5 days ago
Base Salary
$133k - $190k/yr
Responsibilities
- Identify detection opportunities and define telemetry requirements with detection infrastructure teams and data owners.
- Develop, test, tune, and maintain detections across endpoint, identity, cloud, SaaS, email, and other security environments.
- Investigate and prioritize alerts, assess security impact, and participate in incident containment and remediation.
- Build investigation workflows and playbooks for triage, evidence collection, escalation, containment, and response.
- Improve threat identification and hunting using internal telemetry and external threat intelligence.
- Create and critically evaluate AI workflows that enrich alerts, analyze evidence, guide investigations, and automate repetitive response tasks.
- Measure detection effectiveness, identify coverage gaps, and balance detection value, fidelity, and analyst workload.
- Use SIEM, EDR, SOAR, and related security platforms to research threats and validate outcomes.
- Document decisions, share knowledge, and communicate security findings to technical and non-technical audiences.
Requirements
- At least 3 years of hands-on experience in security operations, incident response, threat detection, detection engineering, or closely related work.
- Experience triaging and investigating alerts and understanding how detection quality affects analyst decisions and workload.
- Ability to create and tune detections based on attacker behavior, available telemetry, and investigation paths.
- Experience with SIEM, EDR, SOAR, or comparable monitoring and response technologies.
- Ability to write code or use automation platforms to analyze telemetry, enrich alerts, and build investigation workflows; Python or a similar language is valuable.
- Understanding of detection-as-code practices, including GitHub, peer review, CI/CD, testing, and production detection content management.
- Experience with at least one major cloud platform, such as Google Cloud, AWS, or Azure.
- Understanding of common threats affecting SaaS-oriented corporate and production environments.
- Strong documentation, collaboration, communication, security judgment, and ability to evaluate AI workflows with appropriate human oversight.
Benefits
- The role is based in New York with flexibility to work from home and some in-person meetings.
- Health insurance is provided.
- Six-month paid parental leave is provided.
- 401(k) retirement plan is provided.
- Monthly meal allowance is provided.
- 23 paid days off, paid flexible holidays, and paid sick leave are provided.
About Spotify
Spotify builds a global audio streaming platform for listeners and creators, offering on-demand music and podcasts across mobile, desktop, and connected devices. The business runs a freemium model: an ad-supported free tier and a paid Premium subscription, plus creator tools like Spotify for Artists and podcast publishing. Founded in 2006 and headquartered in Stockholm, it is a publicly traded company on the NYSE (SPOT) serving consumers and rights holders worldwide.
