Security Engineer- Product Security

3 hours, 41 minutes ago
Full-time
Mid Level
Software Development
Spotify

Spotify

Spotify is a leading global audio streaming service empowering artists and inspiring fans worldwide with over 70 million tracks. It has 365 million users, including 165 million subscribers, across 178 markets.

Media
Founded 2006

Description

  • Champion and implement security best practices, standards, and automated tooling across Spotify’s infrastructure, platforms, and AI-driven development.
  • Partner with product, platform, and development teams to embed security throughout the software development lifecycle from ideation to deployment and monitoring.
  • Consult, educate, and advocate for practical security approaches across technical and non-technical audiences.
  • Drive cross-disciplinary initiatives that improve the security of Spotify’s engineering ecosystem and products.
  • Conduct threat modeling, security reviews, and risk assessments for generative AI and non-AI systems and platforms.
  • Evaluate, prototype, and integrate security solutions and tools that improve security outcomes and developer experience at scale.
  • Stay current on AI security threats, academic research, vulnerabilities, and mitigation strategies relevant to Spotify’s environment.
  • Contribute to security incident response activities, including detection, response, and remediation improvements.

Requirements

  • 3+ years of hands-on experience in security engineering or a related technical field.
  • Ability to write code to integrate security tools and automate workflows using modern software development practices.
  • Experience in one or more areas such as backend development, AI/ML systems, distributed computing, CI/CD platforms, cloud infrastructure, or developer platforms.
  • Strong foundation in security concepts including cryptography, threat modeling, secure design, and software security.
  • Ability to communicate security concepts clearly to both technical and non-technical stakeholders.
  • Experience working in agile environments and adapting quickly to changing priorities.
  • Ability to read and write code in one or more languages such as Java, Python, Scala, C++, or TypeScript.
  • Experience applying generative AI tools to security and software engineering challenges.
  • Strong understanding of security risks, attack vectors, and vulnerabilities relevant to AI and machine learning systems, and how to mitigate them.
  • Familiarity with modern agentic AI frameworks and emerging AI development patterns.

Benefits

  • Flexible work location with the option to work from home, with some in-person meetings.
  • Role based in London, United Kingdom or Stockholm, Sweden.
  • Inclusive workplace with reasonable accommodations available during the interview and application process.
  • Opportunity to work at a global company with broad impact across music and podcasting.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer

Nebius 51-250 Internet Software & Services

Nebius is hiring an Application Security Engineer to help secure its AI cloud platform by identifying vulnerabilities, improving secure development practices, and supporting application security across the software lifecycle.

Burp Suite Cybersecurity Go Java JavaScript Linux OpenID Connect Penetration Testing Python SAML
2 hours, 56 minutes ago

Senior Application Security Engineer - Southeast region (Remote)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring a senior Application Security consultant to help client organizations strengthen and operationalize their AppSec programs through a mix of advisory work, hands-on engineering, and executive-level guidance.

AWS Azure CI/CD DevSecOps GCP Kubernetes Secrets Management
3 hours, 26 minutes ago

Product Security Engineer

MLabs 11-50 Internet Software & Services

MLabs is hiring a Product Security Engineer to secure an enterprise-grade open-source proof-of-stake blockchain platform as it scales across protocol upgrades, EVM-compatible services, and cross-chain infrastructure.

Blockchain CI/CD Encryption gRPC Java Rust
3 hours, 56 minutes ago

Application Security Engineer

Inovalon 1K-5K IT Services

Inovalon is hiring a Staff Software Engineer focused on application security to embed secure practices across the design, development, and operation of cloud-native SaaS healthcare platforms.

Agile DevSecOps Encryption GCP HIPAA Penetration Testing
1 day, 6 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers