Spotify logo
Spotify
Posted 10 days agoVerified live 14h ago

Security Engineer - Detection and Response

Brief overview

Remote
UndergradOr in progress
$133k–$190k/yrStated range
3+ yrsMinimum
298 H-1B approvalsDept. of Labor
96 green cardsCertified filings
Security OperationsIncident ResponseThreat DetectionDetection EngineeringSecurity Alert Triage and InvestigationThreat HuntingSIEMEDRSOARSecurity Telemetry AnalysisPythonDetection-as-CodeGitHubCI/CDCloud Security Google CloudCloud Security AWSCloud Security

About the company

Spotify is a commercial music streaming service that provides restricted digital content from a range of record labels and artists.

Visa sponsorship history

4 years sponsoring, last filed FY2026H-1B dependent

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
298H-1B approved
98%approval rate
92new H-1B hires
96PERM certified
$201,600median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
202387
2024101
202590
202620
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
202340
202422
202515
202616
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
202324
202420
202552
Top sponsored roles
Senior EngineerSenior Backend EngineerSenior Analytics EngineerData EngineerData Scientist II
Sponsored employees from
IndiaChinaSwedenCanadaFrance

Job description

Summary

Spotify is a global audio streaming company seeking an experienced Security Engineer to join its Detection and Response organization. The role focuses on identifying, investigating, and responding to threats by developing detections, building investigation workflows, improving threat hunting, and creating AI workflows for security operations.

Responsibilities

  • Identify detection opportunities, define clear telemetry requirements, and partner with the detection infrastructure squad and data owners to make the signals needed for detection and investigation available
  • Develop, test, tune, and maintain detections across endpoint, identity, cloud, SaaS, email, and other security-relevant environments
  • Investigate and prioritize alerts, determine their security impact, and participate in incident containment and remediation
  • Build repeatable investigation workflows and playbooks for alert triage, evidence collection, decision-making, escalation, containment, and response
  • Improve proactive threat-identification and threat-hunting capabilities using internal telemetry and external threat intelligence
  • Create cutting-edge AI workflows for Detection and Response that enrich alerts, gather and analyze evidence, guide investigations, and automate repetitive response work while preserving appropriate human judgment and oversight
  • Measure detection effectiveness, identify coverage gaps, and tune detections to balance security value, fidelity, and analyst workload
  • Use SIEM, EDR, SOAR, and related security platforms to research threats, develop detections, investigate alerts, and validate security outcomes
  • Share knowledge, document decisions, and communicate security findings clearly to technical and non-technical audiences

Skills

  • You are curious, collaborative, and comfortable making progress in an ambiguous and rapidly changing environment
  • You have 3+ years of hands-on experience in security operations, incident response, threat detection, detection engineering, or closely related work
  • You understand how analysts triage and investigate alerts and how detection quality affects their decisions and workload
  • You know how to create and tune detections based on attacker behavior, available telemetry, and an expected investigation path
  • You are experienced with security platforms such as SIEM, EDR, SOAR, or comparable monitoring and response technologies
  • You can write code or use an automation platform to analyze security telemetry, enrich alerts, build investigation workflows, and remove repetitive work. Experience with Python or a similar language is valuable
  • You understand modern detection-as-code practices, including GitHub, peer review, CI/CD, testing, and safely managing production detection content
  • You have experience working with at least one major cloud platform, such as Google Cloud, AWS, or Azure
  • You understand common threats affecting SaaS-oriented corporate and production environments
  • You care about clear documentation, inclusive collaboration, and explaining security concepts to people with different backgrounds and levels of expertise
  • You are excited to create and critically evaluate cutting-edge AI workflows for detection development, alert triage, security investigations, and response, while applying sound security judgment and appropriate human oversight
  • This role is based in New York
  • We offer you the flexibility to work where you work best! There will be some in person meetings, but still allows for flexibility to work from home

Qualifications

Must Haves

  • You are curious, collaborative, and comfortable making progress in an ambiguous and rapidly changing environment
  • You have 3+ years of hands-on experience in security operations, incident response, threat detection, detection engineering, or closely related work
  • You understand how analysts triage and investigate alerts and how detection quality affects their decisions and workload
  • You know how to create and tune detections based on attacker behavior, available telemetry, and an expected investigation path
  • You are experienced with security platforms such as SIEM, EDR, SOAR, or comparable monitoring and response technologies
  • You can write code or use an automation platform to analyze security telemetry, enrich alerts, build investigation workflows, and remove repetitive work. Experience with Python or a similar language is valuable
  • You understand modern detection-as-code practices, including GitHub, peer review, CI/CD, testing, and safely managing production detection content
  • You have experience working with at least one major cloud platform, such as Google Cloud, AWS, or Azure
  • You understand common threats affecting SaaS-oriented corporate and production environments
  • You care about clear documentation, inclusive collaboration, and explaining security concepts to people with different backgrounds and levels of expertise
  • You are excited to create and critically evaluate cutting-edge AI workflows for detection development, alert triage, security investigations, and response, while applying sound security judgment and appropriate human oversight
  • This role is based in New York
  • We offer you the flexibility to work where you work best! There will be some in person meetings, but still allows for flexibility to work from home

Benefits

  • Equity
  • Health insurance
  • Six-month paid parental leave
  • 401(k) retirement plan
  • Monthly meal allowance
  • 23 paid days off
  • Paid flexible holidays
  • Paid sick leave
  • Flexibility to work where you work best, including working from home with some in-person meetings

More jobs like this