Sr. Information Security Engineer
Funko is a purveyor of pop culture, making and selling license-focused collectibles. Based in Everett, WA, Funko holds hundreds of licenses for franchises ranging from Marvel to Harry Potter, creating tens of thousands of characters—one of the largest portfolios in the pop culture and collectibles industry. The company transforms favorite characters into collectible figures, with its most famous line, Pop! Vinyl, having millions of fans worldwide.
About the role
The Sr. Security Engineer will protect Funko’s cloud, application, and data environments as the business scales, acting as a subject matter expert across vulnerability management, application security, cloud security, AI security, and risk. This role is responsible for building and maturing Funko’s security engineering program and partnering closely with IT, development, and business teams to identify risk, close gaps, and build the tools and automation that let the security program scale.
This individual must be a highly effective communicator (both verbal and written) with excellent analytical and problem-solving skills. A builder’s mindset, the ability to design, automate, and scale security tooling and processes, and the capacity to multi-task and re-prioritize work in a dynamic, fast-paced environment are essential. The candidate should be a self-starter, performing day-to-day tasks with minimal supervision while collaborating effectively with cross-functional teams.
Responsibilities
- Own and mature Funko’s vulnerability management program across cloud, on-premises, and application environments, driving identification, prioritization, and remediation of risk.
- Build and maintain automated vulnerability scanning and reporting pipelines integrated into CI/CD and infrastructure provisioning workflows.
- Partner with engineering and infrastructure teams to track remediation SLAs, reduce mean-time-to-remediate, and manage risk acceptance exceptions.
- Own Funko’s application security program, including SAST/DAST/SCA tooling, secure code review, and secure SDLC guidance for development teams.
- Build automation and tooling that make secure coding practices frictionless for developers, embedding security checks directly into the pipelines they already use.
- Harden and continuously monitor Funko’s Azure and AWS environments, ensuring identity, network, storage, and logging configurations align with security best practices.
- Own cloud security posture management (CSPM) tooling and drive remediation of misconfigurations before they reach production.
- Build Infrastructure-as-Code guardrails and policy-as-code to catch security issues at the source rather than after deployment.
- Evaluate and secure AI and LLM-powered tools and workflows adopted across the business, addressing risks such as prompt injection, data leakage, and unauthorized model access.
- Develop practical guardrails, monitoring, and review processes that let Funko adopt AI safely without slowing the business down.
- Lead risk assessments for new vendors, applications, and cloud services, partnering with Legal, Privacy, and Compliance stakeholders.
- Perform threat modeling on new architectures and initiatives, ensuring security is designed in from the start rather than bolted on later.
- Maintain and continuously refine Funko’s risk register, working with business stakeholders to size, prioritize, and track risk to resolution.
- Design, build, and maintain custom security tooling, scripts, and integrations (Python, Terraform, APIs) that scale the security program without scaling headcount.
- Provide security incident response support, including detection, investigation, and post-mortem analysis to determine root cause and prevent recurrence.
- Review technical design documents and provide security guidance and sign-off on new systems and architecture.
- Provide cross-functional security leadership within IT, acting as a trusted advisor and partner to engineering, development, and business teams.
- Continually evaluate new security technologies and vendors, run pilots, and develop business cases to justify investment.
- Support audit and compliance efforts (e.g., SOC 2, PCI, GDPR/CCPA) by providing evidence, closing findings, and improving control maturity.
Requirements
- 5 years of experience in security engineering, information security, or related roles within enterprise environments.
- 3+ years of hands-on experience with vulnerability management platforms (e.g., Tenable, Qualys, Rapid7) and driving remediation across large, hybrid environments.
- 3+ years of experience with application security tooling and practices, including SAST/DAST/SCA (e.g., Checkmarx, Snyk, Semgrep, Veracode) and manual secure code review.
- Strong scripting and automation skills (Python, Terraform, Bash, PowerShell) with a demonstrated builder mindset—comfortable writing tools, not just running them.
- Experience building automation and integrations that scale security processes across engineering and IT teams.
- Experience securing multi-cloud environments (Azure and AWS), including IAM, network security, storage, logging, and CSPM tooling (e.g., Wiz, Prisma Cloud, Microsoft Defender for Cloud).
Qualifications
- Familiarity with AI/LLM security concepts and emerging threats (prompt injection, data leakage, model abuse, insecure plugin/tool use).
- Demonstrated experience leading risk assessments and threat modeling exercises for new vendors, applications, and architectures.
- Working knowledge of security frameworks and compliance requirements such as NIST CSF, SOC 2, PCI-DSS, or GDPR/CCPA.
- Advanced industry certifications such as CISSP, OSCP, CCSP, or GIAC (GPEN/GWAPT/GCLD), or comparable security certifications.
- Experience partnering with development teams to embed security into CI/CD pipelines and the software development lifecycle.
- Proven ability to evaluate solution designs, set technical security standards, and guide architecture decisions.
- Program management skillset—technical acumen, attention to detail, and operational follow-through.
- Strong, professional communication skills, both verbal and written, including translating technical risk into business terms for non-technical stakeholders.
- Vendor management experience leveraging SLA and KPI metrics to drive results.
- Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity, or other related field or equivalent work experience.
Pay
The base salary range for this position is $121,500–$151,500 annually. Compensation may vary outside of this range depending on qualifications, skills, competencies, experience, and location. Base pay is one part of the total package, which may include additional discretionary bonuses/incentives and restricted stock units.
Benefits
- Competitive compensation package with full benefits.
- 401(K) plan with matching contributions from the company.
- Creative work environment with colleagues who share a passion for pop culture.
Schedule
This is an onsite position based in Funko’s Burbank, CA or Everett, WA offices. Local candidates will be considered first.
Work Environment
The noise level in the work environment is usually moderate. While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; and talk or hear. The employee is frequently required to reach with hands and arms and occasionally required to stand and walk. The employee must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds.