Universal Music Group
Application Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Music is Universal
It’s the passionate and dedicated team at Universal Music who help make us the world’s leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.
Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.
We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email UniversalMusicCareers@umusic.com.
Job Summary:
We are UMG, the Universal Music Group. We are the world’s leading music company. In everything we do, we are committed to artistry, innovation, and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute, and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.
We are currently seeking a highly skilled vulnerability engineer to join our Vulnerability Management program. They will drive resolution of all identified IT vulnerabilities in a global enterprise to ensure the smooth and efficient ongoing operation of the UMG Global infrastructure. A high level of diverse technical skills for troubleshooting and problem analysis is required, along with the ability to clearly communicate the results of problem analysis to business stakeholders, IT support teams, and network providers to resolve operational issues quickly and effectively. This position requires established and proven experience in a global environment. In addition to having strong technical skills, you must be comfortable in effectively communicating with business end users, technical IT teams, business partners, network providers, and business process outsourced vendors, all while being sensitive to a wide diversity of cultural and technical backgrounds in a global business environment.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Job Functions:
- Demonstrate ability to anticipate security issues, identify emerging risks, and take initiative in vulnerability remediation without constant supervision. A track record of proactively addressing vulnerabilities and improving security processes is essential.
- Prioritize and classify vulnerabilities based on risk impact, system criticality, and business context.
- Drive resolution of identified vulnerabilities within 60 days of identification.
- Administer and maintain the Veritas eDiscovery platform, ensuring its availability, security, and proper configuration.
- Administer and maintain Cortex XDR for endpoint detection and response.
- Ensure compliance with data retention policies and assist legal and compliance teams with data retrieval and analysis requests.
- Work with internal customers, teammates, and 3rd party providers to ensure operational security of the cloud and server infrastructure.
- Maintain high-quality process and procedure documentation.
- Maintain & enhance knowledge of key technologies and risks.
- Communicate risk and remediation requirements clearly to both technical and non-technical stakeholders, including leadership and external auditors.
- Automate the vulnerability reporting and remediation processes to improve efficiency and reduce manual intervention.
- Participate in incident response activities related to vulnerability exploitation and provide remediation guidance.
- Participate in on-call rotation to respond to critical security alerts and events. Work out of standard business hours will occasionally be required.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Job Requirements:
- 3+ years of hands-on experience in vulnerability management, remediation, or related cybersecurity roles.
- 1-2 years of experience administering and maintaining Veritas eDiscovery platforms, including troubleshooting, upgrades, and ensuring compliance with data retention requirements.
- Experience with common vulnerability assessment tools (e.g., Nessus, Qualys, Tenable, OpenVAS).
- Knowledge of patch management processes and tools.
- Must possess strong people skills and the ability to be both diplomatic and firm.
- Experience in highly available 24x7x365 production environment.
- Fluency in operating system administration and tools including: Microsoft, Mac OS X, Linux, Python, Powershell, etc.
- Proven experience with Amazon AWS and Microsoft Azure (Google Compute a plus) in an enterprise setting.
- Manage time well in a high-interrupt operational environment. Handle the details of several technical tasks simultaneously.
- Familiarity with VMware Tanzu CloudHealth.
- Appropriate professional certifications.
Education:
- Bachelor’s Degree in Computer Science or Engineering or closely related field or comparable education and experience.
- Certifications such as CISSP, CISA, Security+
- ITIL Foundation Certification strongly desired.
Just So You Know…
The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
Job Category:
Universal Music Group
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location