We are looking for an Information Security Specialist to strengthen our approach to cyber and business security. We need an expert who can embed security by default into our IT services, working closely with our IT Operations and Application Management teams.
We are actively integrating AI and automation into all areas of the business and expect candidates with mindset focused on improving efficiency and deliver a better user experience.
Key responsibilities
Secure Software Development Lifecycle (S-SDLC)
- Build S-SDLC mostly from scratch. Then own and continuously improve the company's secure SDLC framework: requirements, design and architecture review gates, secure coding standards, and the role of SAST/DAST and dependency scanning within the pipeline. Work with product and engineering teams on adoption, and track compliance against the framework.
SIEM implementation and management
- Define the SIEM architecture, log source inventory, retention requirements, correlation rules and alerting logic, building on the company's existing log-management approach. Partner with IT Operations and Enterprise IT, who own the underlying platform build and day-to-day maintenance.
Monitoring of information security systems
- Regularly review output from the company's security monitoring stack (endpoint detection and response, vulnerability scanning, SIEM, threat intelligence and etc.) and translate findings into prioritised, risk-based recommendations and escalations.
Information security audits
- Plan and run internal audits against ISO 27001 and the CIS Critical Security Controls (CIS18) or similar frameworks, maintain the related compliance trackers, and coordinate external audits, and penetration tests and remediation follow-up.
- Security architecture, configuration and “secure by default” analysis
- Prepare and analyse proposals for security architecture and secure configuration of infrastructure and products. Review new initiatives against “secure by default” and “secure by design” principles, and provide written recommendations to the owning teams.
Information security incident handling
- Participate in incident response as a governance and coordination function: support the incident team, review evidence and logs, coordinate the data-protection breach assessment, and own post-incident root-cause and lessons-learned documentation.
Zero Trust concept
- Design the company's Zero Trust roadmap — identity-centric access, least privilege, network micro-segmentation, Zero Trust network access — and drive its adoption across corporate and product infrastructure, in partnership with the teams that implement it.
Important, what this role is and is not:
- Is: governance, architecture and configuration review, audit planning and execution, monitoring oversight, and coordination during incident response.
- Is not: hands-on implementation of infrastructure changes, production system administration, or a place on an on-call / out-of-hours rotation.
- Hands-on access is expected for read purposes only — reviewing configurations, logs, dashboards and alerts to produce well-founded recommendations.
Requirements
- More than 6 years of hands-on experience in information security or IT infrastructure, with a strong technical background — this is what allows the Specialist to review configurations and logs credibly, even though the role itself is not hands-on.
- Solid understanding of web and mobile application vulnerabilities and secure coding practices (e.g., OWASP Top 10), Ability to identify, explain, and mitigate risks based on the OWASP framework, familiarity with OWASP ASVS (Application Security Verification Standard) for security requirements and testing.
- Practical knowledge of ISO 27001 and the CIS Critical Security Controls (CIS18) or similar frameworks; experience running or supporting internal or external security audits.
- Working knowledge of SIEM concepts and tools (e.g., Graylog, Splunk, Elastic, Microsoft Sentinel), secure SDLC / DevSecOps practices, vulnerability management, EDR, and identity and access management.
- Understanding of Zero Trust architecture principles and how to sequence their adoption.
- Strong written English and the ability to produce clear, business-facing documentation and recommendations.
Beneficial:
- Experience in a remote-first, multi-product SaaS or consumer software company.
- Prior exposure to GDPR or data-privacy work is an advantage.
- Familiarity with CrowdStrike Falcon, Invicti, or comparable EDR / vulnerability-scanning tools.
- Relevant certifications (e.g., CompTIA Security+, CSSLP, CISM, ISO 27001 Lead Auditor/Implementer, CISA or analogs).
Benefits
Creativity every day: Make inspiring products for musicians, artists and creators – no day is the same.
Impactful work Influence the future of the music industry and change the lives of millions worldwide.
Work set up: We’ll make sure you’re set up for success with the right work equipment, whether that’s company-provided hardware or an equipment allowance.
Growth and development: Receive specialized training, language lessons, conferences and learning materials.
Team well-being: Support for your mental health and wellbeing, including confidential help during life’s tougher moments.