Security Engineer – Product Security
UTA Ventures is the venture division of United Talent Agency.
About UTA Ventures
UTA Ventures seeks out, builds, and accelerates innovative businesses that change how people live, work, and play. It operates at the intersection of entertainment, commerce, and technology, partnering with talent to build companies, extend brand platforms, and expand into new categories. The division also invests in growing startups, including businesses in the creator economy, frontier technology, and the future of entertainment.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will design and review security controls for web mobile and cloud applications. You will lead threat modeling, integrate security testing into CI/CD pipelines, assess APIs and containers, manage vulnerabilities, support monitoring and incident response, and create secure development guidance and training.
Requirements
- Bachelor’s degree in Computer Science Cybersecurity Engineering or a related field or equivalent practical experience
- 3+ years of experience in security engineering application security or product-aligned security roles
- Knowledge of web mobile and API vulnerabilities including OWASP Top 10
- Experience securing applications and services in a major cloud provider
- Knowledge of SAST DAST SCA secret scanning WAF and CI/CD integration
- Familiarity with Terraform review GitHub Actions security and secrets management
- Familiarity with container security Kubernetes RBAC network policies and runtime protection
- Familiarity with securing AI and ML platforms and agentic workflows
- Experience collaborating with software engineering teams in agile environments
- Knowledge of identity authentication and authorization technologies including OAuth OIDC and SSO
- Excellent communication and stakeholder management skills
Responsibilities
- Support security design and architecture reviews
- Define product security requirements and roadmaps
- Conduct threat modeling workshops
- Review AWS Azure and GCP services
- Own the application security lifecycle
- Integrate SAST DAST SCA and secrets scanning into CI/CD pipelines
- Coordinate application security testing and remediation
- Establish secure coding standards and frameworks
- Assess REST and GraphQL API security
- Support vulnerability triage and remediation
- Ensure appropriate handling of sensitive data
- Evaluate and implement product security tools
- Develop security documentation playbooks and training
- Advise on secure use of AI-assisted development tools
