Senior Cloud Security Engineer at Tripadvisor

February 23, 2026

No location

Full-time

RemotoJOB

Apply
Descripción

Job Description

Job Description
This position is crucial and combines proactive security engineering with reactive incident response. The selected person will work in the product's cloud environment, monitoring threats, responding to security incidents, automating defenses, and collaborating with engineering teams to build a more resilient platform.
Responsibilities:
Monitor, analyze, and investigate security alerts originating from AWS infrastructure, application logs, and security tools (WAF, SIEM, cloud-native tools).
Lead the response to security incidents that directly impact the Tripadvisor Experiences application, such as potential data breaches, application layer attacks, or infrastructure compromises.
Manage and classify vulnerabilities reported through the bug bounty program and other external sources.
Develop and maintain security monitoring and alerting capabilities within the production environment.
Automate security operations tasks using scripting languages ​​such as Python or Go to improve detection and response times.
Configure, tune, and manage security tools such as Web Application Firewall (WAF), AWS GuardDuty, and Security Hub.
Operationalize findings from application security tools (SAST, DAST, SCA), working with engineering teams to prioritize and remediate vulnerabilities in the code base and dependencies.
Perform threat models for new features in order to identify and mitigate risks before going into production.
Act as a security expert for the product and engineering teams, providing guidance on coding practices and architecture.
Requirements:
Experience protecting production environments on AWS. Knowledge of major security services such as GuardDuty, Security Hub, WAF and CloudTrail.
Complete knowledge of core AWS services beyond security tools (VPC networking, EC2, RDS, S3, Lambda, EKS). Ability to understand and configure a complete infrastructure with security criteria.
Terraform domain for the management and security of cloud infrastructure. Ability to read, write, and review Terraform code, ensuring that the defined infrastructure is secure by design.
Experience managing security incidents, from initial detection and analysis to containment, remediation and subsequent analysis.
Proficiency in at least one scripting language such as Python, Go or Bash to automate security operations and analysis tasks.
Understanding of common vulnerabilities in web applications (OWASP Top 10) and strategies to mitigate them.
Ability to use AI tools to improve efficiency, quality and decision making in daily work.
Ability to operate effectively with a global mindset.

Salary to receive
To agree