Application Security Engineer

600 UMG Recordings Inc

Tennessee

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Universal Music Group seeks an Application Security Engineer to enhance security across internal apps and cloud services. You will partner with engineering, infrastructure, and product teams to embed secure practices throughout the software lifecycle.

The role requires hands‑on testing (SAST/DAST/SCA), secure coding guidance, and security design reviews in a dynamic, global environment. Collaboration with DevOps is essential.

Qualifications

  • Bachelor’s degree in CS, Information Security, Engineering, or equivalent practical experience.
  • 5+ years in Application Security or related field.
  • Experience with SAST/DAST/SCA and API security testing.
  • Knowledge of OWASP Top10 and secure coding practices.
  • Experience CI/CD/DevSecOps integrations.
  • Experience with AWS/Azure/GCP environments.

Responsibilities

  • Perform application security assessments, threat modeling, and secure design reviews for internal and third‑party apps.
  • Conduct SAST/DAST/SCA and API security testing; validate findings.
  • Review source code and provide secure coding guidance based on OWASP.
  • Partner with engineering teams to identify risks and remediation strategies.
  • Integrate security testing into CI/CD pipelines and delivery workflows.
  • Provide security architecture guidance for new apps, APIs, and cloud services.
  • Support investigations and remediation of application‑layer incidents and vulnerabilities.
  • Develop reusable security guidance and technical documentation for engineers.

Skills

Security assessments
Threat modeling
Secure coding
CI/CD security
DevSecOps
Cloud security
Collaboration

Education

Bachelor’s degree in CS/Info Security/Engineering

Tools

SAST
DAST
SCA
API security testing
OWASP tools
Burp Suite
Checkmarx/Veracode/GitHub Advanced Security

Job description

We are UMG, the Universal Music Group, the world’s leading music company that operates across more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most acclaimed and commercially successful music worldwide.

We are currently seeking an Application Security Engineer to join UMG’s global Tech Security & Identity organization. Reporting to the Manager, Security Engineering and Vulnerability, you will improve the security of internally developed applications and cloud services by partnering closely with engineering, infrastructure, and product teams.

Responsibilities
  • Perform application security assessments, threat modeling, and secure design reviews for internally developed and third‑party applications.
  • Conduct application security testing using static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), API security testing, and manual validation techniques.
  • Review source code and provide secure coding guidance based on OWASP best practices and secure development principles.
  • Partner with software engineering teams to identify security risks and recommend practical remediation strategies throughout the software development lifecycle.
  • Collaborate with DevOps teams to integrate application security testing into CI/CD pipelines and software delivery workflows.
  • Provide security architecture guidance for new applications, APIs, cloud‑native services, and technology integrations.
  • Support implementation of modern authentication and authorization technologies, including OAuth, OpenID Connect (OIDC), SAML, and other identity standards.
  • Evaluate, implement, and maintain application security tools and help improve security testing coverage across the development lifecycle.
  • Develop automation and scripting to improve application security testing, reporting, and engineering workflows.
  • Participate in security reviews for new technologies, cloud services, and third‑party applications.
  • Support investigation and remediation of application‑layer security incidents and vulnerabilities when required.
  • Create reusable security guidance, reference architectures, and technical documentation to improve secure development practices across engineering teams.
  • Deliver secure coding guidance and developer education to promote security‑by‑design principles.
  • Collaborate with security, infrastructure, and identity teams to continuously improve enterprise application security capabilities.
Qualifications
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • 5+ years of experience in Application Security, Security Engineering, Software Engineering, or a related discipline with a security focus.
  • Experience performing application security assessments, threat modeling, and secure architecture reviews.
  • Strong understanding of secure coding principles and common application vulnerabilities, including the OWASP Top10 and OWASP API Security Top10.
  • Experience with application security testing technologies including SAST, DAST, SCA, API security testing, and penetration testing methodologies.
  • Experience working with modern application architectures, REST APIs, microservices, and cloud‑native technologies.
  • Experience integrating security into CI/CD pipelines and DevSecOps workflows.
  • Experience working within AWS, Azure, or Google Cloud Platform environments.
  • Knowledge of modern authentication and authorization technologies including OAuth, OpenID Connect (OIDC), SAML, and JWT.
  • Understanding of security frameworks and standards including OWASP, NIST Cybersecurity Framework, and ISO27001.
  • Strong analytical, problem‑solving, and communication skills with the ability to work effectively across technical and non‑technical teams.
Desired Qualifications
  • Experience implementing Secure Software Development Lifecycle (SSDLC) practices within Agile development environments.
  • Experience with application security platforms such as GitHub Advanced Security, Microsoft Defender for Cloud, Checkmarx, Veracode, Burp Suite, Semgrep, or similar tools.
  • Experience with container security, Kubernetes, and Infrastructure as Code security.
  • Experience developing automation using Python, PowerShell, or similar scripting languages.
  • Experience performing security assessments of cloud‑native applications and APIs.
  • Professional certifications such as CSSLP, GIAC GWEB, AWS Certified Security Specialty, Security+, CISSP, or equivalent.
  • Experience working within large global enterprise environments.
  • Experience in media, entertainment, or similarly distributed global organizations.

Universal Music Group is an Equal Opportunity Employer. We are an E‑Verify employer in Alabama, Arizona, Georgia, Mississippi, North Carolina, South Carolina, Tennessee, and Utah. Universal Music Group is not enrolled in E‑Verify in California and New York, and cannot support employment of candidates whose employer must enroll in E‑Verify, for example candidates on STEM‑OPT.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Universal Music Group • Nashville (TN)

On-site
USD 120,000 - 150,000
Medical, dental, vision coverage
Fertility coverage
Wellbeing reimbursements
Application Security Engineer — Cloud & DevSecOps
Application Security Engineer — Cloud & DevSecOps

600 UMG Recordings Inc • Tennessee

On-site
USD 90,000 - 130,000
Application Security Engineer: Secure SDLC & Cloud
Application Security Engineer: Secure SDLC & Cloud

Universal Music Group • Nashville (TN)

On-site
USD 120,000 - 150,000
Medical, dental, vision coverage
Fertility coverage
Wellbeing reimbursements
Identity Access Management (IAM) Engineer – Identity Governance and Administration
Identity Access Management (IAM) Engineer – Identity Governance and Administration

600 UMG Recordings Inc • United States

On-site
USD 90,000 - 130,000
Comprehensive medical, dental, vision, and mental health coverage
401(k) plan with 100% immediate vesting
Flexible paid time off
+2
Sr. Identity Access Management Architect
Sr. Identity Access Management Architect

600 UMG Recordings Inc • United States

On-site
USD 130,000 - 160,000
Comprehensive medical, dental, and vision coverage
Wellbeing reimbursements for fitness and travel
401(k) with immediate vesting and additional contributions
Identity Access Management (IAM) Engineer – Identity Governance and Administration
Identity Access Management (IAM) Engineer – Identity Governance and Administration

Universal Music Group • United States

On-site
USD 101,000 - 145,000
Comprehensive medical, dental, andvis
Wellbeing reimbursements and wellness
401(k) with immediate vesting
+1
Sr. Identity Access Management Architect
Sr. Identity Access Management Architect

Universal Music Group • Nashville (TN)

On-site
USD 164,000 - 200,000
Comprehensive medical, dental, and vision coverage
Flexible Paid Time Off (PTO)
401(k) with immediate vesting
+2
Identity Access Management (IAM) Engineer – Identity Governance and Administration
Identity Access Management (IAM) Engineer – Identity Governance and Administration

Universal Music Group • Nashville (TN)

On-site
USD 101,000 - 146,000
Comprehensive medical, dental, and vision coverage
401(k) with immediate vesting
Flexible Paid Time Off (PTO)
+1
Systems Engineer
Systems Engineer

600 UMG Recordings Inc • Tennessee

On-site
USD 70,000 - 114,000
Comprehensive benefits
PTO and paid holidays
Winter Break
+1
Systems Engineer
Systems Engineer

Universal Music Group • Nashville (TN)

On-site
USD 70,000 - 114,000
Medical/dental/vision coverage
401(k) with company contribution
Tuition reimbursement