At a Glance
- Tasks: Design and implement security controls for innovative products and platforms.
- Company: Join UTA, a leading global talent agency in media and entertainment.
- Benefits: Competitive salary, well-being programs, and a collaborative work environment.
- Other info: Inclusive culture with opportunities for professional growth and development.
- Why this job: Shape the future of product security while working with top talent in the industry.
- Qualifications: 3+ years in security engineering and familiarity with cloud security practices.
The predicted salary is between 63000 - 77000 £ per year.
UTA seeks a Security Engineer - Product Security to help embed security into the design, development, and operation of our products and platforms.
In this role, you will work closely with engineering, product, and security teams to design and implement security controls across our applications and services, safeguarding our brand, our people, and our digital assets.
If you are passionate about building secure products from the ground up and enjoy operating at the intersection of software development and cybersecurity, this role offers the opportunity to meaningfully shape UTA's product security posture.
What You Will Do
- Product security strategy & architecture
- Support security design and architecture reviews for new and existing products, including web, mobile, and cloud-based custom applications, and provide clear, actionable recommendations.
- Partner with product and engineering leadership to define product security requirements, risk tolerances, and security roadmaps across multiple teams and initiatives.
- Conduct and facilitate threat modeling workshops to proactively identify emerging risks and attack vectors and drive mitigations into product design.
- Conduct security reviews for products and services deployed across AWS, Azure, and GCP including cloud-native architectures, and platform-specific security controls.
- Secure development lifecycle & testing
- Own and mature the application and product security lifecycle, including threat modeling, secure design, secure coding practices, testing, and release validation.
- Assess and secure early-stage product design, architecture and workflows, associated with rapid prototyping and deployment
- Drive the adoption of automated security checks in CI/CD pipelines (SAST, DAST, SCA, secrets scanning, etc.) and ensure they are tuned to balance risk reduction with developer velocity.
- Support and coordinate application security testing efforts, including tool-based and manual reviews, and work closely with development teams to prioritize and remediate findings.
- Establish and evangelize secure coding standards, patterns, and reusable frameworks that can be leveraged across engineering teams.
- Support API security assessments, including authentication/authorization validation for REST/Graph QL APIs and API gateway configuration reviews.
- Operations, monitoring & incident response
- Collaborate with security operations to ensure product-related logs, alerts, and events are captured, correlated, and integrated into monitoring and incident response workflows.
- Support vulnerability triage and management for product and application findings, including those surfaced through penetration tests and attack surface monitoring, covering risk assessment, remediation planning, and validation of fixes.
- Ensure products handle sensitive data appropriately, including data classification, storage, transit, and retention practices aligned with organizational security requirements.
- Tooling, enablement & leadership
- Evaluate, select, and help implement product security focused tools and services, influencing build vs buy decisions.
- Develop documentation, playbooks, and training to raise the overall level of security awareness and capability across product and engineering teams.
- Provide best practices on the secure use of AI-assisted development tools, including risks around dependency integrity, code suggestions, and agent-driven changes.
- What You Will Need
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field; or equivalent practical experience
- 3+ years of experience in security engineering, application security, or product aligned security roles, with a track record of owning and driving security initiatives
- Familiarity with common web, mobile, and API vulnerabilities (e. g., OWASP Top 10) and practical experience preventing and remediate them at scale
- Experience securing applications and services in at least one major cloud provider (AWS preferred), including cloud native architectures
- Knowledge of application security tooling (SAST, DAST, SCA, secret scanning, WAF, or similar) and integrating these into CI/CD workflows
- Familiarity with secure deployment practices, including Infrastructure-as-Code review of Terraform, CI/CD pipeline security (Git Hub Actions), and secrets management.
- Familiarity with container security, including image hardening, Kubernetes RBAC, network policies, and runtime protection.
- Familiarity with securing AI/ML platforms in cloud environments and agentic workflows, including access control, data protection, and governance across the application development and deployment lifecycle.
- Some experience collaborating with software engineering teams in agile environments, including participating in design reviews, code reviews, and sprint planning
- Knowledge of identity, authentication, and authorization concepts and technologies (e. g., OAuth, OIDC, SSO, modern identity platforms)
- Excellent communication and stakeholder management skills, with the ability to influence senior technical and nontechnical partners and drive consensus
- What You Will Get
- The unique and exciting opportunity to work at one of a leading global entertainment companies
- Access to the tools, leadership, and resources you will need to create and drive a center of excellence
- The opportunity to do the best work of your career
- Work in an inclusive and diverse company culture
- Competitive programs to support your well-being
- Experience working in a collaborative environment with room to grow
- About UTA
UTA is a premier global talent agency built for the future of media and entertainment.
The agency's diversified platform and best-in-class, client-first approach is innovative, collaborative, and positioned to lead in an evolving market.
UTA represents the most celebrated artists, creatives, and brands, from icons and legends to next-generation talent.
Its integrated capabilities span film and television, music, comedy, creators, sports, brands, news, publishing, speakers, theater, and more.
It is based in Los Angeles with offices in the U.
S., London, and Munich.
For more information: https://www. unitedtalent. com/about/
UTA and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers.
- https://www. unitedtalent. com/privacy-policy
- #J-18808-Ljbffr
Security Engineer - Product Security employer: United Talent Agency LLC
UTA is an exceptional employer, offering a unique opportunity to work at the forefront of the entertainment industry in Los Angeles. With a strong focus on employee well-being and professional growth, UTA fosters a collaborative and inclusive culture where innovative ideas thrive. As a Security Engineer - Product Security, you will have access to cutting-edge tools and resources, enabling you to make a meaningful impact while advancing your career in a dynamic environment.
StudySmarter Expert Advice🤫
We think this is how you could land Security Engineer - Product Security
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including United Talent Agency LLC, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through United Talent Agency LLC
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at United Talent Agency LLC. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security Engineer - Product Security
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at United Talent Agency LLC insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to United Talent Agency LLC that you’re committed to staying ahead in the game.
How to prepare for a job interview at United Talent Agency LLC
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at United Talent Agency LLC to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at United Talent Agency LLC.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.