 2+ years of experience implementing security automation and integrating security tooling (e.g., SEIM, SAST/DAST, WIZ/ORCA, or other).
  • Automation/Scripting: 2+ years of experience with Python for automation and scripting in a security/DevSecOps context. Or, related development experience.
  • Git and GitOps: Practical experience and comfortable using Git and automated workflows for developing code securely.
  • Web Security Knowledge: Familiarity with web security best practices, including DNS, firewalls, secure APIs, and database security (e.g., PostgreSQL, MySQL).
  • Cloud Security: Proven ability to secure cloud environments, including implementing and managing security controls, auditing, and monitoring.
  • Communication & Collaboration: Exceptional written and verbal communication skills with the ability to explain complex security concepts to technical and non-technical audiences.
  • Track Record of Solutions: Demonstrated ability to identify and address security challenges, delivering effective solutions through collaboration and leadership.

Preferred Qualifications:

  • Regulated Environments: Experience working in environments with complex compliance requirements (e.g., PCI-DSS, SOC 2, ISO27001).
  • AWS Certifications: Relevant certifications such as AWS Certified Security – Specialty or AWS Certified Solutions Architect.
  • Web Security & Threat Detection: Hands-on experience with WAFs (e.g., AWS WAF, Cloudflare) and centralized logging stacks (e.g., Splunk, Kibana).
  • DevSecOps Expertise: Strong understanding of secure CI/CD practices and integrating compliance objectives into pipelines.
  • Infrastructure as Code (IaC): Experience with Terraform or CloudFormation for managing secure infrastructure.
  • Security Mentorship: Proven ability to mentor engineers and share security knowledge effectively.
  •  

Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.

Additional Information

As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.

If you are a qualified individual with a disability or a disabled veteran and require support throughout the application and/or recruitment process as a result of your disability, you have the right to request a reasonable accommodation. You can submit your request to [email protected].

NBCUniversal Glassdoor Company Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
NBCUniversal DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of NBCUniversal
NBCUniversal CEO photo
Jeff Shell
Approve of CEO

Average salary estimate

$115000 / YEARLY (est.)
min
max
$100000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Platform Security Engineer - NBC Sports Next, NBCUniversal

Are you ready to make a significant impact in the world of cloud security? Join NBC Sports Next as a Platform Security Engineer! In this exciting role, you'll be at the forefront of securing our engineering ecosystem, developing capabilities, services, and automating processes to maintain a balance between speed, scalability, and compliance. You'll take the lead in our DevSecOps roadmap, shaping the future of secure cloud infrastructures. If you’re passionate about designing scalable, secure cloud solutions and have a solid background in AWS security and CI/CD practices, we want to speak with you! Your main responsibilities will include driving security solutions across AWS cloud environments, enhancing secure CI/CD practices, and implementing reusable patterns to ensure compliance with critical standards. You'll collaborate closely with cross-functional teams, promoting knowledge sharing and security excellence. This remote position may require some travel, making it perfect for those looking to innovate and connect in a dynamic work environment. If you're eager to create a safer digital future for millions of sports fans and athletes worldwide while fostering a diverse and inclusive culture, don’t hesitate to apply today!

Frequently Asked Questions (FAQs) for Platform Security Engineer - NBC Sports Next Role at NBCUniversal
What are the responsibilities of a Platform Security Engineer at NBC Sports Next?

As a Platform Security Engineer at NBC Sports Next, your main responsibilities will include leading security efforts on AWS cloud, enhancing secure CI/CD pipelines, standardizing secure patterns, advancing secure software delivery, and collaborating with various teams to strengthen the organization's security posture. You'll also focus on compliance automation and support incident response, leveraging your skills in AWS, Terraform, and Python.

Join Rise to see the full answer
What qualifications are needed to become a Platform Security Engineer at NBC Sports Next?

To qualify for the Platform Security Engineer role at NBC Sports Next, candidates should have at least 2 years of hands-on experience with AWS, 4 years of experience managing and securing Linux systems, and knowledge of security automation tools. Familiarity with web security best practices and excellent communication skills are also essential to effectively collaborate across teams and explain complex concepts.

Join Rise to see the full answer
How does NBC Sports Next ensure compliance in the role of a Platform Security Engineer?

NBC Sports Next ensures compliance by requiring the Platform Security Engineer to design and implement reusable patterns that promote security best practices. The engineer will also develop automation strategies to enforce regulatory controls while ensuring continuous compliance with industry standards such as PCI-DSS, ISO27001, and SOC 2. Your role will be critical in reducing vulnerabilities and improving the overall security posture.

Join Rise to see the full answer
Is the Platform Security Engineer position at NBC Sports Next remote?

Yes, the Platform Security Engineer position at NBC Sports Next is fully remote. This means that you can contribute to the team from a non-NBCUniversal worksite, typically your home. However, the role may require some travel for team collaboration and meetings.

Join Rise to see the full answer
What tools and skills are important for a Platform Security Engineer at NBC Sports Next?

Important tools and skills for a Platform Security Engineer at NBC Sports Next include a solid understanding of AWS cloud services, experience with Terraform for infrastructure automation, and proficiency in Python for securing automation. Additionally, familiarity with security tools and practices, along with excellent communication skills, will help you succeed in this role.

Join Rise to see the full answer
Common Interview Questions for Platform Security Engineer - NBC Sports Next
Can you describe your experience with AWS security as a Platform Security Engineer?

When answering this question, detail your hands-on experience with AWS, emphasizing your understanding of IAM best practices and how you've secured resources such as EC2 and S3 in production environments. Provide concrete examples of challenges you've faced and the solutions you implemented.

Join Rise to see the full answer
How do you approach security automation in a DevSecOps context?

Discuss your strategies for integrating security into the CI/CD pipeline. Explain the tools you have used for automation, and provide an example of a successful implementation that streamlined security processes while maintaining compliance.

Join Rise to see the full answer
What best practices do you recommend for securing CI/CD pipelines?

Share best practices such as implementing code reviews, utilizing automated testing for security vulnerabilities, and emphasizing the principle of least privilege when granting access within the pipeline. Illustrate your points with past experiences to demonstrate effectiveness.

Join Rise to see the full answer
How do you ensure compliance with security standards?

Explain your method for designing security solutions that meet regulatory requirements. Discuss how you stay updated with industry standards and the tools you use for continuous compliance monitoring.

Join Rise to see the full answer
What steps do you take during an incident response?

Describe your approach to incident response, including preparation, identification, containment, eradication, recovery, and lessons learned. Use examples from previous experiences to illustrate your competency in handling security incidents.

Join Rise to see the full answer
Can you discuss your experience with container security?

When responding, highlight your work with containerization technologies such as ECS or Kubernetes. Mention any security best practices you’ve implemented, including image scanning and runtime monitoring.

Join Rise to see the full answer
How do you maintain effective communication with non-technical stakeholders?

Share your techniques for simplifying complex security concepts for diverse audiences. Provide examples of presentations or reports you’ve created that educated stakeholders while ensuring their understanding of security protocols.

Join Rise to see the full answer
What techniques do you use to promote security best practices among engineering teams?

Explain how you advocate for security best practices through training, workshops, and documentation. Share experiences where you successfully influenced engineering teams to adopt secure coding and operational practices.

Join Rise to see the full answer
How do you assess the security posture of an organization?

Outline your approach for performing security assessments, including vulnerability scanning, risk assessments, and gap analyses. Provide examples of how your assessments led to tangible improvements in organizational security.

Join Rise to see the full answer
What motivates you to work in platform security?

When addressing this question, express your passion for protecting systems and data. Discuss any personal experiences or professional achievements that inspire your commitment to security and innovation in technology.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 4 days ago
Photo of the Rise User
NBCUniversal Hybrid 12285 Pellicano Drive Suite C, El Paso, TEXAS
Posted 4 days ago
Photo of the Rise User
Experian Remote BLOCK-B, Cyber Pearl Building, 4th floor, Phase 2, Hyderabad, India
Posted 10 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Intelerad Remote Canada, Remote, Canada
Posted 14 days ago
Photo of the Rise User
OTIP Group of Companies (OGC) Remote 17704 103 Ave NW, Edmonton, AB T5S 1J9, Canada
Posted 5 days ago

We are in business to create and deliver content so compelling it entertains, informs and shapes our world. We believe that the talent, creativity and diversity of our people are our greatest resources. We take our business seriously, but do no...

885 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
January 14, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!