M+E Technology Job Board

Application Security Software Engineer

Spotify

The Security organization is an ambitious, hardworking and friendly group working together on an important and complex mission; improving the security posture of Spotify. In a distributed and growing organization of engineering teams that need to iterate fast on their products, our environment is ever changing and so are the challenges for Security. We are now looking for an engineer to join one of our teams, focusing on securing product development at Spotify.

As a part of this team, you will work on projects, often spanning across the wider organization, to improve the security of Spotify’s end user facing applications and features. Above all, your work will impact the way the world experiences music.

What you’ll do

You will be part of an agile team focusing on securing product development at Spotify, often together with engineers and teams across the Spotify organisation in a project oriented fashion.
You will take on different roles and responsibilities, depending on what the situation requires; ranging from consulting and supporting, to hands on problem solving and software development.
You will design, build and operate distributed security systems at large scale, as well as educate and influence the Spotify engineering community in security related topics.
Your work will cover all parts of securing the software development lifecycle, and it will be tailored to the needs of the organisation, always striving to to improve the security properties and attributes of our applications and production systems.
You will have the opportunity be a key player in Spotify’s security organisation, with lots of room to grow and develop your skills, knowledge and experience.

Who you are

You enjoy working in teams, solving problems, learning about new technology, and sharing your learnings with others.
You are flexible and tend to take on the role that’s needed the most. You thrive in an ever changing environment where adaptation is key, where you get to support others in balancing fast deliveries with secure development.
You are either a curious software engineer who has been part of building high quality, production grade services and is passionate about security, or you are a curious application security engineer who cares about software development, feels comfortable digging into code and likes doing code reviews.
You can easily describe your designs and proposals to others, and you enjoy collaboratively improving and executing on them.
You have experience from working in agile environments, and you value collaboration, feedback and continuous improvement.
You are comfortable with Linux and have experience in any language of choice. Java or Python experience is strongly preferred.
You are interested in continuous deployment and delivery philosophies using tools like Docker, Jenkins and Kubernetes, as well as cloud platforms such as GCP.
If you have knowledge of or experience from working with mobile application security, that is a bonus.