Qualifications
ResponsibilitiesLead application security initiatives for Label Engine (PHP 8.x / Laravel / MySQL / Redis / Elasticsearch) and across web applications. Implement security measures for royalty processing, accounting, and payment workflows involving sensitive financial data. Integrate and manage SAST, DAST, and SCA tooling within CI/CD pipelines. Conduct thorough code-level security reviews focusing on OWASP Top 10 and Laravel-specific attack vectors. Drive the operationalization of the broader security roadmap, ensuring compliance and enhancing security posture.
About the job
Job Summary
As the Senior Application & Cloud Security Engineer, you will be a pivotal member of the Technology team at Create Music Group, directly reporting to the VP of Data Engineering. This position is instrumental in safeguarding our application portfolio and multi-cloud infrastructure (AWS & GCP). You will work hands-on to enhance the security of Label Engine (PHP/Laravel on AWS, processing over $1B in royalties), fortify the expanding GCP-based CreateOS data and AI platform, and implement the company's extensive security roadmap, which encompasses identity management, endpoint protection, vulnerability management, incident response, and compliance.
About Create Music Group
Founded in 2015, Create Music Group stands at the forefront of the music and entertainment industry. Operating as a record label, distribution company, and entertainment network, we generate over 15 billion music streams monthly on digital service platforms. Recognized as the #2 fastest-growing company in America by Inc. 5000 in 2020, we have experienced phenomenal growth by leveraging our proprietary intellectual property through our media and technology platforms. Collaborating with both superstar artists and independent labels, we manage various companies, including Label Engine, one of the world's largest independent music distribution platforms, serving over 75,000 artists and 5,000 label clients, as well as Flighthouse, a leading digital entertainment brand.