Security Engineer II (AWS, SecOps)
Confirmed live in the last 24 hours
Tripadvisor
Job Description
About Tripadvisor
The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world’s most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global audience with partners through rich content, travel guidance, and two-sided marketplaces for experiences, accommodations, restaurants, and other travel categories. The subsidiaries of Tripadvisor, Inc. (Nasdaq: TRIP), include a portfolio of travel brands and businesses, including Tripadvisor, Viator, and TheFork.
We are looking for a hands-on Cloud Security Engineer II (AWS, SecOps) to be the first line of defense for the Tripadvisor Experiences platform. This is a critical mid-level role that blends proactive security engineering with reactive incident response. You will live and breathe in our product's cloud environment, monitoring for threats, responding to security incidents, automating defenses, and working closely with our engineering teams to build a more resilient platform.
Job Location: Remote. This role is a remote or hybrid position in Portugal. Occasional travel to company offices as necessary.
What You’ll Do:
Product-Focused Incident Response:
- Monitor, analyze, and investigate security alerts originating from our AWS infrastructure, application logs, and security tooling (WAF, SIEM, Cloud-Native tools).
- Respond to security incidents that directly impact the Tripadvisor Experiences application, such as potential data breaches, application-layer attacks, or infrastructure compromises.
- Triage vulnerabilities reported through our bug bounty program and other external sources.
Security Engineering & Automation:
- Build and maintain security monitoring and alerting capabilities within our production environment.
- Automate security operations tasks using scripting languages like Python or Go to improve our detection and response times.
- Configure, tune, and help manage security tools like our Web Application Firewall (WAF), AWS GuardDuty, and Security Hub.
Vulnerability Management & Collaboration:
- Operationalize findings from application security tools (SAST, DAST, SCA) by working with engineering teams to prioritize and remediate vulnerabilities in our codebase and dependencies.
- Conduct threat modeling for new features to identify and mitigate risks before they reach production.
- Collaborate with engineering teams and provide guidance on secure coding practices and architecture.
Skills & Experience:
- AWS Security Operations: Hands-on experience securing a production environment in AWS. You must be comfortable with its core security services (e.g., GuardDuty, Security Hub, WAF, CloudTrail).
- AWS Cloud Infrastructure: A good understanding of core AWS services beyond just security tools (e.g., VPC networking, EC2, RDS, S3, Lambda, EKS). You must be capable of understanding and spinning up a full infrastructure stack to effectively secure it.
- Infrastructure as Code: Proficiency with Terraform for managing and securing cloud infrastructure. You should be able to read, write, and review Terraform code, ensuring that the infrastructure you define is secure by design.
- Incident Response: Proven experience with the full lifecycle of security incidents, from initial detection and analysis to containment, remediation, and post-mortem.
- Scripting for Automation: Proficiency in at least one scripting language (e.g., Python, Go, Bash) to automate security operations and analysis tasks.
- Application Security Fundamentals: A solid understanding of common web application vulnerabilities (OWASP Top 10) and how to defend against them.
- Demonstrated ability to use AI tools to improve efficiency, quality, and decision-making in day-to-day work.
- Proven ability to operate effectively with a global-first mindset.&l
Similar Jobs
Five9
Senior Staff DevOps Engineer
Five9
Senior Staff DevOps Engineer
Parloa
Forward Deployed Engineer, DevOps
Pure Storage
Senior SW Engineer Python/Java (Security)
Booz Allen Hamilton
AWS DevOps Cloud Engineer
Red Hat