Network Engineer – Firewall Security

Universal Music Group · Kings Cross, London

Music is Universal
 
It’s the passionate and dedicated team at Universal Music who help make us the world’s leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.

Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.

We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email [email protected].

The Role


UMG is seeking an experienced Network Engineer – Firewall Security to join our Global Network Infrastructure team. This role plays a critical part in UMG’s Global Security and Cybersecurity strategy by designing, standardizing, and operating enterprise firewall and perimeter security platforms.

The ideal candidate will have deep hands-on experience with next-generation firewall technologies, a strong focus on security standardization, and the ability to partner closely with Cybersecurity and Infrastructure teams in a global enterprise environment.

Key Responsibilities

  • Design, deploy, and support enterprise firewall and perimeter security solutions

  • Build, implement and maintain security controls aligned with Zero Trust and least-privilege principles

  • Lead standardization efforts across firewall platforms and configurations

  • Define and maintain Network Access Control (NAC) strategy, standards, and architectures (Cisco ISE) to support secure enterprise access

  • Design, implement, and operationalize NAC policy including authentication/authorization, device profiling, and identity-based segmentation enforcement

  • Own network security logging and telemetry strategy for firewall and NAC controls, including log scope, retention, access controls, and audit readiness

  • Design and implement logging methods and systems (e.g., syslog, API-based ingestion, cloud-native logging) to onboard network security events into the enterprise SIEM for monitoring and incident response

  • Partner with the SOC to define alerts, dashboards, and investigation workflows based on firewall and NAC security logs

  • Perform security assessments and contribute to risk reduction initiatives

  • Serve as an escalation point for complex firewall and network security issues

  • Maintain network security standards documentation, configuration standards, and operational runbooks

  • Participate in technology evaluations and security architecture reviews

  • Ensure adherence to change, incident, and problem management processes

Qualifications

Required:

  • 5+ years of overall IT experience

  • 3+ years in firewall or network security engineering roles

  • Experience with firewall concepts and implementations, preferably Palo Alto Networks firewalls

  • Experience with Network Access Control (NAC) concepts and implementations, preferably Cisco Identity Services Engine (ISE)

  • Working knowledge of AAA and secure access methods including 802.1X and RADIUS/EAP; familiarity with certificate-based authentication and PKI dependencies

  • Experience designing and operating security logging for network security controls, including log source onboarding, normalization, retention, and integration with SIEM platforms

  • Solid understanding of IP networking, routing, and security fundamentals

  • Experience working in large, global, or regulated environments

  • Strong communication and documentation skills

Preferred:

  • Security certifications such as CCNP Security, PCNSE, or equivalent

  • Familiarity with Zero Trust, network segmentation, and security governance frameworks

  • Experience supporting audits, compliance, or regulatory requirements

About UMG UK

We are Universal Music Group UK – the UK’s leading music-based entertainment company. We exist to shape culture through the power of artistry. We help UK artists produce, distribute and promote the most critically acclaimed and commercially successful music to inspire and entertain fans at home and around the world.​

Bonus Tracks: Your Benefits

  • Group Personal Pension Scheme (between 3% and 9%)

  • Private Medical Insurance

  • 25 paid days of annual leave

  • Interest Free Season Ticket Loan

  • Holiday Purchase scheme

  • Dental and Travel Insurance options

  • Cycle to Work Scheme

  • Salary Sacrifice Cars

  • Subsidised Gym Membership

  • Employee Discounts (Reward Gateway)

Just So You Know…

The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.


Job Category:

Universal Music Group

DevOps pay context

Based on 1,245 disclosed DevOps salaries on RoleSuite, the role pays a median of $140K/year, with most offers between $115K and $173K (10th–90th percentile: $100K–$210K).

See the full DevOps salary breakdown →
Apply →