ironquill.tech/board

$ cat jobs/infrastructure-security-engineer-cast-crew-7ccf53d3782b.json

Infrastructure Security Engineer

cast crew·US·United States·mid
Apply on himalayas → Get AI match score →
About Us At Cast & Crew, we’ve empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies – we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production’s best ally every step of the way. #OneCastOneCrew Position Overview We are looking for an Infrastructure Security Engineer to run the operational core of our offensive and vulnerability management programs. You will own the tooling that continuously tests our environment — bug bounty, agentic red team, CSPM, and vulnerability scanners — turn the output of those platforms into a prioritized, de-duplicated set of real issues, and drive them to verified closure with engineering and infrastructure teams. This is a hands-on, highly cross-functional role for someone who is as comfortable validating an exploit as they are chasing a fix to completion. We are also looking for someone who is genuinely curious and learns fast. Our security stack changes quickly, and a meaningful part of this role is exploring, testing, and deploying emerging security products — including tooling built on the latest AI capabilities — evaluating whether they actually work in our environment, and putting the ones that do into production. ​ Core Responsibilities Bug Bounty Program Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications. Triage inbound submissions: reproduce and validate findings, de-duplicate against known issues, assign severity, and reject out-of-scope or invalid reports with clear rationale.