{"id":1200795,"url":"https://alion.io/job/spotify-security-engineer-detection-and-response","title":"Security Engineer - Detection and Response","company":{"id":57,"name":"Spotify","domain":"spotify.com","url":"https://alion.io/company/spotify","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Lever","truth_index":{"grade":"B","score":79,"open_postings":6,"ghost_share":0,"stale_share":0.833,"repost_share":0,"time_to_fill_p50_days":56,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["New York, United States"],"countries":["US"],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":96000,"max_usd":180000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":62},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"Edge AI","optional":false},{"name":"GCP","optional":false},{"name":"GitHub","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-09-24T18:52:39Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-30T20:08:15Z","board_verified":true,"closed_at":null,"days_open":6,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":6},"description":"The Platform team creates the technology that enables Spotify to learn quickly and scale easily, enabling rapid growth in our users and our business around the globe. Spanning many disciplines, we work to make the business work; creating the infrastructure, tooling, frameworks, and capabilities needed to welcome a billion customers.\nSecurity engineers at Spotify protect our platform, employees, creators, and more than 700 million users. We are looking for an experienced Security Engineer to join the Detection and Response organization and help identify, investigate, and respond to threats across Spotify's environment.\nYou will work within our detection engineering squad where the team owns alert triage, security investigations, threat hunting, and the detection engineering lifecycle. You will turn threat intelligence, incident learnings, and analyst feedback into effective detections and investigation workflows. You will partner closely with the detection infrastructure squad, which builds and operates Detection and Response platforms and telemetry pipelines, and with teams across Spotify to make sure your squad has the signals and capabilities needed to detect and respond to threats at Spotify's scale.\nWe are a distributed team that values curiosity, sound judgment, clear communication, and continuous learning. We teach and learn from one another, adapt as the threat landscape changes, and focus our effort according to business needs and risk.\nWhat You'll Do\nIdentify detection opportunities, define clear telemetry requirements, and partner with the detection infrastructure squad and data owners to make the signals needed for detection and investigation available.\n\nDevelop, test, tune, and maintain detections across endpoint, identity, cloud, SaaS, email, and other security-relevant environments.\n\nInvestigate and prioritize alerts, determine their security impact, and participate in incident containment and remediation.\n\nBuild repeatable investigation workflows and playbooks for alert triage, evidence collection, decision-making, escalation, containment, and response.\n\nImprove proactive threat-identification and threat-hunting capabilities using internal telemetry and external threat intelligence.\n\nCreate cutting-edge AI workflows for Detection and Response that enrich alerts, gather and analyze evidence, guide investigations, and automate repetitive response work while preserving appropriate human judgment and oversight.\n\nMeasure detection effectiveness, identify coverage gaps, and tune detections to balance security value, fidelity, and analyst workload.\n\nUse SIEM, EDR, SOAR, and related security platforms to research threats, develop detections, investigate alerts, and validate security outcomes.\n\nShare knowledge, document decisions, and communicate security findings clearly to technical and non-technical audiences.\n\nWho You Are\nYou are curious, collaborative, and comfortable making progress in an ambiguous and rapidly changing environment.\n\nYou have 3+ years of hands-on experience in security operations, incident response, threat detection, detection engineering, or closely related work.\n\nYou understand how analysts triage and investigate alerts and how detection quality affects their decisions and workload.\n\nYou know how to create and tune detections based on attacker behavior, available telemetry, and an expected investigation path.\n\nYou are experienced with security platforms such as SIEM, EDR, SOAR, or comparable monitoring and response technologies.\n\nYou can write code or use an automation platform to analyze security telemetry, enrich alerts, build investigation workflows, and remove repetitive work. Experience with Python or a similar language is valuable.\n\nYou understand modern detection-as-code practices, including GitHub, peer review, CI/CD, testing, and safely managing production detection content.\n\nYou have experience working with at least one major cloud platform, such as Google Cloud, AWS, or Azure.\n\nYou understand common threats affecting SaaS-oriented corporate and production environments.\n\nYou care about clear documentation, inclusive collaboration, and explaining security concepts to people with different backgrounds and levels of expertise.\n\nYou are excited to create and critically evaluate cutting-edge AI workflows for detection development, alert triage, security investigations, and response, while applying sound security judgment and appropriate human oversight.\n\nWhere You'll Be\nThis role is based in New York\n\nWe offer you the flexibility to work where you work best! There will be some in person meetings, but still allows for flexibility to work from home.","description_format":"text","description_chars":4668,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Continuous learning"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Media & Entertainment","Advertising","Audio Production","Podcasting"],"lifecycle":[{"event":"open","at":"2026-09-24T20:45:15Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":5,"expected_fill_days":56,"reasons":["conf:5","velocity","win:early"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/spotify-security-engineer-detection-and-response","json_url":"https://alion.io/job/spotify-security-engineer-detection-and-response.json","meta":{"generated_at":"2026-10-01T01:36:06Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1014,"day_limit":5000,"remaining_today":3986,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}