Security Engineer
Job Summary:
Department Description:
At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world - a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - and we’re constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.
FOR GIS ONLY - DELETE IF NOT GIS
The Global Information Security (GIS) organization strives to secure the magic by employing best-in-class services to assess, prevent, detect, and respond to cyber threats that present risk to The Walt Disney Company. We enable the business by integrating enterprise and business segment-specific supported services to create a robust, efficient, and adaptable cybersecurity program. Our key objectives are to:
- Secure our information systems and platforms.
- Reduce risk through proactive assessment, prevention, and detection.
- Strengthen the business through optimized execution, application, and technology.
- Innovate by investing in core capabilities to enhance operational efficiency.
Team Description:
The Identity & Access Management (IAM) – Directory Services team is responsible for building and operating a secure, standardized, and automated enterprise identity foundation across The Walt Disney Company. We provide authoritative directory platforms that enable authentication, authorization, and access governance for both human and non-human identities.
Our mission is to move identity governance from manual, reactive processes to automated, policy-driven enforcement, ensuring identities are secure, compliant, and healthy by default across their lifecycle. We partner with security and infrastructure teams to reduce legacy risk and enable modern, cloud-first identity capabilities.
What You’ll Do:
Directory Platform Engineering & Operations
- Engineer, harden, and operate enterprise and multi-domain Active Directory environments supporting critical business workloads.
- Lead Active Directory consolidation and domain rationalization efforts.
- Support RadiantLogic’s Virtual Directory System operations and enhancements.
- Establish and enforce multi-domain baseline security standards.
- Implement and mature RBAC-based access models.
- Integrate AD with PIM and PAM platforms.
- Eliminate standing privilege through JIT access patterns.
- Implement synchronization between Active Directory and Entra ID.
- Support cross-tenant identity governance.
- Enable automated human and non-human identity governance.
- Reduce directory and tool sprawl.
- Mentor junior engineers and contribute to documentation.
Required Qualifications & Skills:
- 8+ years of hands-on experience with large-scale Active Directory environments.
- Deep expertise in Active Directory architecture, trusts, replication, DNS, PKI, multi-domain designs, security hardening, and Radiant Logic’s Virtual Directory Services.
- Proven experience implementing RBAC, PIM, PAM, and privileged account separation.
- Strong troubleshooting skills in complex, regulated environments.
- Experience in enterprise-scale IAM or directory services teams.
Preferred Qualifications:
- Experience with AD and Entra ID integration.
- Familiarity with identity governance automation and non-human identity management.
- Background in cross-tenant identity models.
- Experience with directory consolidation and legacy system sunset.
Required Education:
- Bachelor’s degree in a relevant field or equivalent experience.
Engineer, harden, and operate large-scale, multi-domain Active Directory environments.
Lead consolidation and rationalization efforts.
Support virtual directory services and baseline security standards.
Integrate with PIM/PAM and enforce Tier 0 controls.
Design synchronization with Entra ID.
Improve identity governance and lifecycle through automation and mentoring.
