Infrastructure Security Engineer
$150k - $170kCast & Crew Entertainment Services
About Us
At Cast & Crew, we’ve empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies – we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production’s best ally every step of the way. #OneCastOneCrew
Position Overview
We are looking for an Infrastructure Security Engineer to run the operational core of our offensive and vulnerability management programs. You will own the tooling that continuously tests our environment — bug bounty, agentic red team, CSPM, and vulnerability scanners — turn the output of those platforms into a prioritized, de-duplicated set of real issues, and drive them to verified closure with engineering and infrastructure teams. This is a hands-on, highly cross-functional role for someone who is as comfortable validating an exploit as they are chasing a fix to completion.
We are also looking for someone who is genuinely curious and learns fast. Our security stack changes quickly, and a meaningful part of this role is exploring, testing, and deploying emerging security products — including tooling built on the latest AI capabilities — evaluating whether they actually work in our environment, and putting the ones that do into production.
Core Responsibilities
Bug Bounty Program
Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications.
Triage inbound submissions: reproduce and validate findings, de-duplicate against known issues, assign severity, and reject out-of-scope or invalid reports with clear rationale.
Make and defend bounty award decisions in coordination with the platform provider and Security leadership.
Route confirmed findings to the owning engineering or infrastructure team, track them to closure, and verify fixes before the report is closed.
Use recurring submission patterns to drive systemic fixes, scope adjustments, and secure-development feedback rather than one-off patches.
Vulnerability Scanning and Findings Triage
Manage and operate enterprise vulnerability scanners across cloud, on-premise, and hybrid assets, ensuring coverage of the full asset inventory and investigating scanning gaps.
Configure, tune, and maintain scan policies, credentialed scanning, authenticated checks, and scan schedules to maximize signal and minimize disruption.
Triage and prioritize findings using exploitability, asset criticality, and business context (e.g., CVSS, EPSS, CISA KEV, threat intelligence).
Assign findings to the correct engineering and infrastructure owners, negotiate remediation timelines, and verify remediation through re-scan or manual validation.
Track remediation against SLAs, escalate aging findings, and manage the exception and risk-acceptance process with the GRC team.
Produce metrics and reporting on coverage, backlog, mean time to remediate, and SLA compliance for engineering and executive audiences.
Monitor emerging CVEs, assess applicability to our environment, and coordinate emergency patching when critical vulnerabilities arise.
Cloud Security Posture Management (CSPM)
Manage and operate the CSPM platform across our multi-cloud environment, including onboarding new accounts, subscriptions, and projects.
Tune policies and baselines, suppress noise, and maintain exception handling so that surfaced findings are consistently actionable.
Drive remediation of misconfigurations with cloud and platform owners, and verify that fixes hold over time.
Enforce least-privilege access principles and audit cloud permissions, IAM policies, security groups, SCPs, and guardrails on a recurring basis.
Support secure architecture reviews for new cloud infrastructure and services.
Agentic Red Team and Continuous Penetration Testing Platform
Manage and operate the agentic red-team pentesting platform, including target scoping, scheduling, credentials, and environment onboarding.
Define and enforce rules of engagement and safety guardrails so that automated testing does not disrupt production systems.
Validate platform output, eliminate false positives, and translate confirmed attack paths into concrete, owner-assigned remediation items.
Feed results into the same triage, prioritization, and verification workflow used for scanner and bug bounty findings so there is one prioritized view of risk.
Coordinate with third-party penetration testers and use platform coverage to focus manual testing where it adds the most value.
Security Tooling Evaluation and Adoption
Research, pilot, and benchmark emerging security products, including AI-driven and agentic tooling, against real problems in our environment rather than vendor demos.
Run structured proofs of concept: define success criteria up front, test against known findings, and make a clear recommendation to adopt, defer, or reject.
Deploy and integrate selected tooling into existing workflows and ticketing, and own it operationally once it is in production.
Automate repetitive triage, enrichment, and reporting work so that engineering time goes to remediation rather than data handling.
Network and Perimeter Security
Support enterprise network security infrastructure including firewalls, IDS/IPS, proxies, VPNs, and DDoS mitigation.
Perform firewall rule reviews and access control audits to reduce attack surface.
Investigate anomalous network activity surfaced by security tooling and escalate to incident response as needed.
Key Qualifications
5+ years of experience in infrastructure, network, or cloud security roles.
Experience running or supporting an enterprise vulnerability management program end-to-end, from scanner operation through verified remediation.
Demonstrated ability to triage security findings: reproduce issues, judge real-world exploitability, de-duplicate, and prioritize against business context rather than raw severity scores.
Deep, practical understanding of common vulnerability classes and how they are actually exploited — remote code execution, injection, cross-site scripting, SSRF, insecure deserialization, authentication and authorization bypasses, and denial-of-service and DDoS techniques — sufficient to assess real exploitability rather than defer to a scanner score.
Hands-on proficiency with security testing tooling, including Burp Suite for web application testing and Postman for API testing, along with comparable intercepting proxies and fuzzing tools.
Working coding ability, primarily Python and shell scripting, sufficient to automate triage and reporting, parse and enrich findings, build integrations between security platforms, and write or adapt proof-of-concept code to validate a finding.
Hands-on experience securing at least one major cloud platform (AWS, Azure, or GCP), including operating or responding to CSPM tooling.
Solid understanding of network protocols (TCP/IP, DNS, TLS) and perimeter security technologies.
Familiarity with security frameworks and standards (NIST CSF, CIS Benchmarks, ISO 27001) and the ability to translate control requirements into actionable technical configurations, including gathering, maintaining, and presenting evidence to support audit and assessment activities.
Strong written and verbal communication skills, with the ability to translate technical risk for non-technical stakeholders and to hold remediation owners accountable without escalating every disagreement.
Demonstrated curiosity and speed of learning: a track record of picking up unfamiliar tooling, evaluating new security products, and getting them into production use without extensive hand-holding.
Interest in applying emerging AI capabilities to security operations, and the judgment to distinguish tooling that meaningfully reduces risk from tooling that only adds noise.
Preferred Qualifications
Experience operating or triaging a public or private bug bounty program on a platform such as HackerOne, Bugcrowd, or Intigriti.
Offensive security experience: penetration testing, exploit validation, or red-team operations, including familiarity with automated or agentic testing platforms.
Experience with infrastructure-as-code security (Terraform, CloudFormation) and shift-left security practices.
Experience securing containerized workloads, including image hardening, registry security, runtime protection, and familiarity with orchestration platforms such as Kubernetes or ECS.
Experience developing security automation or internal tooling beyond scripting, including work with security platform APIs and CI/CD integrations.
Exposure to SIEM/SOAR platforms and security telemetry pipelines.
Familiarity with zero trust network architecture (ZTNA) and micro-segmentation.
Relevant certifications: AWS Security Specialty, CCSP, CISSP, OSCP, CompTIA Security+, or equivalent.
Special Work Conditions
Sedentary - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time.
#LI-JM1
We take care of our people.
When you join Cast & Crew, you're backed by a benefits package built around what matters most. From comprehensive medical, dental, and vision coverage, to a 401(k) match, generous PTO, paid parental leave, health and wellness programs, tuition reimbursement, and employee discounts. We’re committed to helping you thrive, professionally, and personally.
Benefits are subject to eligibility requirements.
Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.
CA residents
Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies. A summary of your California privacy rights can be found at:
- ...remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv. Runway is hiring an Infrastructure Security Engineer to secure the platform our models are trained and served on. The role covers Kubernetes platform security, cloud...SuggestedRemote work
- ...To support a growing technology environment, the full-time Infrastructure Security Engineer will design, administer, and secure corporate and program-specific technology infrastructures while ensuring compliance with federal cybersecurity requirements, all in a fully...SuggestedFull timeRemote work
- We are looking for an experienced Security Network Engineer to support and strengthen a data center environment in California. This long-term... ...who brings deep expertise in secure network operations, infrastructure monitoring, and enterprise firewall administration. The role...SuggestedLong term contractRemote work
- ...About The Role Our Security Engineering team builds intelligent systems that protect Opendoor and our customers while enabling unprecedented... ...and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter,...SuggestedWork at officeMonday to FridayShift work
- ...Ada could be the place for you. Learn more at . Engineering at Ada As an Ada engineer, you’ll have the autonomy... ...strive to improve, both as individuals and as a team. As a Security Infrastructure Engineer on Ada’s Security Operations team, your work will...SuggestedPermanent employmentFull timeWork experience placementLocal areaRemote workWork from homeFlexible hours
$165k - $250k
...company that isn't just moving fast, but rewriting what fast looks like. Role Overview We're looking for a hands-on Infrastructure Security Engineer to own security across our cloud and ML infrastructure — the platform that trains our models and serves millions of...Work at officeImmediate startRemote workWorldwide3 days per week- ...Job Description Job Description Description: Summary: The Infrastructure & Security Engineer is a hands-on individual contributor with responsibilities split approximately evenly between infrastructure engineering and operations, and cybersecurity engineering...Remote workFlexible hours
$165k - $215k
...innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization...Temporary workWork at officeLocal areaRemote work- ...: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building... ...-house AI/ML infrastructure. Built by engineers, for engineers. From large-scale GPU... ...hardware, software and AI R&D. Infrastructure security Infrastructure is a special type of “...Full time
$147k - $210k
Identify security issues and implement and design security controls, tools, and services to improve security systems and processes... ...binaries.Provide subject matter expertise to Platform Infrastructure Engineering (PIE) teams designing and developing the next-generation...$160k - $190k
...Staff Security Engineer, Network Security Houston; New York; San Francisco; Seattle About Nscale Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables...Work at officeLocal areaRemote workFlexible hours- ...Description Job Description: Short Description: Network Security Engineer Complete Description: Employment Type: W2/ 1099... ...security of the Client network and the supporting security infrastructure. Duties & Responsibilities: Ability to monitor and...Remote workWork from homeFlexible hours
$86.8k - $198k
Cloud Security EngineerThe Opportunity:Everyone is trying to “harness the cloud”, but not everyone knows how to secure it. As a Microsoft Purview Data Protection Engineer, you know how to design, implement, and automate enterprise data‑protection capabilities that safely...Full timeContract workPart timeLocal areaRemote work$272k - $431.25k
...Securing NVIDIA’s EDA clusters is not a matter of deploying the standard security stack. These workloads are too... ...apply. That constraint is the job. We’re hiring an engineering leader to build and run Infrastructure Security Engineering for EDA Clusters: the team responsible...Full timeRemote work$112.9k - $257k
Elastic Cloud Security EngineerThe Opportunity:Designs, implements, integrates, and maintains systems and tools to automate complex cyber activities. Applies leading-edge principles, theories, and concepts. Contributes to the development of new principles and concepts....Full timeContract workPart timeWork at officeLocal areaRemote work$91k - $152k
Come join a security team who focuses on ease of use and delighting our customers to build... ...security into the cloud and Amazon infrastructure from the minute a server hits our data... ...services. At Amazon, we are looking for engineers who know how to think through a problem...Work at officeWork from homeFlexible hours- ...The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers... ...CISO team, the purpose of Cloud Security Engineering team is to provide outstanding and...Remote workFlexible hours
$110k - $145k
...has grown into a trusted enterprise solution that helps IT and Security teams automate, manage, deploy, and report on third-party updates... .... About this Role: We're hiring a Cloud Security Engineer to strengthen and operate our Microsoft cloud security stack. This...Remote work- ...Opportunity One of our clients is seeking a qualified Cloud Security Engineer to join its cybersecurity team. This position offers the... ...policies, standards, and procedures. Collaborate with infrastructure, DevOps, and application teams to embed security into cloud...Contract workRemote work
$86k - $112k
...Cloud Security Engineer Location: Remote, USA Employment Type: Full-Time Benefits Offered: Vision, Medical, Life, Dental,... ...experience). ~3+ years of experience securing cloud-based infrastructure, services and technologies. ~ Experience identifying,...Full timeTemporary workWork experience placementRemote work$208k - $312k
# Security Engineer, CloudReview the role, location requirements, compensation details, and application process before deciding whether... ...protecting its cloud-native platform. The role centers on infrastructure hardening, infrastructure-as-code, policy enforcement, service...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours$120k - $130k
...support Connected Logistics is seeking a Mid-Level Cloud Security Engineer to support the Cybersecurity Architecture and Engineering... ...and operational reporting. Collaborate with cloud, infrastructure, application, and cybersecurity teams to integrate...Contract workWork at officeRemote work- ## Cloud Security EngineerApply: Remote-United States: Full time: Posted 2 Days Ago: JR... ...focus to the business. The Cloud Security Engineer designs, implements, and enforces cloud... ...partners closely with Cloud Engineers, Infrastructure Security Engineers, and operations...Full timeWork at officeRemote workHome office
$161k - $194k
...Ireland. Come join us! About the Role As a Senior Cloud Security Engineer you’ll be working to improve the security of AlphaSense’s... ...have solid experience with containerised environments, infrastructure as code and Kubernetes across a multi-cloud (AWS and GCP) estate...Local areaRemote work- ...Job Purpose The Senior Cloud Security Engineer will design, implement, and maintain security controls across our multi-cloud environment... ...to improve visibility and incident response Build Infrastructure-as-Code (Terraform, CloudFormation, Bicep), Policy-as-Code,...Work at officeLocal areaRemote work
- ...Relevance is seeking a Senior AWS Cloud Security Consultant to help design remotely and... ...of cloud security architecture, policy engineering, and AWS governance, with a primary focus... ...cloud engineering, cloud security, or infrastructure security experience. ~ Deep expertise...Full timeRemote work
- ...Our direct client has an opening for a Sr Cloud Network/Security Engineer position # 759936. This position is for 12+ months, with option... ...include but are not limited to: Troubleshooting cloud infrastructure issues related to networking and security. Building highly...Hourly payImmediate startRemote work
$162k - $200k
...for someone with 5+ years of experience in cloud network engineering and security. We need hands-on experience with hybrid cloud connectivity... ...subnets, and load balancers. We need proficiency with Infrastructure as Code tools and frameworks such as Terraform and...Full timeWork at officeWork from homeWorldwideFlexible hours- ...solutions for the federal government by securing and managing data, providing scalable... ...NIH production systems. Deep hands-on engineering experience is still essential. Responsibilities... ...technology/IoT device segmentation. Infrastructure-as-code (Terraform, CloudFormation) and...Work at officeLocal areaRemote work2 days per week1 day per week
- ...Job Description Job Description Cloud Security Engineer Location: Atlanta, GA Employment Type: Full Time Position Overview... ...a professionalwith hands-on expertise in Azure Cloud infrastructure, cloud security solutions, and compliance frameworks. The Cloud...Full timeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Infrastructure Security Engineer. Be the first to apply!
- security infrastructure engineer Remote
- principal infrastructure engineer Remote
- data infrastructure engineer Remote
- infrastructure engineer Remote
- remote infrastructure engineer Remote
- senior infrastructure engineer Remote
- infrastructure developer Remote
- infrastructure engineering manager Remote
- dlp security engineer Remote
- application security engineer Remote




