The opportunity
The Platform team creates the technology that enables Spotify to learn quickly and scale easily, enabling rapid growth in our users and our business around the globe. Spanning many disciplines, we work to make the business work; creating the infrastructure, tooling, frameworks,…
What you'll do
Identify detection opportunities, define clear telemetry requirements, and: partner with the detection infrastructure squad and data owners to make the signals needed for detection and investigation available.
Develop, test, tune, and maintain detections across endpoint, identity,: cloud, SaaS, email, and other security-relevant environments.
Investigate and prioritize alerts, determine their security impact, and: participate in incident containment and remediation.
Build repeatable investigation workflows and playbooks for alert triage,: evidence collection, decision-making, escalation, containment, and response.
Improve proactive threat-identification and threat-hunting capabilities using: internal telemetry and external threat intelligence.
Create cutting-edge AI workflows for Detection and Response that enrich: alerts, gather and analyze evidence, guide investigations, and automate repetitive response work while preserving appropriate human judgment and oversight.
What they're looking for
- You are curious, collaborative, and comfortable making progress in an: ambiguous and rapidly changing environment.
- You have 3+ years of hands-on experience in security operations, incident: response, threat detection, detection engineering, or closely related work.
- You understand how analysts triage and investigate alerts and how detection: quality affects their decisions and workload.
- You know how to create and tune detections based on attacker behavior,: available telemetry, and an expected investigation path.
- You are experienced with security platforms such as SIEM, EDR, SOAR, or: comparable monitoring and response technologies.
- You can write code or use an automation platform to analyze security: telemetry, enrich alerts, build investigation workflows, and remove repetitive work. Experience with Python or a similar language is valuable.
- You understand modern detection-as-code practices, including GitHub, peer: review, CI/CD, testing, and safely managing production detection content.
- You have experience working with at least one major cloud platform, such as Google Cloud, AWS, or Azure.