$87,000 – $104,000
Listed on CAA’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
A hands-on security role focused on delivering enterprise risk management and threat detection within an entertainment agency's Information Security group. The position suits someone with cybersecurity risk experience who can conduct vendor assessments, coordinate security integrations across cloud and on-premises systems, and help the organization maintain a defensible security posture.
Our summary, not CAA’s wording. The full posting is on their site.
Skills this role names
- Active Directory
- Amazon Web Services (AWS)
- Data Privacy Law (GDPR/CCPA)
- GDPR
- ITIL
- Jira
- Microsoft Azure
- Microsoft Office
- PCI DSS
- Security Assertion Markup Language (SAML)
- SoC System on Chip
- Splunk
Log in to see which of these are already on your profile.
What they ask for
Required
- 3-4 years of IT experience
- 2 years of cybersecurity risk management experience
- Bachelor's or Master's degree in a relevant field
- Strong analytical skills for vendor risk assessment and due diligence
- Familiarity with information security frameworks (NIST, ISO 27001)
- Familiarity with data privacy regulations (GDPR, CCPA)
- Familiarity with information security certifications and attestations (SOC, ISO, PCI DSS, FedRAMP)
- Experience coordinating technical integrations for security tooling
- Ability to review complex system architectures for security opportunities
- Can produce comprehensive written security assessments of vendor security posture
- Experience using security analytics tooling for operational metrics and dashboards
- Understanding of servers, operating systems, cloud applications, and infrastructure fundamentals
Nice to have
- Core cybersecurity fundamentals and third-party risk management skills
- Familiarity with third-party risk management tools (OneTrust, SIG, or similar GRC platforms)
- Hands-on experience with Azure and AWS cloud environments and core cloud services
- Familiarity with single sign-on concepts (PingFed, SAML)
- Familiarity with identity and access administration (Active Directory, Azure AD, AWS IAM)
- Familiarity with event management tools (Splunk)
- Expert-level proficiency with Microsoft Office and JIRA