Senior Product Security Engineer - AI & Cloud Defense

Senior Product Security Engineer - AI & Cloud Defense

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
SoundCloud

At a Glance

  • Tasks: Join our Security team to safeguard products against cyber threats and advocate for security best practices.
  • Company: SoundCloud, an artist-first platform connecting millions through music.
  • Benefits: Flexible work culture, generous PTO, professional development allowance, and wellness benefits.
  • Other info: Diverse and inclusive environment with excellent career growth opportunities.
  • Why this job: Make a real impact in securing innovative music technology while collaborating with talented teams.
  • Qualifications: 8+ years in product security, strong coding skills, and experience with cloud providers.

The predicted salary is between 80000 - 100000 £ per year.

SoundCloud empowers artists and fans to connect and share through music. Founded in 2007, SoundCloud is an artist-first platform empowering artists to build and grow their careers by providing them with the most progressive tools, services, and resources. With over 400+ million tracks from 40 million artists, the future of music is SoundCloud.

We are looking for a Principal Product Security Engineer to join our Security team! As a Product Security Engineer, you will collaborate cross-functionally with engineering teams to identify and address potential vulnerabilities in our products and services. You will advocate and shape security best practices across SoundCloud’s Engineering, Product, and Design (“EPD”) organization. This position offers a unique opportunity to play a direct, pivotal role in safeguarding our products against emerging cyber threats to our platform, artists and creators, and listeners and fans.

Key Responsibilities
  • Identify security anti-patterns in our codebases and architecture and drive cross-functional initiatives to systemically address them.
  • Help guide our Engineering and Product teams around the safe and responsible use of agentic AI in our products and Software Development Lifecycle (SDLC).
  • Drive efforts to automate the security of our SDLC, including our CI/CD pipelines.
  • Secure our AWS, GCP, and on-prem infrastructure through implementing proper access control and guardrails.
  • Conduct secure code reviews and threat modeling exercises to identify and remediate potential security vulnerabilities.
  • Define, implement, and oversee processes and policies in our Vulnerability Management Program.
  • Triage and drive to remediation submissions from our external bug bounty program.
  • Participate in our security incident response process.
  • Make recommendations to external teams and stakeholders about how to improve the consumer security of our platform.
  • Promote security best practices through educational initiatives such as CTFs and technical talks.
  • Improve internal tooling, processes, and documentation.
  • Help to define the Product Security program and team strategy.
  • Mentor and onboard team members.
Experience And Background
  • 8+ years of product or application security experience, or other relevant software engineering experience.
  • Deep expertise in designing secure architecture.
  • Enthusiasm about collaborating with engineering and product teams to proactively address security issues in products.
  • Experience conducting threat modeling exercises and secure code reviews.
  • Experience configuring DevSecOps tools (e.g. SAST, SCA, Secret Scanning).
  • Experience managing bug bounty programs.
  • Familiarity with languages such as Javascript, Go, Ruby, Python, or Scala.
  • Experience working with cloud providers (AWS, GCP) and Developer SaaS solutions (GitHub, Jira).
  • Familiarity with IaC tools such as Terraform and CloudFormation.
  • Ability to effectively communicate risk to technical and non-technical audiences.
  • Experience with data analysis (SQL) in order to determine scope and impact of vulnerabilities.
  • Knowledge of industry-standard security frameworks and regulations, such as GDPR, CCPA, SOC2, NIS2, and OWASP is a plus.
  • Experience with vulnerability management is a plus.
  • Experience threat modelling and securing Generative AI applications & use-cases in the context of the EU AI Act is a plus.
  • Experience with data governance is a plus.
About Us

We are a multinational company with offices in the US (New York and Los Angeles), Germany (Berlin), and the UK (London). We provide a flexible work culture that offers the opportunity to collaborate and connect in person at our offices as well as accommodating work from home. We are deeply committed to ensuring diversity, equity and inclusion at all levels of our organization and fostering a community where everyone’s voice, perspective and experience is respected and heard. We believe a strong team is made by investing in employees through mentorship, workshops and enrichment opportunities.

Benefits
  • Not located in Berlin? No worries, we offer extensive relocation support including allowances, one way flights, temporary accommodation and, by partnering with Expath, on the ground support on arrival.
  • Interested in a gym membership, photography course or book? We have a Creativity and Wellness benefit!
  • Employee Equity Plan.
  • Generous professional development allowance.
  • Flexible vacation and public holiday policy where you can take up to 35 days of PTO annually.
  • Various snacks, goodies, and 2 free lunches weekly when at the office.
Diversity, Equity and Inclusion at SoundCloud

SoundCloud is for everyone. Diversity and open expression are fundamental to our organization; they help us lead what’s next in music by understanding and empowering our creators and fans, no matter their identity. We acknowledge the challenges in the music industry, and strive to influence an inclusive culture where everyone can contribute respectfully and thrive, especially the historically marginalized communities that many of our creators, fans and SoundClouders identify with. We are dedicated to creating an inclusive environment at SoundCloud for everyone, regardless of gender identity, sexual orientation, race, ethnicity, migration background, national origin, age, disability status, or care-giver status. At SoundCloud you can find your community or elevate your allyship by joining a Diversity Resource Group. Diversity Resource Groups are employee-organized groups focused on supporting and promoting the interests of a particular underrepresented community in order to build a more inclusive culture at SoundCloud. Anyone can join, whether you share the identity or strive to be an ally.

Senior Product Security Engineer - AI & Cloud Defense employer: SoundCloud

At SoundCloud, we pride ourselves on being an exceptional employer that champions creativity and innovation in a flexible work environment. Our commitment to diversity, equity, and inclusion fosters a vibrant culture where every voice is valued, while our extensive professional development opportunities and generous benefits, including a Creativity and Wellness allowance, empower employees to thrive both personally and professionally. Join us in Berlin, where you can make a meaningful impact on the future of music while enjoying a supportive community and a balanced work-life experience.

SoundCloud

Contact Details:

SoundCloud Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Product Security Engineer - AI & Cloud Defense

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with SoundCloud employees on LinkedIn. A personal touch can make all the difference when it comes to landing that interview.

Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to security and AI. This gives you a chance to demonstrate your expertise beyond just a CV.

Tip Number 3

Prepare for the interview by brushing up on common security scenarios and challenges. Think about how you would tackle vulnerabilities in products similar to SoundCloud’s. We want to see your problem-solving skills in action!

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the SoundCloud team.

We think you need these skills to ace Senior Product Security Engineer - AI & Cloud Defense

Product Security
Application Security
Secure Code Reviews
Threat Modeling
DevSecOps Tools Configuration
Bug Bounty Program Management
Cloud Security (AWS, GCP)

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Senior Product Security Engineer role. Highlight your experience with secure architecture and collaboration with engineering teams, as these are key aspects of the job.

Showcase Your Skills:Don’t forget to mention your expertise in threat modelling, secure code reviews, and any relevant tools you've used like SAST or Terraform. We want to see how your skills align with our needs!

Be Authentic:Let your personality shine through in your application. We value diversity and want to know what makes you unique and how you can contribute to our inclusive culture at SoundCloud.

Apply Through Our Website:For the best chance of success, make sure to apply directly through our website. This way, we can easily track your application and get back to you quicker!

How to prepare for a job interview at SoundCloud

Know Your Stuff

Make sure you brush up on your product security knowledge, especially around secure architecture and threat modelling. Familiarise yourself with the specific technologies mentioned in the job description, like AWS, GCP, and the programming languages listed. This will show that you're not just a fit for the role but also genuinely interested in what they do.

Show Your Collaborative Spirit

Since this role involves working cross-functionally, be ready to discuss examples of how you've successfully collaborated with engineering and product teams in the past. Highlight any initiatives where you’ve driven security best practices or automated processes, as this will demonstrate your proactive approach.

Prepare for Technical Questions

Expect to dive deep into technical discussions during your interview. Prepare to explain your experience with DevSecOps tools and vulnerability management. You might even be asked to conduct a mock secure code review or threat modelling exercise, so practice articulating your thought process clearly.

Emphasise Your Passion for Security

SoundCloud values a culture of diversity and inclusion, so share your enthusiasm for promoting security best practices through educational initiatives. Talk about any workshops, talks, or community involvement you've had in the security space. This will help you connect with their mission and show that you’re a great cultural fit.