Experience Inc. Jobs

Job Information

SiriusXM Radio, Inc. Application Security Engineer in New York, New York

Who We Are:

SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners -- in the car, at home, and anywhere on the go with connected devices. Our vision is to shape the future of audio, where everyone can be effortlessly connected to the voices, stories and music they love wherever they are.

This is the place where a diverse group of emerging talent and legends alike come to share authentic and purposeful songs, stories, sounds and insights through some of the best programming and technology in the world. Our critically-acclaimed, industry-leading audio entertainment encompasses music, sports, comedy, news, talk, live events, and podcasting. No matter their individual role, each of our employees plays a vital part in bringing SiriusXM's vision to life every day.

SiriusXM is the leading audio entertainment company in North America, and the premier programmer and platform for subscription and digital advertising-supported audio products. SiriusXM's platforms collectively reach approximately 150 million listeners, the largest digital audio audience across paid and free tiers in North America, and deliver music, sports, talk, news, comedy, entertainment and podcasts. Pandora, a subsidiary of SiriusXM, is the largest ad-supported audio entertainment streaming service in the U.S. SiriusXM's subsidiaries Simplecast and AdsWizz make it a leader in podcast hosting, production, distribution, analytics and monetization. The Company's advertising sales organization, which operates as SiriusXM Media, leverages its scale, cross-platform sales organization and ad tech capabilities to deliver results for audio creators and advertisers. SiriusXM, through SiriusXM Canada Holdings, Inc., also offers satellite radio and audio entertainment in Canada. In addition to its audio entertainment businesses, SiriusXM offers connected vehicle services to automakers.

How you'll make an impact:

The Application Security Engineer will join the security organization to support SiriusXM technology objectives. The ideal candidate has a passion for finding opportunities and inspiration to solve security challenges and will do so by providing tools, guidance, context and continuous support to ensure the security success of our software and applications.

What you'll do:

  • Build and document security features to enable developers to write secure code.

  • Facilitate the implementation and continual improvement for a secure SDLC.

  • Secure tool creation, enabling security by default by building security and tooling into the software development process, conducting regular audits and tests to identify risks and prioritizing fixes.

  • Drive the technical implementation of our security solutions by providing necessary guidance and technical leadership to the SiriusXM engineering community.

  • Develop and improve the Application Security capabilities of SiriusXM by continually designing runbook procedures and expanding the scope and capabilities of security tools.

  • Consulting and systems development responsibilities for needs brought to the Application Security team by the business.

  • Write and design SDKs, containers images, guardrails, and testing suites.

  • Design, implementation, facilitation, and maintenance of tooling and frameworks to make adoption of security guardrails and best practices easier for developers when working in our code bases.

  • Participate in the design and implementation of applications, services, and infrastructure to ensure security and privacy design principles are being followed by performing security reviews and threat modeling.

  • Work within a collaborative team to develop scripts and software to solve for security automation and development needs.

  • Aid in secure code reviews, focused on security bug reduction.

  • Develop documentation, training, and security baselines to inform and educate the engineers, IT practitioners and developers on best practices.

  • Deploy, manage, and tune infrastructure used to protect our applications from common vulnerability exploitation, account takeover, and denial of service attacks.

  • Triage, escalate, and remediate vulnerabilities found as part of our vulnerability management program, bug bounty program and discovered in enterprise penetration tests.

  • Work with the product management teams to prioritize fixes for vulnerabilities and work with engineering teams to understand how to fix these issues.

  • Conducting root cause analysis of security findings to develop systematic improvements to develop processes, tooling, and security checks.

  • Fixing vulnerabilities, building in security telemetry/instrumentation, and adding security features to our products/applications.

  • Participate with the architecture and planning for company-wide security efforts.

  • Form a strong relationship with developer teams and serve as point of contact and security SME for questions arising around secure development.

  • Actively participate in all facets of the incident response lifecycle.

What you'll need:

  • 3+ years of software development experience, 2+ years of security (direct or adjacent) experience.

  • Proficient in at least one primary development language (preferably Python and Java/Scala).

  • Some experience with mobile application security preferred (Kotlin and Swift).

  • Experience with internal development for identity management, Cognito, OIDC, SAML, and SSO integration development.

  • Experience with AWS and/or GCP.

  • Experience calling REST and/or GraphQL APIs.

  • Experience administering application security tools such as SAST, SCA, DAST.

  • Knowledge of OWASP classifications and how to implement security checks for these vulnerabilities.

  • Ability to understand security code reviews.

  • Understanding of continuous integrations, testing, and delivery.

  • Ability to discover, document and fix security bugs.

  • Experience using Git and related, development processes in a professional setting.

  • Knowledge of JIRA (Issue/bug tracking), Confluence.

  • Experience writing educational documentation or knowledge bases.

  • Security mindset, self-starter, and ability to operate independently.

  • Be an organized and responsive problem solver.

  • Excellent oral/written presentation skills with the ability to teach and communicate effectively to developers and leadership.

  • Passionate about understanding complex systems.

  • Eager to learn, adapt, and improve your work.

  • Must have legal right to work in the U.S.

At SiriusXM, we carefully consider a wide range of factors when determining compensation, including your background and experience. These considerations can cause your compensation to vary. We expect the base salary for this position to be in the range of $64,700 to $131,300 and will depend on your skills, qualifications, and experience. Additionally, this role might be eligible for discretionary short-term and long-term incentives. We encourage all interested candidates to apply.

Our goal at SiriusXM is to provide and maintain a work environment that fosters mutual respect, professionalism and cooperation. SiriusXM is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, national origin, ancestry, alienage or citizenship status, age, disability or handicap, sex, gender identity, marital status, familial status, veteran status, sexual orientation or any other characteristic protected by applicable federal, state or local laws.

The requirements and duties described above may be modified or waived by the Company in its sole discretion without notice.

R-2024-07-87

As an EEO/Affirmative Action Employer all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status.



Minimum Salary: 31200.00 Maximum Salary: 31200.00 Salary Unit: Yearly

DirectEmployers