Logo for Spotify

Security Engineer - Detection and Response

Role overview

Qualifications

  • 3+ years of hands-on experience in security operations, incident response, threat detection, detection engineering, or closely related work
  • Experience with security platforms such as SIEM, EDR, SOAR, or comparable monitoring and response technologies
  • Ability to write code or use an automation platform, with experience in Python or a similar language valued
  • Experience working with at least one major cloud platform, such as Google Cloud, AWS, or Azure

Responsibilities

  • Identify detection opportunities and define telemetry requirements for detection and investigation
  • Develop, test, tune, and maintain detections across security-relevant environments
  • Investigate and prioritize alerts, determining their security impact
  • Build repeatable investigation workflows and playbooks for alert triage and response

Key facts

Hard skills

Other skills

  • Collaboration
  • Communication
  • Curiosity
  • Adaptability

About the company

Spotify logo

Spotify

Streaming Services (SVOD/AVOD)

Our mission is to unlock the potential of human creativity—by giving a million creative artists the opportunity to live off their art and billions of fans the opportunity to enjoy and be inspired by it. Spotify transformed music listening forever when it launched in Sweden in 2008. Discover, manage and share over 70m tracks for free, or upgrade to Spotify Premium to access exclusive features including offline mode, improved sound quality, and an ad-free music listening experience. Today, Spotify is the most popular global audio streaming service with 365m users, including 165m subscribers across 178 markets. We are the largest driver of revenue to the music business today.

Company details

Company typeXLarge
IndustryStreaming Services (SVOD/AVOD)
Company size5001 - 10000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

The Platform team creates the technology that enables Spotify to learn quickly and scale easily, enabling rapid growth in our users and our business around the globe. Spanning many disciplines, we work to make the business work; creating the infrastructure, tooling, frameworks, and capabilities needed to welcome a billion customers.

Security engineers at Spotify protect our platform, employees, creators, and more than 700 million users. We are looking for an experienced Security Engineer to join the Detection and Response organization and help identify, investigate, and respond to threats across Spotify's environment.

You will work within our detection engineering squad where the team owns alert triage, security investigations, threat hunting, and the detection engineering lifecycle. You will turn threat intelligence, incident learnings, and analyst feedback into effective detections and investigation workflows. You will partner closely with the detection infrastructure squad, which builds and operates Detection and Response platforms and telemetry pipelines, and with teams across Spotify to make sure your squad has the signals and capabilities needed to detect and respond to threats at Spotify's scale.

We are a distributed team that values curiosity, sound judgment, clear communication, and continuous learning. We teach and learn from one another, adapt as the threat landscape changes, and focus our effort according to business needs and risk.


What You'll Do
  • Identify detection opportunities, define clear telemetry requirements, and partner with the detection infrastructure squad and data owners to make the signals needed for detection and investigation available.

  • Develop, test, tune, and maintain detections across endpoint, identity, cloud, SaaS, email, and other security-relevant environments.

  • Investigate and prioritize alerts, determine their security impact, and participate in incident containment and remediation.

  • Build repeatable investigation workflows and playbooks for alert triage, evidence collection, decision-making, escalation, containment, and response.

  • Improve proactive threat-identification and threat-hunting capabilities using internal telemetry and external threat intelligence.

  • Create cutting-edge AI workflows for Detection and Response that enrich alerts, gather and analyze evidence, guide investigations, and automate repetitive response work while preserving appropriate human judgment and oversight.

  • Measure detection effectiveness, identify coverage gaps, and tune detections to balance security value, fidelity, and analyst workload.

  • Use SIEM, EDR, SOAR, and related security platforms to research threats, develop detections, investigate alerts, and validate security outcomes.

  • Share knowledge, document decisions, and communicate security findings clearly to technical and non-technical audiences.


Who You Are
  • You are curious, collaborative, and comfortable making progress in an ambiguous and rapidly changing environment.

  • You have 3+ years of hands-on experience in security operations, incident response, threat detection, detection engineering, or closely related work.

  • You understand how analysts triage and investigate alerts and how detection quality affects their decisions and workload.

  • You know how to create and tune detections based on attacker behavior, available telemetry, and an expected investigation path.

  • You are experienced with security platforms such as SIEM, EDR, SOAR, or comparable monitoring and response technologies.

  • You can write code or use an automation platform to analyze security telemetry, enrich alerts, build investigation workflows, and remove repetitive work. Experience with Python or a similar language is valuable.

  • You understand modern detection-as-code practices, including GitHub, peer review, CI/CD, testing, and safely managing production detection content.

  • You have experience working with at least one major cloud platform, such as Google Cloud, AWS, or Azure.

  • You understand common threats affecting SaaS-oriented corporate and production environments.

  • You care about clear documentation, inclusive collaboration, and explaining security concepts to people with different backgrounds and levels of expertise.

  • You are excited to create and critically evaluate cutting-edge AI workflows for detection development, alert triage, security investigations, and response, while applying sound security judgment and appropriate human oversight.


Where You'll Be
  • This role is based in New York

  • We offer you the flexibility to work where you work best! There will be some in person meetings, but still allows for flexibility to work from home.

The United States base range for this position is $132,948–$189,927 USD, plus equity. The benefits available for this position include health insurance, six-month paid parental leave, 401(k) retirement plan, monthly meal allowance, 23 paid days off, paid flexible holidays, and paid sick leave. These ranges may be modified in the future.
Spotify is an equal opportunity employer. You are welcome at Spotify for who you are, no matter where you come from, what you look like, or what’s playing in your headphones. Our platform is for everyone, and so is our workplace. The more voices we have represented and amplified in our business, the more we will all thrive, contribute, and be forward-thinking! So bring us your personal experience, your perspectives, and your background. It’s in our differences that we will find the power to keep revolutionizing the way the world listens.   At Spotify, we are passionate about inclusivity and making sure our entire recruitment process is accessible to everyone. We have ways to request reasonable accommodations during the interview process and help assist in what you need. If you need accommodations at any stage of the application or interview process, please let us know - we’re here to support you in any way we can.  

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Spotify

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.