Security Engineer - Detection and Response

Spotify
New York
Workplace: RemoteFull timeUSD 132,948 - 189,927 annuallyFunction: CybersecuritySkills: ["Curiosity","Collaboration","Sound judgment","Clear communication","Continuous learning"]

Build and improve Spotify’s Detection and Response capabilities by turning threat intelligence, incident learnings, and analyst feedback into high-quality detections and investigation workflows. Develop, test, tune, and maintain detections across endpoint, identity, cloud, SaaS, and email while using SIEM/EDR/SOAR to research threats and validate outcomes. Collaborate with detection engineering and infrastructure squads, automate repetitive response work, and measure effectiveness to reduce analyst workload.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Spotify
Spotify
16 hours ago

Security Engineer - Detection and Response

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Build and improve Spotify’s Detection and Response capabilities by turning threat intelligence, incident learnings, and analyst feedback into high-quality detections and investigation workflows. Develop, test, tune, and maintain detections across endpoint, identity, cloud, SaaS, and email while using SIEM/EDR/SOAR to research threats and validate outcomes. Collaborate with detection engineering and infrastructure squads, automate repetitive response work, and measure effectiveness to reduce analyst workload.
Location: New York
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Identify detection opportunities and define telemetry requirements in partnership with detection infrastructure and data owners.
  • •Develop, test, tune, and maintain detections across endpoint, identity, cloud, SaaS, email, and other security-relevant environments.
  • •Investigate and prioritize alerts, determine security impact, and participate in incident containment and remediation.
  • •Build repeatable investigation workflows and playbooks for alert triage, evidence collection, decision-making, escalation, containment, and response.
  • •Use internal telemetry and external threat intelligence to improve threat-hunting and detection effectiveness, balancing fidelity and analyst workload.

Pay and Benefits

Salary: USD 132,948 - 189,927 annually
Perks:Health Insurance401kPaid ParentalMeal AllowancePaid Leave

Key Requirements

  • •3+ years of hands-on experience in security operations, incident response, or threat detection/detection engineering.
  • •Ability to triage and investigate alerts, and tune detections based on attacker behavior, telemetry, and expected investigation paths.
  • •Experience with security platforms such as SIEM, EDR, SOAR (or comparable monitoring and response technologies).
  • •Ability to write code or use automation to analyze telemetry, enrich alerts, and build investigation workflows (Python valued).
  • •Experience with at least one major cloud platform (Google Cloud, AWS, or Azure).
Experience:Security operationsIncident responseThreat detectionDetection engineering
Skills:CuriosityCollaborationSound judgmentClear communicationContinuous learning
Tech Stack:SIEMEDRSOARPythonGitHubCI/CDAWSGoogle CloudAzureAI

Company Brief

Spotify
Provides a music, podcast and audio streaming service offering on-demand access to millions of tracks and podcasts, personalized recommendations, and advertising and subscription-based tiers for listeners and creators worldwide.
Industry: Streaming Platforms
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Stockholm, Sweden
Founded: 2006
Glassdoor
Glassdoor: 4.1
WebsiteLinkedInGlassdoor