Infrastructure Security Engineer
About Us
At Cast & Crew, weβve empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies β we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a productionβs best ally every step of the way. #OneCastOneCrew
Position Overview
We are looking for an Infrastructure Security Engineer to run the operational core of our offensive and vulnerability management programs. You will own the tooling that continuously tests our environment β bug bounty, agentic red team, CSPM, and vulnerability scanners β turn the output of those platforms into a prioritized, de-duplicated set of real issues, and drive them to verified closure with engineering and infrastructure teams. This is a hands-on, highly cross-functional role for someone who is as comfortable validating an exploit as they are chasing a fix to completion.
We are also looking for someone who is genuinely curious and learns fast. Our security stack changes quickly, and a meaningful part of this role is exploring, testing, and deploying emerging security products β including tooling built on the latest AI capabilities β evaluating whether they actually work in our environment, and putting the ones that do into production.
β
Core Responsibilities
Bug Bounty Program
-
Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications.
-
Triage inbound submissions: reproduce and validate findings, de-duplicate against known issues, assign severity, and reject out-of-scope or invalid reports with clear rationale.
-
Make and defend bounty award decisions in coordination with the platform provider and Security leadership.
-
Route confirmed findings to the owning engineering or infrastructure team, track them to closure, and verify fixes before the report is closed.
-
Use recurring submission patterns to drive systemic fixes, scope adjustments, and secure-development feedback rather than one-off patches.
Vulnerability Scanning and Findings Triage
-
Manage and operate enterprise vulnerability scanners across cloud, on-premise, and hybrid assets, ensuring coverage of the full asset inventory and investigating scanning gaps.
-
Configure, tune, and maintain scan policies, credentialed scanning, authenticated checks, and scan schedules to maximize signal and minimize disruption.
-
Triage and prioritize findings using exploitability, asset criticality, and business context (e.g., CVSS, EPSS, CISA KEV, threat intelligence).
-
Assign findings to the correct engineering and infrastructure owners, negotiate remediation timelines, and verify remediation through re-scan or manual validation.
-
Track remediation against SLAs, escalate aging findings, and manage the exception and risk-acceptance process with the GRC team.
-
Produce metrics and reporting on coverage, backlog, mean time to remediate, and SLA compliance for engineering and executive audiences.
-
Monitor emerging CVEs, assess applicability to our environment, and coordinate emergency patching when critical vulnerabilities arise.
Cloud Security Posture Management (CSPM)
-
Manage and operate the CSPM platform across our multi-cloud environment, including onboarding new accounts, subscriptions, and projects.
-
Tune policies and baselines, suppress noise, and maintain exception handling so that surfaced findings are consistently actionable.
-
Drive remediation of misconfigurations with cloud and platform owners, and verify that fixes hold over time.
-
Enforce least-privilege acces