Security Engineer - Detection and Response
Core
Build and maintain detection engineering workflows, investigate security alerts, and automate response actions to protect Spotify's platform and 700M+ users.
Role type
Senior Security Engineer (Detection and Response)
Builds
Detection rules, investigation playbooks, and AI-driven response workflows for endpoint, identity, cloud, and SaaS environments.
Domain
Cybersecurity / Threat Detection and Response
Deliverable
production ML models | product features
Required skills
Threat hunting, alert triage, detection engineering, incident response, SIEM/EDR/SOAR platform usage, Python scripting, cloud security (AWS/Azure/GCP), detection-as-code practices, threat intelligence analysis
Preferred skills
AI workflow development for security automation, modern CI/CD for security content, experience with SaaS threat landscapes
Technologies
SIEM, EDR, SOAR, Python, GitHub, CI/CD pipelines, AWS, Azure, Google Cloud
Responsibilities
Identify detection opportunities and define telemetry requirements; develop, test, and tune detections across multiple environments; investigate and prioritize security alerts; build repeatable investigation workflows and playbooks; improve proactive threat-hunting capabilities; create AI workflows to automate alert enrichment and response; measure detection effectiveness and tune for optimal analyst workload.
Seniority
Senior, hands-on IC