
Musixmatch · Italy or Remote
About Musixmatch Musixmatch is the leading music metadata company, featuring the world’s largest lyrics catalog and a community of over 80M contributors. Musi...
About Musixmatch
Musixmatch is the leading music metadata company, featuring the world’s largest lyrics catalog and a community of over 80M contributors. Musixmatch is the trusted global partner of companies like Spotify, Apple, Amazon Music, Meta, Google, YouTube, Tidal, and Snapchat and works with nearly 4,000 music publishing rightsholders (representing more than 225,000 songwriters), including Sony Music Publishing, Universal Music Publishing, Warner/Chappell, Kobalt, BMG Rights, and the Harry Fox Agency.
We are a bunch of creatives who care about our work and what we do. We believe that participation and collaboration are key to getting things done well. We are looking for tech-savvy people who are eager to learn in a fast-paced environment, who have an international outlook on life, and who love taking on new challenges.
We are looking for a Security Practice Lead to own and drive information security across our organization. You will shape our security strategy, protect our systems, data, and expanding AI infrastructure, and act as a key voice in company-wide decisions. This is a high-impact, cross-functional role at the intersection of engineering, AI development, compliance, and leadership.
Define and own the security strategy: Oversee comprehensive security across cloud, network, and application layers, partnering with engineering on vulnerability management.
Secure AI & ML integrations: Establish and enforce security guardrails for AI pipelines and LLM deployments, protecting against AI-specific threats (e.g., prompt injection, data poisoning, supply chain) and ensuring model safety.
Risk & Incident Management: Assess security risks, monitor processes continuously, and coordinate effective incident response and recovery efforts.
Policy & Compliance: Develop and manage security policies, ensuring compliance with privacy laws, standard frameworks, and emerging AI regulations (e.g., EU AI Act), aligning closely with DPO directives.
Cross-functional Leadership: Collaborate with senior leadership to embed security (and AI security-by-design) into business decisions.
Security Evangelism, Training & Vendor Management: Champion a security-first culture across the company. Design and deliver training programs, run awareness campaigns, and act as an internal advocate who makes security understandable and relevant for everyone, from engineers to non-technical teams. Manage risk assessments for external vendors and consultants to ensure third-party security standards are met.
Proven information security leadership experience with the ability to translate technical risks into business language
Deep knowledge of standard security frameworks (ISO 27001, SOC 2, GDPR) and strong background in policy development
Solid understanding of AI security: familiarity with AI-specific vulnerabilities (e.g., OWASP Top 10 for LLMs) and experience securing data privacy within machine learning pipelines
Hands-on experience with cloud, application, and device security (MDM), incident management, and post-incident recovery
Ability to work cross-functionally with engineering, product, AI/Data, legal, and executive teams
Security certifications such as CISSP, CISM, CEH, or CAISP (Certified AI Security Professional)
Familiarity with AI risk management frameworks (e.g., NIST AI RMF)
Experience in the music, media, or entertainment tech industry
Familiarity with DPO workflows, privacy-by-design principles, and working with regulatory bodies
Relocation to Bologna (Italy) or remote work. We are a hybrid company.
Italian and English language lessons.
Top-class tech and equipment.
Company-wide retreats.
The gross annual base salary for this role is €60,000-€70,000, calibrated on experience and seniority. The package includes a variable performance bonus tied to individual and company goals, plus a flexible welfare credit to use on the benefits that matter most to you. As a distributed team hiring across multiple countries, compensation may vary based on local market benchmarks and employment conditions in the candidate’s location.
ABOUT US: SRLabs is home to knowledge leaders securing critical infrastructures in finance, energy, and telecommunications. We focus on hands-on hacking resilience – not compliance –, which we shape by combining our hacking research with impactful consulting work for innovation leaders that have a natural thrive for cutting-edge technologies. We come from diverse backgrounds from all over the world, and that's just the way we like it. From coding, reverse engineering, penetration testing, exploit scripting, process design, research and consulting skills, our mix of colleagues possesses a vast set of qualifications, that equips us to influence design decisions of large-scale organisations. YOUR RESPONSIBILITIES Job brief: In this role, you lead a team of security consultants delivering consulting and assessment services such as offensive assessments, resilience improvements, or AI security engagements for some of the world's most complex organisations. You are equally comfortable in front of a client board and in the weeds of a red team debrief. Your responsibilities: * Lead and oversee security engagements including red teaming, TIBER/DORA resilience assessments, penetration testing, and AI-focused security reviews and others * Act as the primary point of contact for senior client stakeholders – translating technical findings into business risk and actionable recommendations * Manage project delivery across scope, timeline, quality, and team utilisation * Mentor and develop junior and mid-level consultants, providing hands-on guidance on complex engagements * Drive business development by contributing to proposals, scoping, and client relationships * Shape our AI security offering – including LLM red teaming, model security assessments, and AI risk frameworks * Contribute to research and thought leadership that keeps SRLabs at the cutting edge WHAT DO YOU BRING? * Proven hands-on background in security with the credibility to lead technical teams * Experience leading or managing security consulting engagements, including client-facing delivery at senior levels * Solid understanding of enterprise and resilience frameworks * Familiarity with AI/ML security concepts * Ability to communicate complex security issues clearly to both technical and non-technical audiences * Strong communication skills in English and German is nice to have * Experience writing proposals, scoping engagements, and managing expectations WHAT AWAITS YOU WITH US? * A senior role with real influence over how we build and grow our offensive security practice * Diverse team of motivated security experts from many countries and backgrounds * Opportunity to shape cutting-edge AI security work before it becomes mainstream * Annual company retreat – a week of working holiday packed with fun, team building, and knowledge sharing * Professional development: conference speaking, research publication, and training budget * Competitive salary and flexible home office * 30 days vacation period * A wide range of benefits (discounts on Urban sports gym and Public transport ticket) APPLY NOW We are looking forward to getting to know you! SRLabs is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for our team.
At i3D.net, we provide world-class global coverage with one of the most interconnected networks in the world. Our solutions focus on low latency, zero packet loss, and unmatched scalability, enabling seamless experiences for millions of users worldwide. With dedicated support, bespoke solutions, and cutting-edge technology, we deliver reliable, cost-efficient infrastructure that empowers game developers and businesses to scale effortlessly. Partnering with major names like Nvidia, DuckDuckGo, and Ubisoft, we are shaping the future of gaming and network technology. WHY YOUR ROLE MATTERS At i3D.net, we’re building our internal security foundation, and you’ll be right at the center of it. As our Lead Security Analyst, you’ll play a key role in securing our Microsoft environment (including Azure, Entra ID, and IAM), while also working on broader topics like incident response, tooling improvements, and DDOS investigations. We’re currently moving to a new Microsoft tenant, which means you’ll help shape security from the ground up. This includes defining how access is managed, working closely with the Workspace Management (WSM) team, and supporting the rollout of new security controls and monitoring tools. You’ll collaborate closely with our other Security Analysts and subject matter experts to strengthen detection and response and help support our future SOC capabilities and i3D’s overall security program. WHAT YOU’LL BE DOING * Ownership of securing our environment from the physical layer all the way up to application: Help design and improve the security of our Azure tenant, Entra ID, and identity and access setup. * Partner with the Workspace Management (WSM) team: You’ll guide protecting employees, endpoints and tools. Coordinate with the team that manages rights, starters, movers, and leavers, so access stays under control and risks are caught early. * Tracking, and handling escalated alerts and incidents: Investigate alerts, respond to breaches or policy violations, and make sure issues are resolved properly. * Drive continuous improvement: Suggest smarter ways of working, contribute to the development of security tools and processes, and strengthen the overall security posture of the company. * Partnering with Risk and Compliance teams: maintain and enable our compliance with frameworks such as ISO27001 and NIS2 * Lead vulnerability management: Drive system patching efforts for user endpoints and server infrastructure, making sure vulnerabilities are addressed quickly and effectively. * Support our SOC setup: Help implement or improve tooling like SIEM and SOAR together with the other Security Analyst(s) and partners. * Stay ahead of threats: Track what’s happening in the security world and help us stay a step ahead. * Keep others informed: Make sure relevant updates get to the right people, and that security processes are well documented. * Collaborate with external partners: Join conversations with groups like CSIRT-DSP and handle outside security contacts when needed. * Work with internal teams: Server as a SME and business partner to aid other departments and product teams to improve how they handle security in their own systems and workflows. WHAT SUCCESS LOOKS LIKE IN THE FIRST YEAR * Our technology environment is safer, easier to manage, and aligned with best practices. * Alerts and incidents are handled faster and with more confidence, reducing overall risk. * Our SOC tooling and processes have improved, thanks to your input and collaboration. * Vulnerability management is running smoothly, and critical systems are patched on time. * The company’s overall security posture has strengthened - security is embedded in workflows and visible across teams. * You’ve made yourself known across the company as someone who drives security forward and gets things done. YOUR PROFILE * Broad security ownership experience: You bring 5+ years of experience securing enterprise environments and have owned security outcomes across identity, infrastructure, endpoints, cloud, and incident response. You have been responsible for improving security posture, not just monitoring it. * Deep Microsoft security expertise: You have hands-on experience securing Azure, Entra ID, Conditional Access, Privileged Identity Management (PIM), Intune, and Microsoft Defender. You understand how to design and implement secure identity and access controls at scale. * SOC/Blue Team experience: You've monitored, detected, and responded to security threats in live environments, led incident investigations, and coordinated remediation across multiple teams. * Security tooling and detection engineering: You have experience implementing and improving SIEM, SOAR, and detection capabilities, developing use cases, tuning alerts, and increasing the effectiveness of security monitoring. * Vulnerability management leadership: You have driven vulnerability remediation programs, partnered with infrastructure teams to prioritize risks, and ensured critical findings are resolved effectively. * Security architecture and stakeholder influence: You are comfortable advising technical teams, challenging existing approaches, and helping shape security controls, standards, and processes across the organization. * Reliable and flexible when needed: You’re available when something urgent comes up, even outside of regular hours. * Netherlands-based and Hybrid-ready: You live in the Netherlands and are happy to join us on-site around two days a week. GOOD TO HAVES * Experience with SIEM and SOAR tooling: It’s a plus if you’ve worked with tools like Wazuh, Sentinel or Splunk and helped set them up or improve how they’re used. * Certifications: CISSP, CISM, CompTIA Security+, CySA+, AZ-500, or SC-900 or other relevant security certifications help, but your real experience matters most. * Familiarity with secure development practices is a bonus. WHY JOIN US? * Real Impact: Your work directly protects our employees, platform, our customers, and the broader internet, from handling DDOS cases to shaping how we secure our systems. * Small Team, Big Ownership: You’re not just a cog in the machine; you’ll help shape tools, processes, and how we grow our security practice. * Competitive Perks: Enjoy great pay, shift bonuses, annual bonus, 25 vacation days (excluding national holidays), travel allowance, and a premium-free pension. * Skill Development: Level up with career guidance and education reimbursement. * Gaming Perks: Get lifetime access to Ubisoft’s game library and two free games every year. * Stay Active: Use our in-house gym in Rotterdam or unwind in the game and music rooms.
About Yondr Yondr is a disruptor. We challenge convention and simplify complexity. A global developer, owner operator and service provider of data centers, we deliver complex data center capacity needs for the world’s largest tech companies. Our exponential growth sees us looking for extraordinary people to help accelerate us towards our vision: a tomorrow without constraints. But we can’t do this without you. About the Role Our business is growing and we need an experienced Information Security engineer to join our Global Technology Security team with a proven track record of building/operating in a modern Information Security practice in a global organisation. You will have developed, managed and implemented information security controls and processes. This will involve a range of activities including consultative engagements, project-work, pro-active security testing, vulnerability management, auditing, reporting and investigations. You’ll be responsible for conducting risk assessment, policy creation and awareness training while staying up to date with other industry best practices. You’ll be hands-on with a variety of security technology and interact with various internal teams to lead and deliver best-in-class solutions in an exciting fast-paced environment. Dynamic, smart people and inspiring, innovative technologies are the norms here. Main Responsibilities * Drive the evolution of the company’s Information Security standards to maintain best practice and alignment with corporate policies and regulatory requirements * Be hands on in managing and maturing our security technology and processes * Investigate and respond to information and cybersecurity incidents * Provide consultation and/or education as needed and drive the adoption of security as a value add/best practice * Work in partnership with stakeholders, to ensure all projects, changes, IT standards and procedures are compliant with Information Security Standards and Policies * Manage (third party) penetration testing and facilitate any subsequent remediation activities * Act as a subject matter expert on matters of Information security relating to Yondr * Conduct 3rd party risk assessments to ensure suppliers are aligned with our security standards and fall within our risk tolerances * Manage phishing platform, training and related reporting * Provide guidance and subject matter expertise on processes, controls, and objectives around audit and information security activities, best practices, and process improvements * Conduct vulnerability assessments, risk analyses, and remediation tracking to drive the attack surface management program * Conduct Identity and Access Management entitlement reviews of key platforms and applications * Engage in audits, compliance assessments, and regulatory security requirements * Maintain documentation related to security processes, incidents, and compliance requirements Qualifications and experience * Experience with regulatory and compliance standards; ISO27001, SOC2, PCI DSS * 5+ years experience working as an information security professional within a medium to large sized global organisation * Proven experience implementing, maintaining and leading an effective information security control assurance programme * Strong stakeholder management and communication skills, including technical members of staff and senior non-technical business leaders * Applied working knowledge of networking principles and the OSI model to evaluate control effectiveness and support investigation of network‑based security incidents * Background in working with international organizations that provide 24x7x365 operations * Must understand OT, Network and Zero-trust architecture * Understanding of email security tools, vulnerability management, penetration testing and remediation * Strong analytical, troubleshooting, and problem-solving skills * Information Security, alongside significant knowledge and experience of Cyber security * Working knowledge of Microsoft Sentinel, Qualys, Microsoft Defender, Knowbe4 are essential. * Exposure to Microsoft Purview, MDR services, UBA and IT/OT network environment are desirable * Excellent verbal and written communication skills * Ability to manage multiple priorities and work independently or within a team environment * Relevant certifications preferred, such as: * * CISSP * * Security+ * * CISA * * CEH * * GSEC * * Microsoft Certifications At Yondr, we want to enhance the diversity, equity, inclusion and belonging of our workforce to reflect the world we live in. Our roles are potential opportunities for everyone; all interested parties, regardless of nationality, race, ethnicity, religion, age, sexual orientation, or gender, are welcome to apply. We ensure all candidates have equitable access and consideration throughout the hiring process. Yondr is committed to fostering a welcoming, safe and inclusive work environment. We provide support through our benefits, which are inclusive of all backgrounds.