About the role
Funko Overview
Welcome to the Funko-verse, a world built on pure imagination, a land governed by the philosophy that stories matter, a universe comprised of characters from countless fandoms, a galaxy of once upon a times and happily ever afters.
But what does Funko do?
Funko is a purveyor of pop culture and licensed-focused collectibles company. Funko currently holds thousands of lenses and the rights to create tens of thousands of characters – one of the largest portfolios in the pop culture and collectibles industry. Funko’s Pop! Vinyl is the number one stylized vinyl collectible on the market, selling millions of figures to fans around the world.
We are seeking a highly skilled and experienced Senior Security Engineer to join our dynamic team. In this role, you will be responsible for designing, implementing, and maintaining robust security solutions for our on-premise and cloud-based infrastructure. The ideal candidate will have a deep understanding of information security principles, hands-on experience with various cloud platforms and tools, and a proactive approach to identifying and mitigating security risks. In this role you will optimize and normalize our existing security toolsets, as well as put forward new methodologies and process to analyze and act on this data.
What You’ll Do
- Cloud Security Architecture: Design, develop, and implement cloud security architecture and solutions to safeguard our environments. This includes defining security requirements, designing security controls, and integrating security best practices.
- Security Assessment & Compliance: Conduct security assessments, vulnerability scans, and penetration tests to identify and mitigate security risks. Ensure compliance with industry standards and regulatory requirements such as SOX, GDPR, HIPAA, PCI-DSS, etc.
- Identity & Access Management (IAM): Implement and manage robust IAM policies and controls to regulate access to cloud resources. This involves managing user identities, roles, permissions, and enforcing least privilege access principles.
- Provide oversight and assist the IT Operations team with the deployment and development of our Identity Management platform. Will assist in developing workflows, automations, and integrations to reduce risk and minimize our attack surface
- Security Automation & Orchestration: Develop scripts, automation tools, and workflows to automate security processes, enhance security incident response, and streamline security operations in cloud environments.
- Threat Detection & Incident Response: Monitor cloud infrastructure for security threats and anomalies. Update and maintain our Incident Response procedures to promptly address security incidents, investigate root causes, and implement corrective actions.
- Security Governance & Risk Management: Establish and maintain security governance frameworks, policies, and procedures. Conduct risk assessments, analyze security posture, and provide recommendations to mitigate risks effectively.
- Security Training & Awareness: Provide security training and awareness programs to educate staff on Cybersecurity Best-practices, emerging threats, and security policies. Foster a culture of security awareness across the organization.
- Collaboration & Communication: Provide direction to DevOps and traditional Development teams to mitigate current and future risk. Bring awareness to all Technology teams on security best-practices, emerging threats, and security policies.
- Work with our vCISO to participate with Risk Assessment and help advise with Executive/Board-Level reports.
- Perform and Review Security assessments for new SaaS, PaaS, and On-Prem solutions to be deployed
- Assist Data Privacy Office (DPO) with privacy compliance and accompanying regulatory standards.
What You’ll Bring
- Bachelor’s degree in Computer Science, Information Security, or related field. Master’s degree or relevant certifications (e.g., CISSP, CCSP, AWS Certified Security - Specialty) preferred.
- Proven experience (5+ years) in security engineering, specifically, designing and implementing security solutions for cloud platforms such as AWS, Azure, or Google Cloud Platform (GCP).
- Proven Experience operating and managing 3rd-party security assessment tools, MDR/XDR, SIEM solutions, and cloud-native security services.
- Foundational background with on-premise infrastructure: Active Directory, Windows Server, SQL Server, Windows/Mac/Linux desktops
- Solid understanding of Networking concepts: TCP/IP, Wireless, Storage Networks, SDWAN, VPCs, VPNs
- Strong understanding of cloud security principles, architectures, and services including IAM, network security, encryption, logging, monitoring, and compliance.
- Proficiency in scripting and automation using languages suc
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s