Job Description
THE AGENCY
Creative Artists Agency (CAA) is a leading entertainment and sports agency, with globalexpertisein filmed and live entertainment, digital media, publishing, sponsorship sales and endorsements, media finance, consumer investing, fashion, brand management and consumer product licensing, and philanthropy. Distinguished by its culture of collaboration and exceptional client service, CAA’s diverse workforceidentifies, innovates, and amplifies opportunities for the people and organizations that shape culture and inspire the world.
The trailblazer of the agency business, CAA was the first to build a sports business, create an investment bank, launch a venture fund, found technology start-up companies, establish a philanthropic arm, build a business in China, form brand marketing services division, and launch a family office advisory practice, among other innovations. Named Most Valuable Sports Agency by for 10 consecutive years, CAA represents more than 3,000 of the world’s top athletes in football, baseball, basketball, hockey, and soccer, in addition to coaches, on-air broadcasters, and sports personalities and works in the areas of property sales and sponsorships, media advisory, brand consulting, venue development and strategic advisory, and executive search.
OVERVIEW
This is a hands-on security position working within the Information Security group and with the internal IT department. This position’s core focus is to ensure consistent, measurable end-to-end delivery of security services. The successful candidate will work to develop and deploy capabilities, ensuring enterprise systems and data are protected with the security controls and toolsrequiredto meet policy and compliance requirements.
We are looking for candidates who have a passion for cyber security, threat detection, risk mitigation, and response. You will be a key part of our efforts to build and support a defensible environment where we are able to detect,containand respond quickly to threats and compromise in ways that serve to enable the business needs of a highly collaborative organisation. The environment is fast-paced andcommonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practice.
Responsibilities to include:
1. Define and evolve security tooling aligned to cybersecurity architecture and risk objectives
2. Evaluate new and emerging threats against existing security controls; ensuring controlsremaineffective to meet business objectives
3. Translate threat intelligence and risk assessments into engineering roadmaps
4. Review the designs of proposed major applications and upgrades for compliance with security architecture; deliver cross team security integration capabilities
5. Play an active role in CAA’s security incident response efforts, working toidentifyand mitigate information security threats
6. Use input from IRM leadership and key security metrics to ensure technical security controls are meeting desiredobjectives; implement a process of continual review and improvement to ensure the measurable effectiveness of CAA’s technical controls and security tooling
7. Support a security engineering culture focused on ownership and outcomes
QUALIFICATIONS/REQUIREMENTS
8. At least10 years in Information Technology, ideally with a mixed focus on infrastructure and development projects and services
9. At least2 years’ experience in information security
10. Abachelor’s or master’sDegree in a relevant field of work
11. Experience scripting in at least one of the following languages: PowerShell, Python, JavaScript
12. Experience supporting the implementation and operation of security tooling in the following areas: Zero Trust Access and Network Segmentation, Public Key Infrastructure (public and private), Endpoint and Workload Protection, Web Application Firewalls, Secure Email Gateways and Filters, Cloud Security, Secure DNS
13. Large-scale SIEM or security data lake implementations
14. A strong understanding of the fundamental operations of servers, operating systems, networks, cloud services, and infrastructure
15. An expert understanding of the key controls required for secure operation of these systems
16. Experience working in an Azure environment and/or strong knowledge of the Azure cloud environment
17. Demonstrated an organized and methodical approach to making improvements on past organizations security programs.
18. Has designed andmaintainedcontrols to support the secure delivery of applications through continuous development and continuous integration processes
19. Has built and managed frameworks to test andvalidatethe effective operation of security controls; measuring the ability to stop threats and attacks at the earliest point in the kill chain
20. Background working within or implementing a secure development lifecycle
Please ensure you provide complete and legible information in your application. An incomplete application may affect your consideration for employment.Creative Artists Agency (“CAA”) is committed to promoting equal opportunities in employment and creating a workplace culture in which diversity and inclusion is valued and everyone is treated with dignity and respect. As part of our zero-tolerance approach to discrimination in any form, you and any job applicants will receive equal treatment regardless of age, disability, gender reassignment, marital or civil partner status, pregnancy or maternity, race, colour, nationality, ethnic or national origin, religion or belief, sex or sexual orientation, or any other legally recognised protected basis under UK law.Please inform CAA’s Recruitment Department if you need any assistance completing any forms or to otherwise participate in the application process.CAA does not accept unsolicited resumes from third-party recruiters unless they were contractually engaged by CAA to provide candidates for a specified opening. Any such employment agency, person or entity that submits an unsolicited resume does so with the acknowledgement and agreement that CAA will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person or entity.