×
Register Here to Apply for Jobs or Post Jobs. X

Application Security Engineer

Job in Murfreesboro, Rutherford County, Tennessee, 37132, USA
Listing for: 600 UMG Recordings Inc
Full Time position
Listed on 2026-07-18
Job specializations:
  • Software Development
Salary/Wage Range or Industry Benchmark: 90000 - 130000 USD Yearly USD 90000.00 130000.00 YEAR
Job Description & How to Apply Below

We are UMG, the Universal Music Group, the world’s leading music company that operates across more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most acclaimed and commercially successful music worldwide.

We are currently seeking an Application Security Engineer to join UMG’s global Tech Security & Identity organization. Reporting to the Manager, Security Engineering and Vulnerability, you will improve the security of internally developed applications and cloud services by partnering closely with engineering, infrastructure, and product teams.

Responsibilities
  • Perform application security assessments, threat modeling, and secure design reviews for internally developed and third‑party applications.
  • Conduct application security testing using static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), API security testing, and manual validation techniques.
  • Review source code and provide secure coding guidance based on OWASP best practices and secure development principles.
  • Partner with software engineering teams to identify security risks and recommend practical remediation strategies throughout the software development lifecycle.
  • Collaborate with Dev Ops teams to integrate application security testing into CI/CD pipelines and software delivery workflows.
  • Provide security architecture guidance for new applications, APIs, cloud‑native services, and technology integrations.
  • Support implementation of modern authentication and authorization technologies, including OAuth, OpenID Connect (OIDC), SAML, and other identity standards.
  • Evaluate, implement, and maintain application security tools and help improve security testing coverage across the development lifecycle.
  • Develop automation and scripting to improve application security testing, reporting, and engineering workflows.
  • Participate in security reviews for new technologies, cloud services, and third‑party applications.
  • Support investigation and remediation of application‑layer security incidents and vulnerabilities when required.
  • Create reusable security guidance, reference architectures, and technical documentation to improve secure development practices across engineering teams.
  • Deliver secure coding guidance and developer education to promote security‑by‑design principles.
  • Collaborate with security, infrastructure, and identity teams to continuously improve enterprise application security capabilities.
Qualifications
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • 5+ years of experience in Application Security, Security Engineering, Software Engineering, or a related discipline with a security focus.
  • Experience performing application security assessments, threat modeling, and secure architecture reviews.
  • Strong understanding of secure coding principles and common application vulnerabilities, including the OWASP Top
    10 and OWASP API Security Top
    10.
  • Experience with application security testing technologies including SAST, DAST, SCA, API security testing, and penetration testing methodologies.
  • Experience working with modern application architectures, REST APIs, microservices, and cloud‑native technologies.
  • Experience integrating security into CI/CD pipelines and Dev Sec Ops  workflows.
  • Experience working within AWS, Azure, or Google Cloud Platform environments.
  • Knowledge of modern authentication and authorization technologies including OAuth, OpenID Connect (OIDC), SAML, and JWT.
  • Understanding of security frameworks and standards including OWASP, NIST Cybersecurity Framework, and ISO
    27001.
  • Strong analytical, problem‑solving, and communication skills with the ability to work effectively across technical and non‑technical teams.
Desired Qualifications
  • Experience implementing Secure Software Development Lifecycle (SSDLC) practices within Agile development environments.
  • Experience with application security platforms such as Git Hub Advanced Security, Microsoft Defender for Cloud, Checkmarx, Veracode, Burp Suite, Semgrep, or similar tools.
  • Experience with container security,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary