Tripadvisor logo
Tripadvisor

Tripadvisor, founded in 2000, is an award-winning network for travel information that features real advice from global travelers. The world’s largest travel s

Cloud Security Engineer II

Location

Poland

Posted

4 days ago

Salary

0

Seniority

Mid Level

Job Description

Cloud Security Engineer II

Tripadvisor

Role Description We are looking for a hands-on Cloud Security Engineer II (AWS, SecOps) to be the first line of defense for the Tripadvisor Experiences platform. This is a critical mid-level role that blends proactive security engineering with reactive incident response. You will live and breathe in our product's cloud environment, monitoring for threats, responding to security incidents, automating defenses, and working closely with our engineering teams to build a more resilient platform. Job Location: Poland, remote. We are able to offer only permanent contracts (umowa o pracę). What You’ll Do: - Product-Focused Incident Response: - Monitor, analyze, and investigate security alerts originating from our AWS infrastructure, application logs, and security tooling (WAF, SIEM, Cloud-Native tools). - Respond to security incidents that directly impact the Tripadvisor Experiences application, such as potential data breaches, application-layer attacks, or infrastructure compromises. - Triage vulnerabilities reported through our bug bounty program and other external sources. - Security Engineering & Automation: - Build and maintain security monitoring and alerting capabilities within our production environment. - Automate security operations tasks using scripting languages like Python or Go to improve our detection and response times. - Configure, tune, and help manage security tools like our Web Application Firewall (WAF), AWS GuardDuty, and Security Hub. - Vulnerability Management & Collaboration: - Operationalize findings from application security tools (SAST, DAST, SCA) by working with engineering teams to prioritize and remediate vulnerabilities in our codebase and dependencies. - Conduct threat modeling for new features to identify and mitigate risks before they reach production. - Collaborate with engineering teams and provide guidance on secure coding practices and architecture. Qualifications - Hands-on experience securing a production environment in AWS. - A good understanding of core AWS services beyond just security tools (e.g., VPC networking, EC2, RDS, S3, Lambda, EKS). - Proficiency with Terraform for managing and securing cloud infrastructure. - Proven experience with the full lifecycle of security incidents, from initial detection and analysis to containment, remediation, and post-mortem. - Proficiency in at least one scripting language (e.g., Python, Go, Bash). - A solid understanding of common web application vulnerabilities (OWASP Top 10) and how to defend against them. - Demonstrated ability to use AI tools to improve efficiency, quality, and decision-making in day-to-day work. - Proven ability to operate effectively with a global-first mindset. Benefits - Competitive compensation packages (routinely benchmarked against the latest industry data), including base salary and annual bonuses. - “Work your way” with flexibility to suit your lifestyle. - Flexible schedule. Work-life balance is ingrained in our culture by design. - Donation matching. Give back? Give more! - Tuition assistance. Receive annual support for qualified programs. - Lifestyle benefit. An annual benefit to spend on yourself. - Travel perks. Discounts and more. - Employee assistance program. Resources and programs to help you through life’s challenges. - Health benefits. Great coverage and competitive premiums.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001+Since 1976

• Serve as the executive owner of the U.S. customer contractual security program. • Interpret customer security requirements and translate them into standardized operational policies and procedures. • Ensure all security obligations are implemented, documented, maintained, and audited throughout the customer lifecycle. • Partner with Commercial, Customer Success, Solutions Design, and Operations teams during customer pursuits, onboarding, and implementations. • Act as the primary executive contact for customer security matters, audits, escalations, and compliance reviews. • Establish scalable governance processes to ensure consistent execution of customer security requirements across all U.S. locations. • Own the physical security governance program for all U.S. Contract Logistics facilities. • Develop and maintain enterprise security standards, policies, procedures, and operating guidelines. • Implement network-wide security scorecards, performance metrics, and executive reporting. • Lead customer, internal, and third-party security audits. • Ensure timely remediation and sustainable closure of audit findings. • Conduct facility security assessments and enterprise-wide risk evaluations. • Identify vulnerabilities and prioritize mitigation activities based on business and customer impact. • Provide security approval and governance for new facilities, customer implementations, expansions, and major facility modifications. • Collaborate with global Security, Operations, Compliance, Engineering, and Quality teams to drive standardized security programs and practices. • Lead, mentor, and influence cross-functional teams responsible for security program execution.

Arizona + 12 moreAll locations: Arizona | Colorado | Illinois | Kentucky | Nevada | New Jersey | Ohio | Mississippi | Pennsylvania | Texas | Utah | Virginia | Washington
$160.5K - $200.6K / year
ClickHouse logo

Manager, Information Security

ClickHouse

ClickHouse is an open-source, column-oriented OLAP database management system.

Full TimeRemoteTeam 51-200Since 2016H1B Sponsor

Role Description This role sits at the intersection of product management, security engineering, compliance, legal, and cloud infrastructure. You will own the information security strategy for regulated cloud offerings, certifications, sovereign cloud deployments, and specialized regional offerings that enable customers to operate ClickHouse in highly restricted environments. - Define and execute the multi-year roadmap for achieving ClickHouse for Government certifications (FEDRAMP, DOD-IL, StateRAMP, CJIS, etc). - Partner closely with Security, Engineering, Compliance, Legal, GTM, and Operations teams to ensure ClickHouse Cloud meets the requirements of frameworks including SOC 2, ISO 27001/27701, HIPAA, PCI DSS, and government-specific standards (FIPS, Common Criteria / Protection Profile, NIST SP800-171, CMMC, Sec 508/VPAT, DISA STIG). - Translate complex regulatory and security requirements into scalable product capabilities across identity and access management (IAM), encryption, key management, audit logging, access controls, and operational security. - Drive product requirements for FIPS-compliant cryptographic modules and government-specific deployment and licensing models. - Establish long-term strategy for enterprise security capabilities that support regulated industries worldwide. - Own the product strategy and roadmap for sovereign cloud offerings, including the European Sovereign Cloud (ESC), Kingdom of Saudi Arabia (KSA), and future sovereign cloud regions. - Own and deliver long-term Five-Eyes Sovereign Cloud Deployments. - Define product capabilities that address data residency, personnel access controls, customer-managed encryption, and operational sovereignty requirements. - Work with cloud providers and strategic partners to enable deployments in restricted and regulated environments, including offerings such as Assured Workloads and sovereign cloud frameworks. - Partner with legal, compliance, and regional stakeholders to navigate evolving global regulations and regional market requirements. Qualifications - 8+ years of product management experience, including significant experience building cloud infrastructure, platform, security, or enterprise SaaS products. - Deep understanding of FedRAMP certification requirements and the challenges of operating compliant multi-tenant cloud services. - Strong technical understanding of modern cloud architectures across AWS, Azure, and GCP. - Experience with security domains including IAM, network isolation, private connectivity, encryption, key management systems (KMS/BYOK), audit logging, and access controls. - Familiarity with global data residency and sovereignty requirements, including GDPR and emerging regional regulatory frameworks. - Demonstrated success leading complex cross-functional initiatives involving engineering, security, compliance, legal, and GTM teams. - Strong written and verbal communication skills, with the ability to influence both technical and executive audiences. Requirements - Experience with US Government Security and Risk Frameworks (FEDRAMP, DOD IL, RMF, etc). - Experience with sovereign clouds, government cloud regions, and regulated industry offerings. - Background in databases, data platforms, analytics, or infrastructure software. - Experience commercializing open-source technologies for enterprise and government customers. - Familiarity with FIPS 140-2/140-3 validation requirements and government procurement processes. Benefits - Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in over 20 countries. - Healthcare - Employer contributions towards your healthcare. - Equity in the company - Every new team member who joins our company receives stock options. - Time off - Flexible time off in the US, generous entitlement in other countries. - A $500 Home office setup if you’re a remote employee. - Global Gatherings – We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites. - Culture - We All Shape It - As part of a rapidly scaling startup, you will be instrumental in shaping our culture.

Worldwide
$180K - $300K / year
Full TimeRemoteTeam 1-10H1B No Sponsor

• Assess IT security risks and coordinate appropriate countermeasures. • Develop and maintain network and security standards. • Support implementation of regulatory requirements such as ISO 27001, NIS2 and BSI IT-Grundschutz. • Manage and continuously optimize SIEM, EDR and XDR solutions. • Develop detection rules, use cases, alerts and automated response measures. • Conduct security reviews and support internal and external audits. • Monitor current threat landscapes and evaluate new security technologies and attack techniques.

Germany
€80K - €120K / year
PROSTAFF Schweiz GmbH logo

Full Stack Engineer – IAM Security

PROSTAFF Schweiz GmbH

PROSTAFF vermittelt und besetzt Informatik- und Data Science-Projekte in der Schweiz mit Freiberuflern, Freelancern, Contractors und temporären Mitarbeitern.

Full TimeRemoteTeam 201-500

Role Description Für ein langfristiges Entwicklungsprojekt im Bereich Identity & Access Management suchen wir einen erfahrenen Senior Software Engineer Full Stack. Der Schwerpunkt der Position liegt auf der Analyse und Behebung von Security Vulnerabilities innerhalb einer modernen IAM-Anwendung. - Analyse und Behebung von Vulnerabilities im IAM-Umfeld - Weiterentwicklung und Optimierung bestehender Full-Stack-Anwendungen - Umsetzung sicherheitsrelevanter Anpassungen im Backend und Frontend - Entwicklung mit Java, Spring Boot, React und TypeScript - Betrieb und Deployment von Anwendungen auf einer OpenShift-Plattform - Zusammenarbeit mit Security-, Architektur-, DevOps- und IAM-Spezialisten - Durchführung von Code Reviews sowie nachhaltige Dokumentation der Änderungen - Sicherstellung von Qualität, Stabilität und Wartbarkeit der Software Qualifications - Mehrjährige Erfahrung in der Full-Stack-Softwareentwicklung - Sehr gute Kenntnisse in Java und Spring Boot - Fundierte Erfahrung mit React, JavaScript und TypeScript - Erfahrung mit OpenShift, Kubernetes oder vergleichbaren Containerplattformen - Kenntnisse in der Analyse und Behebung von Software-Schwachstellen - Verständnis für Secure Coding, Dependency Management und Application Security - IAM-Erfahrung ist von Vorteil, jedoch keine zwingende Voraussetzung - Selbstständige, kommunikative und lösungsorientierte Arbeitsweise - Deutschkenntnisse sind bevorzugt; sehr gute Englischkenntnisse sind ebenfalls möglich Company Description PROSTAFF vermittelt und besetzt Informatik- und Data Science-Projekte in der Schweiz mit Freiberuflern, Freelancern, Contractors und temporären Mitarbeitern.

Switzerland