Epidemic Sound logo

Epidemic Sound

Senior Security Engineer

Hybrid

Part remote, part office, you need to live within commuting distance of a named location.

Hybrid · Stockholm HQ

Employer listed it 4 months ago · Found 3h ago

Been open since 4 months ago. Long-running listings are sometimes left up after the role is filled.

Salary

Not stated

Location

Hybrid · Stockholm HQ

Timezone

Not stated

Contract

Full-time

Experience

Senior

Category

Software

This employer didn't state pay. Jobs like this usually pay around $165k–$225k a year, a typical range taken from 597 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Hybrid

This role is only partly remote, the employer expects time in the office around Stockholm HQ, Hybrid, so you need to live within commuting distance.

What the employer says

  • Source listing states candidate location: "Stockholm HQ, Hybrid"
  • Listing mentions "Hybrid"

What Nomaders makes of it

  • Not suitable if you plan to move between countries

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

Join our global force of 400+ innovators, blending the latest in tech with the greatest in soundtracking, from our Stockholm HQ to offices in London, New York, Los Angeles, Berlin, Paris, Oslo, and Seoul. We’re an industry leader with a startup mentality. We take what we do seriously, but we don’t take ourselves too seriously. Creating and collaborating to transform the sound of streaming, content, and culture. Come join us, and let the world feel your work.

As a Security Engineer at Epidemic Sound, you will help keep the company safe across three connected surfaces: the products our customers use, the platform our engineers build on, and the systems our employees rely on every day. This is a broad, generalist role where your work directly shapes how an industry-leading company with a startup mentality manages risk and builds securely at scale.

Building security automations and custom AI agents is a normal part of how the team operates, and you will be expected to do the same. You will sit within the Business Tech Division and report to the Head of Security, working closely with engineers, SRE, IT, Legal, and People teams across the organisation.

Your key responsibilities include

Own the vulnerability management programme across our products, cloud, and corporate estate: discovery, prioritisation, remediation tracking, and reporting.

Consolidate findings across our detection stack into a single risk picture.

Partner with software engineers to grow the Secure Software Development Lifecycle, including code reviews, threat models, and pre-ship security input.

Harden the GCP estate, Kubernetes platform, and CI/CD systems our engineers depend on.

Run vendor security reviews and respond to enterprise customer security questionnaires.

Operate and tune the Elastic SIEM and broader detection stack, building new detections as the threat picture evolves.

Respond to security incidents including on-call, and run training exercises to keep the team ready.

Build and run security agents and automations that other engineers and the wider business rely on, treating them as production-grade software.

Evaluate AI models and frameworks against security standards.

Requirements

Around five years in security engineering, with depth in at least one of application security, infrastructure security, enterprise security, or vulnerability management, and solid breadth across the others.

Hands-on experience running or contributing to a vulnerability management programme, including prioritisation, SLA setting, remediation tracking, and reporting.

Working knowledge of SCA/SAST tooling, Internal Developer Portals, and SIEM; we use Snyk, Port, and Elastic.

Working knowledge of the security features of the major public cloud providers, with GCP preferred.

Comfort with Kubernetes, Docker, or other container architectures.

Confident with at least one programming or scripting language such as Python, Go, or Bash.

Solid experience with Git, GitHub Actions, and Terraform.

Active, daily use of AI and agentic tools, with concrete examples of agents you have built and outputs you have shipped.

Experience with vendor security questionnaires.

Familiarity with common security frameworks such as PCI DSS and NIST.

Requirements

  • ·Around five years in security engineering, with depth in at least one of application security, infrastructure security, enterprise security, or vulnerability management, and solid breadth across the others.
  • ·Hands-on experience running or contributing to a vulnerability management programme, including prioritisation, SLA setting, remediation tracking, and reporting.
  • ·Working knowledge of SCA/SAST tooling, Internal Developer Portals, and SIEM; we use Snyk, Port, and Elastic.
  • ·Working knowledge of the security features of the major public cloud providers, with GCP preferred.
  • ·Comfort with Kubernetes, Docker, or other container architectures.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, hybrid, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Epidemic Sound, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 3h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $165k to $225k per year · You'll be taken to the employer's careers page.