
Application Security Engineer
Universal Music Group2 months ago
Nashville, TN, USASenior
Responsibilities
- Perform application security assessments, threat modeling, secure design reviews, source-code reviews, and manual validation for applications and cloud services.
- Conduct SAST, DAST, SCA, API security testing, and penetration testing activities.
- Partner with software engineering, infrastructure, DevOps, product, security, and identity teams to identify and remediate application security risks.
- Integrate application security testing into CI/CD pipelines and software delivery workflows.
- Provide security architecture guidance for applications, APIs, cloud-native services, and technology integrations.
- Support OAuth, OpenID Connect, SAML, JWT, and other authentication and authorization technologies.
- Evaluate and maintain application security tools and improve security testing coverage.
- Develop automation and scripting for application security testing, reporting, and engineering workflows.
- Support investigations and remediation of application-layer security incidents and vulnerabilities.
- Create reusable security guidance, reference architectures, technical documentation, secure coding guidance, and developer education.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
- At least 5 years of experience in Application Security, Security Engineering, Software Engineering, or a related security-focused discipline.
- Experience with application security assessments, threat modeling, secure architecture reviews, secure coding principles, OWASP Top 10, and OWASP API Security Top 10.
- Experience with SAST, DAST, SCA, API security testing, and penetration testing methodologies.
- Experience with REST APIs, microservices, modern application architectures, and cloud-native technologies.
- Experience integrating security into CI/CD pipelines and DevSecOps workflows.
- Experience with AWS, Azure, or Google Cloud Platform.
- Knowledge of OAuth, OpenID Connect, SAML, JWT, OWASP, NIST Cybersecurity Framework, and ISO 27001.
- Strong analytical, problem-solving, communication, and cross-functional collaboration skills.
- Preferred experience with Secure Software Development Lifecycle practices, Agile environments, application security platforms, container security, Kubernetes, Infrastructure as Code security, and cloud-native application assessments.
- Preferred scripting experience with Python, PowerShell, or similar languages.
- Preferred certifications include CSSLP, GIAC GWEB, AWS Certified Security Specialty, Security+, or CISSP.
- Experience in large global enterprises and media, entertainment, or similarly distributed organizations is desirable.
Benefits
- Comprehensive medical, dental, and vision coverage, including full coverage for eligible in-network outpatient mental health services.
- Fertility coverage for eligible medical plan participants.
- Wellbeing reimbursements for fitness classes, spa treatments, meal services, travel, and other activities up to $720 per year.
- Student loan repayment assistance and tuition reimbursement.
- 401(k) with immediate vesting on the first 5% of employee contributions plus an additional UMG contribution.
- Flexible PTO for exempt employees or three weeks of PTO for non-exempt employees.
- Two-week paid winter break, 10 company holidays including Juneteenth and Wellbeing Day, and Summer Fridays between Memorial Day and Labor Day.
- Generous paid parental leave for every type of parent.