U
Senior Cyber Security Engineer
Universal Music Holdings Ltd
About This Role
Job Summary:
We are UMG, the Universal Music Group. We are the world s leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.
The Senior Cybersecurity Engineer reports to the Senior Vice President Global Cybersecurity & Crisis Management. The Candidate must be a highly motivated individual with over 7+ years of experience working in a senior role on security solutions and incident response in an enterprise environment. The role will support the Global Security Office (GSO) mission of security and reliability by working across the organization to lead response to security events and incidents by effectively conducting triage, containment, remediation and driving post-incident improvements. The position works closely with technology, application teams and business units.
As a Senior Cybersecurity Engineer, you will be responsible for securing UMG s enterprise AI platforms. This role will focus on detecting, mitigating, and responding to AI-related security threats, ensuring that applications and services remain resilient against AI-cyber threats. In addition, you will help the team establish, lead, and execute multi-year roadmaps to mature AI security, drawing upon cross-functional partnerships to deliver security posture reviews on a repeatable basis and review new AI systems as they're developed.
The Senior Cybersecurity Engineer will support other efforts in the SecOps, Insider Threat & Business Resiliency teams and work closely with other team members in the Global Security Office (GSO). This role will allow learning and growth on various security technologies.
Job Functions:
The Senior Cybersecurity Engineer role is part of Security Operations team that will, manage, maintain, design, configure, and document security tools, systems, and processes including, but not limited to, the following:
• Lead and support the response to all security events and incidents across UMG s global infrastructure, services and applications.
• Own the security incident lifecycle, respond to incidents and participate in on-call rotation for security incidents.
• Implementing Security Controls & Guardrails for GenAI: Designing, deploying, and operating technical controls to prevent misuse of AI systems. Designs can include content filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AI platforms.
• Continually test and update guardrails, replacing weaker controls with more robust solutions as threats evolve.
• Monitor alignment of solutions to AI Governance processes.
• Provide AI/Agent subject matter expertise for AI Incidents and Security Reviews and help develop incident response playbooks for AI-related security incidents.
• Work to improve UMG s security and reliability posture by driving identified improvements from security events and incidents.
• Support projects end-to-end that will improve UMG s Threat Detection and Response (TDR) capabilities and initiatives.
• Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
• Understand security vulnerabilities, attacker exploit techniques, and methods for their remediation.
• Administer security tools and technologies
• Automate triage, analysis, response, and remediation tasks and processes with code, APIs, and SOAR tools.
• Collect and review systems and application security logs from all systems (Firewalls, OS, Email, IDS, Splunk, etc.), take action to mitigate any threats based on findings.
• Conduct log analysis across a diverse ecosystem of technology (operating systems, internally developed web apps, software-as-a-service apps, cloud infrastructure)
• Ensure compliance with internal policies, standards, and regulatory requirements
• Perform forensics activities and root cause analyses
• Participate in the assessment of network design/architecture, development, and implementation of any new application or service
• Conduct Vulnerability Assessments as required
• Assess and triage potential security incidents. Coordinating and leading response to high impact security incidents.
• Lead efforts to detect and analyze malicious software and work with vendors and teams
• Perform other duties as assigned
• Lead projects, planning, controlling, executing, and closing assigned projects to produce required deliverables
Job Requirements:
Skills/Abilities:
• 7+ years of experienc...
Ready to Apply?
Click the button below to visit the company's application page.
Apply for this Position