Sr. Information Security Engineer

Technology Burbank, California Everett, Washington


Description

Funko Overview

Welcome to the Funko-verse, a world built on pure imagination, a land governed by the philosophy that stories matter, a universe comprised of characters from countless fandoms, a galaxy of once upon a times and happily ever afters.

But what does Funko do?

Funko is a purveyor of pop culture, making and selling license-focused collectibles. We’re based in Everett, WA where we have a store that delights kids of all ages (kids at heart included). We currently hold hundreds of licenses for franchises ranging from Marvel to Harry Potter, giving us the rights to create tens of thousands of characters—one of the largest portfolios in the pop culture and collectibles industry. We take your favorite characters and turn them into adorable, or sometimes scary, collectible figures. Our most famous line, Pop! Vinyl, has millions of fans around the world.

The primary role of the Sr. Security Engineer will be to protect Funko’s cloud, application, and data environments as the business scales, acting as a subject matter expert across vulnerability management, application security, cloud security, AI security, and risk. This role is responsible for building and maturing Funko’s security engineering program and partnering closely with IT, development, and business teams to identify risk, close gaps, and build the tools and automation that let the security program scale.

This individual must be a highly effective communicator (both verbal and written) and possess excellent analytical and problem-solving skills. A builder’s mindset, the ability to design, automate, and scale security tooling and processes rather than rely on manual effort, is essential.   Along with the ability to multi-task, organize, and re-prioritize work in a dynamic, fast-paced environment. The prospective candidate is a self-starter, performing day-to-day tasks with minimal supervision but working effectively with immediate and cross-functional team members.

Your Superpowers in Action

  • Own and mature Funko’s vulnerability management program across cloud, on-premises, and application environments, driving identification, prioritization, and remediation of risk
  • Build and maintain automated vulnerability scanning and reporting pipelines integrated into CI/CD and infrastructure provisioning workflows
  • Partner with engineering and infrastructure teams to track remediation SLAs, reduce mean-time-to-remediate, and manage risk acceptance exceptions
  • Own Funko’s application security program, including SAST/DAST/SCA tooling, secure code review, and secure SDLC guidance for development teams
  • Build automation and tooling that make secure coding practices frictionless for developers, embedding security checks directly into the pipelines they already use
  • Harden and continuously monitor Funko’s Azure and AWS environments, ensuring identity, network, storage, and logging configurations align with security best practices
  • Own cloud security posture management (CSPM) tooling and drive remediation of misconfigurations before they reach production
  • Build Infrastructure-as-Code guardrails and policy-as-code to catch security issues at the source rather than after deployment
  • Evaluate and secure AI and LLM-powered tools and workflows adopted across the business, addressing risks such as prompt injection, data leakage, and unauthorized model access
  • Develop practical guardrails, monitoring, and review processes that let Funko adopt AI safely without slowing the business down
  • Lead risk assessments for new vendors, applications, and cloud services, partnering with Legal, Privacy, and Compliance stakeholders
  • Perform threat modeling on new architectures and initiatives, ensuring security is designed in from the start rather than bolted on later
  • Maintain and continuously refine Funko’s risk register, working with business stakeholders to size, prioritize, and track risk to resolution
  • Design, build, and maintain custom security tooling, scripts, and integrations (Python, Terraform, APIs) that scale the security program without scaling headcount
  • Provide security incident response support, including detection, investigation, and post-mortem analysis to determine root cause and prevent recurrence
  • Review technical design documents and provide security guidance and sign-off on new systems and architecture
  • Provide cross-functional security leadership within IT, acting as a trusted advisor and partner to engineering, development, and business teams
  • Continually evaluate new security technologies and vendors, run pilots, and develop business cases to justify investment
  • Support audit and compliance efforts (e.g., SOC 2, PCI, GDPR/CCPA) by providing evidence, closing findings, and improving control maturity

Must-Have Superhero Gadgetry

  • 5 years of experience in security engineering, information security, or related roles within enterprise environments
  • 3+ years of hands-on experience with vulnerability management platforms (e.g., Tenable, Qualys, Rapid7) and driving remediation across large, hybrid environments
  • 3+ years of experience with application security tooling and practices, including SAST/DAST/SCA (e.g., Checkmarx, Snyk, Semgrep, Veracode) and manual secure code review
  • Strong scripting and automation skills (Python, Terraform, Bash, PowerShell) with a demonstrated builder mindset — comfortable writing tools, not just running them
  • Experience building automation and integrations that scale security processes across engineering and IT teams
  • Experience securing multi-cloud environments (Azure and AWS), including IAM, network security, storage, logging, and CSPM tooling (e.g., Wiz, Prisma Cloud, Microsoft Defender for Cloud)

Nice-to-Have Bonus Utility Belt

  • Familiarity with AI/LLM security concepts and emerging threats (prompt injection, data leakage, model abuse, insecure plugin/tool use)
  • Demonstrated experience leading risk assessments and threat modeling exercises for new vendors, applications, and architectures
  • Working knowledge of security frameworks and compliance requirements such as NIST CSF, SOC 2, PCI-DSS, or GDPR/CCPA
  • Advanced industry certifications such as CISSP, OSCP, CCSP, or GIAC (GPEN/GWAPT/GCLD), or comparable security certifications
  • Experience partnering with development teams to embed security into CI/CD pipelines and the software development lifecycle
  • Proven ability to evaluate solution designs, set technical security standards, and guide architecture decisions
  • Program management skillset — technical acumen, attention to detail, and operational follow-through
  • Strong, professional communication skills, both verbal and written, including the skill in translating technical risk into business terms for non-technical stakeholders
  • Vendor management experience leveraging SLA and KPI metrics to drive results
  • Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity or other related field or equivalent work experience

Salary Information

The base salary range for this position in the selected city is $121,500- $151,500 annually. Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.

What Funko Offers

Funko offers a competitive compensation package with full benefits and a 401(K) plan with matching contributions from the company. Most importantly, we offer a creative work environment with people who love pop culture just as much as you do. Can’t wait to gush about your latest binge? Neither can we! Looking for a place where your favorite pop culture t-shirt will receive the compliments it deserves? We know how you feel! 
 
Funko is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.

Work Environment

The noise level in the work environment is usually moderate. While performing the duties of this Job, the employee is regularly required to sit; use hands to finger, handle, or feel and talk or hear. The employee is frequently required to reach with hands and arms. The employee is occasionally required to stand and walk. The employee must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds.

This onsite position is based in our Burbank, CA or Everett, WA offices. Local candidates will be considered first. 

WHAT FUNKO OFFERS


 Funko offers a competitive compensation package with full benefits and a 401(K) plan with matching contributions from the company. Most importantly, we offer a creative work environment with people who love pop culture just as much as you do. Can’t wait to gush about your latest binge? Neither can we! Looking for a place where your favorite pop culture t-shirt will receive the compliments it deserves? We know how you feel!
 
 Funko is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.


The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities from time to time, as needed