Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Infrastructure Security Engineer

$150k - $170k

Cast & Crew Entertainment Services

About Us

At Cast & Crew, we’ve empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies – we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production’s best ally every step of the way. #OneCastOneCrew

Position Overview

We are looking for an Infrastructure Security Engineer to run the operational core of our offensive and vulnerability management programs. You will own the tooling that continuously tests our environment — bug bounty, agentic red team, CSPM, and vulnerability scanners — turn the output of those platforms into a prioritized, de-duplicated set of real issues, and drive them to verified closure with engineering and infrastructure teams. This is a hands-on, highly cross-functional role for someone who is as comfortable validating an exploit as they are chasing a fix to completion.

We are also looking for someone who is genuinely curious and learns fast. Our security stack changes quickly, and a meaningful part of this role is exploring, testing, and deploying emerging security products — including tooling built on the latest AI capabilities — evaluating whether they actually work in our environment, and putting the ones that do into production.

​

Core Responsibilities
Bug Bounty Program
  • Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications.

  • Triage inbound submissions: reproduce and validate findings, de-duplicate against known issues, assign severity, and reject out-of-scope or invalid reports with clear rationale.

  • Make and defend bounty award decisions in coordination with the platform provider and Security leadership.

  • Route confirmed findings to the owning engineering or infrastructure team, track them to closure, and verify fixes before the report is closed.

  • Use recurring submission patterns to drive systemic fixes, scope adjustments, and secure-development feedback rather than one-off patches.

Vulnerability Scanning and Findings Triage
  • Manage and operate enterprise vulnerability scanners across cloud, on-premise, and hybrid assets, ensuring coverage of the full asset inventory and investigating scanning gaps.

  • Configure, tune, and maintain scan policies, credentialed scanning, authenticated checks, and scan schedules to maximize signal and minimize disruption.

  • Triage and prioritize findings using exploitability, asset criticality, and business context (e.g., CVSS, EPSS, CISA KEV, threat intelligence).

  • Assign findings to the correct engineering and infrastructure owners, negotiate remediation timelines, and verify remediation through re-scan or manual validation.

  • Track remediation against SLAs, escalate aging findings, and manage the exception and risk-acceptance process with the GRC team.

  • Produce metrics and reporting on coverage, backlog, mean time to remediate, and SLA compliance for engineering and executive audiences.

  • Monitor emerging CVEs, assess applicability to our environment, and coordinate emergency patching when critical vulnerabilities arise.

Cloud Security Posture Management (CSPM)
  • Manage and operate the CSPM platform across our multi-cloud environment, including onboarding new accounts, subscriptions, and projects.

  • Tune policies and baselines, suppress noise, and maintain exception handling so that surfaced findings are consistently actionable.

  • Drive remediation of misconfigurations with cloud and platform owners, and verify that fixes hold over time.

  • Enforce least-privilege access principles and audit cloud permissions, IAM policies, security groups, SCPs, and guardrails on a recurring basis.

  • Support secure architecture reviews for new cloud infrastructure and services.

Agentic Red Team and Continuous Penetration Testing Platform
  • Manage and operate the agentic red-team pentesting platform, including target scoping, scheduling, credentials, and environment onboarding.

  • Define and enforce rules of engagement and safety guardrails so that automated testing does not disrupt production systems.

  • Validate platform output, eliminate false positives, and translate confirmed attack paths into concrete, owner-assigned remediation items.

  • Feed results into the same triage, prioritization, and verification workflow used for scanner and bug bounty findings so there is one prioritized view of risk.

  • Coordinate with third-party penetration testers and use platform coverage to focus manual testing where it adds the most value.

Security Tooling Evaluation and Adoption
  • Research, pilot, and benchmark emerging security products, including AI-driven and agentic tooling, against real problems in our environment rather than vendor demos.

  • Run structured proofs of concept: define success criteria up front, test against known findings, and make a clear recommendation to adopt, defer, or reject.

  • Deploy and integrate selected tooling into existing workflows and ticketing, and own it operationally once it is in production.

  • Automate repetitive triage, enrichment, and reporting work so that engineering time goes to remediation rather than data handling.

Network and Perimeter Security
  • Support enterprise network security infrastructure including firewalls, IDS/IPS, proxies, VPNs, and DDoS mitigation.

  • Perform firewall rule reviews and access control audits to reduce attack surface.

  • Investigate anomalous network activity surfaced by security tooling and escalate to incident response as needed.

Key Qualifications
  • 3–5 years of experience in infrastructure, network, or cloud security roles.

  • Experience running or supporting an enterprise vulnerability management program end-to-end, from scanner operation through verified remediation.

  • Demonstrated ability to triage security findings: reproduce issues, judge real-world exploitability, de-duplicate, and prioritize against business context rather than raw severity scores.

  • Deep, practical understanding of common vulnerability classes and how they are actually exploited — remote code execution, injection, cross-site scripting, SSRF, insecure deserialization, authentication and authorization bypasses, and denial-of-service and DDoS techniques — sufficient to assess real exploitability rather than defer to a scanner score.

  • Hands-on proficiency with security testing tooling, including Burp Suite for web application testing and Postman for API testing, along with comparable intercepting proxies and fuzzing tools.

  • Working coding ability, primarily Python and shell scripting, sufficient to automate triage and reporting, parse and enrich findings, build integrations between security platforms, and write or adapt proof-of-concept code to validate a finding.

  • Hands-on experience securing at least one major cloud platform (AWS, Azure, or GCP), including operating or responding to CSPM tooling.

  • Solid understanding of network protocols (TCP/IP, DNS, TLS) and perimeter security technologies.

  • Familiarity with security frameworks and standards (NIST CSF, CIS Benchmarks, ISO 27001) and the ability to translate control requirements into actionable technical configurations, including gathering, maintaining, and presenting evidence to support audit and assessment activities.

  • Strong written and verbal communication skills, with the ability to translate technical risk for non-technical stakeholders and to hold remediation owners accountable without escalating every disagreement.

  • Demonstrated curiosity and speed of learning: a track record of picking up unfamiliar tooling, evaluating new security products, and getting them into production use without extensive hand-holding.

  • Interest in applying emerging AI capabilities to security operations, and the judgment to distinguish tooling that meaningfully reduces risk from tooling that only adds noise.

Preferred Qualifications
  • Experience operating or triaging a public or private bug bounty program on a platform such as HackerOne, Bugcrowd, or Intigriti.

  • Offensive security experience: penetration testing, exploit validation, or red-team operations, including familiarity with automated or agentic testing platforms.

  • Experience with infrastructure-as-code security (Terraform, CloudFormation) and shift-left security practices.

  • Experience securing containerized workloads, including image hardening, registry security, runtime protection, and familiarity with orchestration platforms such as Kubernetes or ECS.

  • Experience developing security automation or internal tooling beyond scripting, including work with security platform APIs and CI/CD integrations.

  • Exposure to SIEM/SOAR platforms and security telemetry pipelines.

  • Familiarity with zero trust network architecture (ZTNA) and micro-segmentation.

  • Relevant certifications: AWS Security Specialty, CCSP, CISSP, OSCP, CompTIA Security+, or equivalent.

Special Work Conditions
  • Sedentary - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time.

#LI-JM1

What We Offer 

Cast & Crew provides a comprehensive package of employee benefits including: Medical, Dental, Vision, PTO, health and wellness programs, employee discounts, and more! Note: Cast & Crew benefits are subject to eligibility requirements.

Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.

CA residents
Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies. A summary of your California privacy rights can be found at:

Compensation is commensurate with various factors including, but not limited to, relevant experience, qualifications, skills, training, licensure, certifications, geographic cost of labor, and other business and organizational needs. Compensation range for candidates in other locations may differ based on the cost of labor in that location. The compensation range for this position is: $150,000.00 - $170,000.00 per year.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Infrastructure Security Engineer in United States vacancy
  •  ...ICS/OT Cybersecurity Engineers and ICS/OT Network Security Engineers support clients in assessing, improving, and maintaining the cybersecurity...  ...if they are configured properly Deploying network infrastructure devices (e.g., switches, routers, etc.), security appliances... 
    Suggested
    Full time
    Work at office
    Remote work

    Logical Systems

    Golden, CO
    more than 2 months ago
  • $130k - $160k

     ...our outstanding work environments and opportunities for career growth and advancement.Our Technology team is seeking an Infrastructure Security Engineer to design, build, and secure the cloud, network, and identity infrastructure that runs a mixed-use real estate... 
    Suggested
    Full time
    Work experience placement

    JBG SMITH

    Bethesda, MD
    2 days ago
  • $198.4k - $342k

    We are seeking a highly technical Infrastructure Security Engineer to join our Public Sector Infrastructure & Security team. Our Infrastructure Security Engineers ensure the security and integrity of our platform. You will be responsible for securing large cloud environments... 
    Suggested
    Full time

    Scale AI

    New York, NY
    4 days ago
  •  ...of people and we’re just getting started.About The RoleOur Security Engineering team builds intelligent systems that protect Opendoor and...  ...engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter,... 
    Suggested
    Work at office
    Monday to Friday
    Shift work

    Opendoor

    Miami, FL
    1 day ago
  • $104k - $171.6k

    Job Classification:Technology - Engineering & CloudAre you interested in building capabilities that enable the organization with...  ...institutions. Your Team & RoleWe are looking for a motivated Senior Infrastructure Security Engineer to support the design, implementation and... 
    Suggested
    Full time
    Part time

    PGIM

    Newark, NJ
    4 days ago
  • $120k - $130k

    Job DescriptionEverforth ECS is seeking an Network & Security Infrastructure Engineer to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking an experienced and technically versatile Network & Security Infrastructure... 
    Work at office
    Remote work

    ECS Federal

    Washington DC
    4 days ago
  •  ...Infrastructure Security Engineer AI needs a new infrastructure layer. We're building it at Modal. Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the... 

    Modal

    New York, NY
    1 day ago
  •  ...remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv. Runway is hiring an Infrastructure Security Engineer to secure the platform our models are trained and served on. The role covers Kubernetes platform security, cloud... 
    Remote work

    Runway, Inc.

    United States
    1 day ago
  • $100k - $258k

     ...Infrastructure Security Engineer Austin, Texas; London, England, United Kingdom; New York, New York; Palo Alto, California; Washington, D.C. SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of... 
    Temporary work
    Relocation

    Xai

    New York, NY
    3 days ago
  •  ...To support a growing technology environment, the full-time Infrastructure Security Engineer will design, administer, and secure corporate and program-specific technology infrastructures while ensuring compliance with federal cybersecurity requirements, all in a fully... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  •  ...or pure transformer-only architectures, combining rigorous engineering with learning systems proven in globally deployed...  ...time our robots run in the field. About the Job The Infrastructure Security Engineer will secure the cloud infrastructure and deployment... 
    Local area

    FieldAI

    Irvine, CA
    1 day ago
  •  ...Infrastructure Security Engineer Social Discovery Group (SDG) is a group of social discovery companies. SDG solves the problems of loneliness, isolation, and disconnection - transforming virtual intimacy into the new normal. SDG's products redefine the way people interact... 
    Full time
    Work at office
    Remote work
    Work from home

    Social Discovery Group

    United States
    3 days ago
  • $60 - $75 per hour

    Malvern, PennsylvaniaHybridContract$60/hr - $75/hrA financial institution is looking to hire a Network Security Engineer to serve as the team's Palo Alto subject matter expert. You'll work with Palo Alto, Cisco firewalls, and Cisco ISE. Ideal candidates have strong experience... 
    Full time
    Temporary work
    Work from home
    Flexible hours

    Motion Recruitment

    Malvern, PA
    1 day ago
  • $174k - $255k

     ...tackling one of the world’s most important infrastructure challenges: helping the energy system...  ...experts in energy, AI, software engineering, and products to build tools that help...  ...mission here.About the role:As a Network Security Engineer within the Network Security pillar... 
    Full time
    Flexible hours

    X Company

    Mountain View, CA
    1 day ago
  • $98.4k - $160k

     ...grow, and make an impact. Join us!Job Description:The Network Security Engineer is responsible for supporting multiple security engineering...  ...RADIUS.Experience with Cisco Catalyst, Nexus, and wireless infrastructure.Experience with packet capture and protocol analysis using... 
    Full time
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America

    Washington DC
    2 days ago
  •  ...possible, with the ultimate goal of enabling human life on Mars.SECURITY ENGINEER (EMBEDDED & NETWORKING)SpaceX is looking for a Security...  ...organizations.Network security systems and the backend infrastructure that powers such services.Application level security controls... 
    Permanent employment
    Temporary work
    Remote work
    Weekend work

    SpaceX

    Hawthorne, CA
    3 days ago
  •  ...Infrastructure Security Engineer Location: Onsite in Lewes, DE and Rehoboth Beach, DE A well-established and growing organization is seeking an Infrastructure Security Engineer to play a key role in strengthening and advancing its enterprise security program. This... 

    Blue Signal Search

    Lewes, DE
    3 days ago
  •  ...Job Description Job Description Senior Infrastructure Security Engineer Why A‑Gas? At A‑Gas, what we do matters - every single day. We are a global leader in Lifecycle Refrigerant Management. We help industries reduce emissions, protect the environment, and transition... 
    Summer work
    Flexible hours

    A-Gas Americas

    Rhome, TX
    7 days ago
  •  ...About the Role: Select Minds LLC is looking for a talented Network Security Engineer to join our growing team in Dallas, TX. This is an exciting opportunity to protect critical infrastructure, design robust security solutions, and work alongside a team of passionate... 

    Select Minds LLC

    Dallas, TX
    12 days ago
  • $176k - $256k

     ...achieve significant organizational impact.Develop security framework, policies, standards and baselines for various infrastructures and network designs with the goal of...  ...qualifications:Bachelor's degree in Computer Science, Engineering, a related field, or equivalent practical... 
    Worldwide

    Google

    Austin, TX
    4 days ago
  • $105.4k - $124k

     ...develops multi-platform converged enterprise engineering solutions targeted to meet existing,...  ...platform solutions for business and infrastructure services. Leads, directs, or recommends...  ...access technologies, VPN solutions, and secure connectivity servicesUnderstanding of... 
    Full time
    Local area
    Remote work
    3 days per week

    US Bank

    Saint Paul, MN
    2 days ago
  •  ...financial institution based in Merrillville, IN is seeking a Senior IT Support Analyst responsible for managing network and server infrastructure. The role includes providing Tier 2/3 support, overseeing backups and disaster recovery, and collaborating with other... 
    Full time
    Remote work

    US #1364 Federal Credit Union

    Merrillville, IN
    4 days ago
  •  ...and transform millions of lives in the coming years. THE ROLE: We are seeking a highly motivated and adaptable engineer to own the infrastructure and security foundation that a fleet of wearable robots depends on. This means hardening our cloud and device infrastructure... 
    Full time
    Work at office
    Relocation

    Skip

    San Francisco, CA
    6 days ago
  • IT Infrastructure and Security Engineer Location: Naperville, Illinois (Hybrid) Role Overview This position is a hybrid role responsible for implementing and managing core technology infrastructure while ensuring the organization is protected against cyber threats.... 
    Work experience placement
    Shift work
    3 days per week

    Apex Systems

    Naperville, IL
    2 days ago
  • Cybersecurity Engineer Client's Technology and Product Security (TPS) is the core Cybersecurity team at Client. TPS is composed of a team of transformative security professionals expanding in multiple directions, across borders and, most of all, in the way we think. Here... 

    Samprasoft

    Moorestown, NJ
    2 days ago
  •  ...interview process will be initiated as soon as possible. We are excited to hear back from you. Job Description: Role: Infrastructure Security Engineer Schedule: Monday - Friday | 9 - 5 pm Location: Memphis, TN - Onsite Preferred will consider remote (as a secondary... 
    Hourly pay
    Contract work
    Immediate start
    Remote work
    Monday to Friday

    Syntricate Technologies

    Memphis, TN
    5 days ago
  •  ...Job Description Job Description Purpose of this role Reduce security risk and maintain patch compliance across Infrastructure Services using approved tooling and processes (Windows Server, Enterprise Linux, cloud/on‑prem, network devices, and assets in scope).... 

    All Lines Technology

    Hermitage, PA
    5 days ago
  •  ...Job Description:   Short Description:   Network Security Engineer  Complete Description: Employment Type: W2/ 1099...  ...security of the Client network and the supporting security infrastructure.  Duties & Responsibilities: Ability to monitor and... 
    Full time
    Contract work
    Remote work
    Worldwide

    AHU Technologies Inc

    Washington DC
    1 day ago
  •  ...Ada could be the place for you. Learn more at . Engineering at Ada As an Ada engineer, you’ll have the autonomy...  ...strive to improve, both as individuals and as a team. As a Security Infrastructure Engineer on Ada’s Security Operations team, your work will... 
    Permanent employment
    Full time
    Work experience placement
    Local area
    Remote work
    Work from home
    Flexible hours

    Ada

    Remote
    5 days ago
  •  ...Responsibilities Design and ship Kubernetes security controls covering admission policy,...  ...federation. Secure research infrastructure, training pipelines, model weights, and...  ...Rust, or another programming language for engineering tooling. Understanding of software supply... 
    Full time
    Remote work

    Runway

    Remote
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Infrastructure Security Engineer. Be the first to apply!