> Markdown version of [/jobs/ext/1085150-principal-security-engineering-vulnerability](https://www.wearedevelopers.com/jobs/ext/1085150-principal-security-engineering-vulnerability). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal, Security Engineering & Vulnerability... - **Company:** Warner Bros. Discovery - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $177,170.0 - $329,030.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Data Security, Github, Identity and Access Management, Key Management, Online Service Provider, Open Web Application Security, Perforce, Secure Coding, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Data Logging, Software Security, Information Technology, Software Version Control, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 27, 2026 - **Apply:** https://www.juju.com/job/00000000gbxvtb ## About the Role + Executive presence, technical security expertise, business acumen, communication skills and alignment focus. + Bachelor's degree in computer science, Engineering, or other related discipline preferred or 10+ years of previous technical security experience. + 10+ years of supervisory or management experience in a technical security environment. + Strong technical engineering background, with the ability to engage credibly with software, infrastructure, and platform engineering teams on architecture, code, and operational decisions. + Demonstrated experience securing the software development lifecycle, including hands-on familiarity with source control and build platforms used in games and media production, particularly GitHub and Perforce, and the ability to embed security controls (SAST/DAST, secrets management, branch protections, CI/CD guardrails) directly into developer workflows. + Proven track record in vulnerability and threat remediation at scale, prioritizing exposures, driving root-cause fixes with engineering owners, and reducing time-to-remediate for both internet-facing and internal assets in fast-moving threat environments. + Should possess proficiency in the technical aspects of cyber security, such as: + Cloud infrastructure and concepts, specifically the security aspects thereof + Application security topics such as the OWASP top 10. + SIEM & logging tools + Vulnerability Management and EDR/XDR toolsets. + Network and Compute architectures + Identity & Access Management and Privileged Access Management + Solid knowledge of various regulatory requirements and information security control frameworks (ISO, NIST, PCI, GDPR, CCPA, SOX). + Strong understanding of audit/risk management methodologies and regulatory requirements pertaining to information security, privacy and/or data security. + Hands-on experience with security practices such as security incident response and risk management. + Exceptional verbal and written communication skills, specifically the ability to communicate within the context of the intended audience, whether that be senior executives or highly technical engineering resources. Good understanding of Industry trends and emerging threats. + Experience in leading projects leveraging global teams with matrix resources. + Extensive experience in the information security field designing and implementing enterprise security solutions in a global context. The Nice to Haves + Experience in providing Cybersecurity services and modeling for Media, Broadcast & Entertainment companies. + Security certifications are a plus (CISSP, CISM, CISA, SANS, etc.) ## Description The Principal, Security Engineering & Vulnerability Management for WB Games is a key leader within the Global Information and Content Security (GICS) team, implementing WBD's security strategy, policies, and standards across global WB Games operations. This critical role helps ensure timely, trustworthy, and fair-minded WB Games to audiences everywhere by driving the security of technical and digital operations. This Principal role is responsible for maintaining a strategic relationship with WB Games leadership, closely aligning WBD's cybersecurity strategy with our evolving WB Games strategy., Security Adoption + Act as the primary link between WB Games and WBD's centralized cybersecurity functions, ensuring security initiatives are aligned with business goals and priorities. + Lead the adoption and enforcement of Global Information and Content Security policies and standards across WB Games business lines. + Partner with GICS leadership to drive adoption of core security services (Identity and Access Management, Logging and Monitoring, Detection and Response, Vulnerability Management, Product Security, Cloud Security, and Content Security) throughout global WB Games operations. + Provide direction and supervision on security-related projects and initiatives, ensuring compliance with global security standards and best practices. + Support enterprise and business-line regulatory and compliance requirements, developing implementation strategies that minimize operational impact and disruption. + Foster a strong security culture and promote awareness, accountability, and technical security measures across WBD's global WB Games functions. Vulnerability and Threat + Lead the identification and reporting of key risk indicators (KRIs) for WB Games operations, driving analytics, metrics, and executive-level reporting to WBD leadership. + Drive vulnerability and threat remediation at scale across internet-facing and internal WB Games assets, partnering with engineering owners to prioritize exposures and reduce time-to-remediate. + Support security operations and incident response teams in the identification, investigation, and mitigation of cybersecurity incidents impacting WB Games. + Evaluate and recommend security solutions and tools that strengthen WB Games' detection, response, and remediation capabilities. + Handle security exceptions for global WB Games operations, ensuring proper documentation, approval, risk acceptance, and periodic review. Secure Development + Partner with WB Games engineering and studio teams to integrate security throughout the software development lifecycle across GitHub and Perforce-based workflows. + Drive adoption of secure development tooling and controls - including SAST, DAST, secrets management, dependency scanning, branch protections, and CI/CD guardrails - embedded directly into developer pipelines. + Champion secure-by-design principles and threat modeling across game studios, live-service platforms, and online services. + Lead application and product security reviews for new game launches, major releases, and live-service features prior to public exposure. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)