<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>f95a801d-05e</externalid>
      <Title>Backend Software Engineer - Security Compliance Engineering Team</Title>
      <Description><![CDATA[<p>We are looking for an experienced backend software engineer to join our security compliance engineering team. As a security engineer at Spotify, you will protect the security of our platform and users.</p>
<p>Your primary responsibility will be to design products, services, and infrastructure that support and strengthen our technical security Governance, Risk, and Compliance (GRC) strategy. You will build infrastructure and tooling that apply regulatory requirements and security framework controls across our distributed environment. Additionally, you will help drive scalable and consistent engineering practices that address security, risk, and compliance requirements.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Designing products, services, and infrastructure that support and strengthen our technical security GRC strategy</li>
<li>Building infrastructure and tooling that apply regulatory requirements and security framework controls across our distributed environment</li>
<li>Helping drive scalable and consistent engineering practices that address security, risk, and compliance requirements</li>
</ul>
<p>Requirements include:</p>
<ul>
<li>Experience as a software engineer with development experience in an object-oriented programming language such as Java</li>
<li>Comfortable with data engineering</li>
<li>Experience writing distributed, high-volume services and deploying and operating them in production</li>
<li>Deep understanding of system design, data structures, and algorithms</li>
<li>Hands-on experience implementing security controls and safeguards in software systems, working within cybersecurity and security GRC frameworks</li>
<li>Excellent written and verbal communication skills, including experience meeting and presenting to senior leaders and non-technical stakeholders</li>
</ul>
<p>This role is based in London or Stockholm, with flexibility to work from home. We offer a competitive salary and benefits package.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Java, data engineering, distributed systems, security controls, cybersecurity, GRC frameworks</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Spotify</Employername>
      <Employerlogo>https://logos.yubhub.co/spotify.com.png</Employerlogo>
      <Employerdescription>Spotify is a music streaming service with over 700 million users.</Employerdescription>
      <Employerwebsite>https://www.spotify.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/spotify/b1f7eac7-40bd-47a9-8564-d2d4e4bf1062</Applyto>
      <Location>London</Location>
      <Country></Country>
      <Postedate>2026-03-31</Postedate>
    </job>
    <job>
      <externalid>fb2a71fd-1e2</externalid>
      <Title>Security GRC Engineer</Title>
      <Description><![CDATA[<p><strong>About the role</strong></p>
<p>Security GRC Engineers design, implement, and scale our governance, risk, and compliance (GRC) program. You will lead automation of compliance workflows, build self-serve tools to enable GTM teams, and ensure our products and infrastructure meet the highest security standards. This role combines technical implementation with strategic program development, directly shaping how we build trust with customers.</p>
<p><strong>You may be a fit if</strong></p>
<ul>
<li>You have experience with GRC frameworks (SOC 2, ISO 27001, ISO 27701, ISO/IEC 42001).</li>
<li>You have hands-on technical skills to automate compliance workflows and integrate with engineering systems.</li>
<li>You have proven ability to balance technical implementation with program strategy.</li>
<li>You have strong cross-functional collaboration skills, especially with engineering, GTM, and auditors.</li>
</ul>
<p><strong>Sample projects include</strong></p>
<ul>
<li>Automate evidence gathering and continuous control testing.</li>
<li>Optimise compliance monitoring and alerting systems; provide guidance on remediation.</li>
<li>Generate security program KPIs and maintain a platform for documenting risks, controls, and assessments.</li>
<li>Build self-serve tools and automation to streamline customer security diligence.</li>
<li>Support GTM teams by providing scalable ways to address customer security concerns.</li>
<li>Maintain corporate security policies and map them to relevant frameworks.</li>
<li>Draft security best practices and drive company-wide awareness and training programs.</li>
<li>Lead the development and maturity of GRC strategies aligned with SOC 2, ISO 27001, ISO/IEC 42001, and related standards.</li>
<li>Partner with auditors, regulators, and business stakeholders to define and implement security requirements and controls.</li>
<li>Conduct security compliance reviews for new products, features, and vendors.</li>
</ul>
<p><strong>Benefits</strong></p>
<ul>
<li>Competitive salary</li>
<li>Opportunity to work with a talented team</li>
<li>Professional development and growth opportunities</li>
<li>Flexible working hours</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Will you now or in the future require visa sponsorship to work in the country where this position is located?</li>
<li>Has someone at Cursor referred you for this role? If so, please include their email here</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>GRC frameworks, SOC 2, ISO 27001, ISO 27701, ISO/IEC 42001, Compliance workflows, Engineering systems, Cross-functional collaboration, Auditing, Security best practices, GTM teams, Auditors, Regulators, Business stakeholders</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Cursor</Employername>
      <Employerlogo>https://logos.yubhub.co/cursor.com.png</Employerlogo>
      <Employerdescription>Cursor is a technology company that designs and implements governance, risk, and compliance (GRC) programs. It has a team of experienced professionals who work together to build trust with customers.</Employerdescription>
      <Employerwebsite>https://cursor.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://cursor.com/careers/security-grc-engineer</Applyto>
      <Location></Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
  </jobs>
</source>