Skip to main content
AfterDuty

Application Security Engineer

Universal Music Group · London, Greater London

Type
Full-time
Posted
8 days ago

Overview

Your experience with digital forensics and incident response provides a foundation, but this role demands deep technical engineering skills beyond typical policing training.

About this role

Music is Universal

It’s the passionate and dedicated team at Universal Music who help make us the world’s leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.

Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.

We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email UniversalMusicCareers@umusic.com.

Job Summary

We are UMG, the Universal Music Group. We are the world’s leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.

We are currently seeking a highly skilled vulnerability engineer to join our Vulnerability Management program. They will drive resolution of all identified IT vulnerabilities in a global enterprise to ensure the smooth and efficient ongoing operation of the UMG Global infrastructure. A high level of diverse technical skills for troubleshooting and problem analysis is required, along with the ability to clearly communicate the results of problem analysis to business stakeholders, IT support teams, and network providers to resolve operational issues quickly and effectively. This position requires established and proven experience in a global environment. In addition to having strong technical skills, you must be comfortable in effectively communicating with business end users, technical IT teams, business partners, network providers, and business process outsourced vendors, all while being sensitive to a wide diversity of cultural and technical backgrounds in a global business environment.

Job Functions

  • Demonstrate ability to anticipate security issues, identify emerging risks, and take initiative in vulnerability remediation without constant supervision. A track record of proactively addressing vulnerabilities and improving security processes is essential.
  • Prioritize and classify vulnerabilities based on risk impact, system criticality, and business context.
  • Drive resolution of identified vulnerabilities within 60 days of identification.
  • Administer and maintain the Veritas eDiscovery platform, ensuring its availability, security and proper configuration.
  • Administer and maintain Cortex XDR for endpoint detection and response.
  • Ensure compliance with data retention policies and assist legal and compliance teams with data retrieval and analysis requests.
  • Work with internal customers, teammates and 3rd party providers to ensure operational security of the cloud and server infrastructure.
  • Maintain high quality process and procedure documentation.
  • Maintain & enhance knowledge of key technologies and risks.
  • Communicate risk and remediation requirements clearly to both technical and non-technical stakeholders, including leadership and external auditors.
  • Automate the vulnerability reporting and remediation processes to improve efficiency and reduce manual intervention.
  • Participate in incident response activities related to vulnerability exploitation and provide remediation guidance.
  • Participate in on-call rotation to respond to critical security alerts and events. Work out of standard business hours will occasionally be required.

Job Requirements

  • 3+ years of hands-on experience in vulnerability management, remediation, or related cybersecurity roles.
  • 1-2 years of experience administering and maintaining Veritas eDiscovery platforms, including troubleshooting, upgrades and ensuring compliance with data retention requirements.
  • Experience with common vulnerability assessment tools (e.g., Nessus, Qualys, Tenable, OpenVAS).
  • Knowledge of patch management processes and tools.
  • Must possess strong people skills and the ability to be both diplomatic and firm.
  • Experience in highly available 24x7x365 production environment.
  • Fluency in operating system administration and tools including: Microsoft, Mac OS X, Linux, Python, Powershell, etc.
  • Proven experience with Amazon AWS and Microsoft Azure (Google Compute a plus) in an enterprise setting.
  • Manage time well in a high-interrupt operational environment. Handle the details of several technical tasks simultaneously.
  • Familiarity with VMware Tanzu CloudHealth.
  • Appropriate professional certifications.

Education

  • Bachelor’s Degree in Computer Science or Engineering or closely related field or comparable education and experience.
  • Certifications such as CISSP, CISA, Security+
  • ITIL Foundation Certification strongly desired.

Just So You Know…

The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.

Job Category

Universal Music Group

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Incident command & response
  • Digital forensics & cybercrime
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your experience managing operational risk and leading incident reviews translates directly into shaping security culture and resilience.

    Posted 2 days ago

  • Information Security Analyst

    Europa Worldwide Group · London

    Full-time

    £40,000 – £45,000Estimated

    Your experience managing evidence, compliance, and risk under ISO standards translates directly into this security assurance role.

    Posted 2 days ago

  • Cyber Security & Compliance Analyst

    Shivom Consultancy Ltd · London

    Full-time

    Your incident management, evidence handling, and risk assessment from policing transfer directly to this role.

    Posted 2 days ago

  • £570 a dayEstimated

    Your experience managing security incidents and coordinating multi-agency responses transfers directly to this governance role.

    Posted 2 days ago