This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a hands-on Cloud Security Engineer II (AWS, SecOps) to be the first line of defense for the Tripadvisor Experiences platform. This is a critical mid-level role that blends proactive security engineering with reactive incident response. You will live and breathe in our product's cloud environment, monitoring for threats, responding to security incidents, automating defenses, and working closely with our engineering teams to build a more resilient platform.
Job Responsibility:
Monitor, analyze, and investigate security alerts originating from our AWS infrastructure, application logs, and security tooling (WAF, SIEM, Cloud-Native tools)
respond to security incidents that directly impact the Tripadvisor Experiences application
triage vulnerabilities reported through our bug bounty program and other external sources
build and maintain security monitoring and alerting capabilities within our production environment
automate security operations tasks using scripting languages like Python or Go
configure, tune, and help manage security tools like our Web Application Firewall (WAF), AWS GuardDuty, and Security Hub
operationalize findings from application security tools (SAST, DAST, SCA) by working with engineering teams
conduct threat modeling for new features
collaborate with engineering teams and provide guidance on secure coding practices and architecture
Requirements:
Hands-on experience securing a production environment in AWS
comfortable with its core security services (e.g., GuardDuty, Security Hub, WAF, CloudTrail)
good understanding of core AWS services beyond just security tools (e.g., VPC networking, EC2, RDS, S3, Lambda, EKS)
proficiency with Terraform for managing and securing cloud infrastructure
proven experience with the full lifecycle of security incidents
proficiency in at least one scripting language (e.g., Python, Go, Bash)
solid understanding of common web application vulnerabilities (OWASP Top 10)
demonstrated ability to use AI tools to improve efficiency, quality, and decision-making in day-to-day work
proven ability to operate effectively with a global-first mindset