Posted at: 14 January

Security Engineer - Application

Company

Epidemic Sound

Epidemic Sound is a Stockholm-based B2B subscription service providing a vast library of royalty-free music and sound effects for video content production, in-store music, and streaming platforms globally.

Remote Hiring Policy:

Epidemic Sound operates globally and hires from various regions, with team members located in cities such as Stockholm, London, New York, Los Angeles, Berlin, Oslo, and Seoul. While some roles may require presence in specific offices, the company embraces a diverse and inclusive workforce.

Job Type

Full-time

Allowed Applicant Locations

Sweden

Apply Here

Job Description

Join our global force of 500+ innovators, blending the latest in tech with the greatest in soundtracking, from our Stockholm HQ to offices in London, New York, Los Angeles, Berlin, Oslo, and Seoul. We’re an industry leader with a startup mentality. We take what we do seriously, but we don’t take ourselves too seriously. Creating and collaborating to transform the sound of streaming, content, and culture. Come join us—and let the world feel your work.

We are looking for a Security Engineer, specializing in Application or Product Security, you will form a key part of the Security Division here at Epidemic Sound. You, along with your team, will help ensure our customers and services are protected from a wide range of online threats. Although we are a global company, this position will be based in our Stockholm office.

Job Summary
Help to design and increase the maturity of our Secure Software Development Lifecycle (SSDLC) to remain resilient to ever changing attack vectors. Balance working closely with a small team of security experts with embedding regularly with product development teams to understand our product needs, build relationships, and translate security knowledge and best practices to best suit the needs of our product teams through in person interactions as well as code libraries and written documentation.

Responsibilities

  • Working closely with software engineering teams and individuals to identify, track and fix vulnerabilities/risks in our applications and products.

  • Expanding, architecting, implementing and evangelizing our SSDLC.

  • Sharing your knowledge through solid documentation, secure coding libraries, secure code reviews, delivering internal tech talks and security awareness training to technical staff.

  • Embedding within development teams to build secure awareness and accurately gauge risk profiles throughout our product environment.

  • Promoting secure ways of working across all areas of the organization.

  • Helping to identify and evaluate new security tools and services, and integrate existing tools and services into central dashboarding tools.

  • Assisting with security incidents (including on-call), breaches and training exercises around them, including creating security patches.

  • Working on a wide range of projects and new initiatives in the team.

  • Responding to product security-related requests from across the organization.

  • Mentoring junior security engineers.

  • Writing solid documentation that can be used by a wide range of different viewers.


Requirements

  • Experience securing products and applications, familiarity with BurpSuite Enterprise, Snyk and Burpsuite Professional especially appreciated.

  • Security features of the big public cloud providers (preferably GCP)

  • At least one programming or scripting language (Python, Go, Kotlin, Node.js, and Bash experience preferred)

  • Kubernetes, Docker or any other containerization architecture

  • Experience with Git, Github Actions and Terraform

  • Identifying vulnerabilities in software, systems and processes

  • Static code analysis

  • Writing test cases for existing code

  • Penetration Testing

And a good understanding or working knowledge of common security frameworks (ISO 27001, SOC2, PCI-DSS, NIST, etc), compliance and regulatory requirements.

Equal opportunity employer
We believe that bringing people together from different backgrounds, experiences and perspectives makes for a healthy workplace, a more successful business and a better world. We value diversity and encourage everyone to come and soundtrack the world with us.

Application
Ready to make the world feel your work? Please apply, in English, by clicking the link “interested” below.

Apply Here