Senior Security Engineer @WeTravel
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2wks ago

[Hiring] Senior Security Engineer @WeTravel

2wks ago - WeTravel is hiring a remote Senior Security Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Europe

Role Description

Own infrastructure vulnerability management. One central register across infrastructure dependencies, containers, images, and cloud infrastructure. Risk-based SLAs, tracking to closure, exception handling, and reporting we can put in front of engineering leadership and an enterprise customer's security team β€” operating within the Product Security severity and risk framework. One register, one scoring model.

  • Prioritize infrastructure remediation using contextual risk signals such as KEV, EPSS, exposure, asset criticality, and relevant compensating controls, within the common severity model.
  • Automate infrastructure-security workflows: scanner integrations, finding pipelines, normalization, ticket routing, and reporting.
  • Build our detection foundation: Security logging coverage and retention across production, cloud, and identity systems; select and run the managed detection and response partner; ensure necessary telemetry exists and survives.
  • Lead infrastructure and cloud security posture management with our platform team: cloud account guardrails, hardening baselines, CSPM findings triage, internet-facing surface inventory, image and container security.
  • Coordinate security incident response: incident classification runbooks, tabletop exercises, and post-incident corrective actions.
  • Partner with Product Security on incidents involving product-security vulnerabilities or customer-facing product risk.
  • Partner with product, platform engineering, and IT on remediation. Findings arrive triaged, deduplicated, and explained.
  • Supply the technical evidence behind our SOC 2, PCI DSS, and customer due diligence obligations β€” access reviews, scan results, patch compliance.
  • Collaborate with Product & Platform teams, and support customer-facing security discussions with accurate technical evidence and context.

AI Related

  • Participate in maintaining and operationalizing the Internal AI Use Policy and application.
  • Secure internal AI tooling and agentic workflows: what data agents can reach, how identities, credentials and tool permissions are scoped, what gets logged, and how inappropriate agent behavior is detected.
  • Make agentic workflows auditable: who or what acted, what data and tools were accessed, and under which identity.

Qualifications

  • 8+ years in security engineering, with real depth in security operations: vulnerability management, cloud security posture, detection, or incident response.
  • Experience with AWS and Kubernetes, and the ability to reason about infrastructure as code.
  • Expertise with security logging and SIEM-class tooling, and with working through a managed detection provider.
  • Hands-on experience running infrastructure vulnerability management at scale: scanning fleets, images, containers and dependencies, prioritizing by exploitability (KEV, EPSS, exposure, asset criticality), and driving remediation through the teams that own the systems.
  • Experience with SOC 2 and/or PCI DSS technical controls.

Nice to have

  • Experience securing payments or regulated fintech systems.
  • Detection engineering, threat modeling, or DFIR experience.
  • Exposure to EU regulatory obligations (GDPR Art. 33/34, the Cyber Resilience Act), and ISO27001.
  • Experience in a product company scaling from mid-market to enterprise customers.

Benefits

  • Competitive salary.
  • Generous "Time to Recharge" policy - enjoy unlimited paid time off to rest, recharge, and show up as your best self.
  • Our Work From Anywhere perk provides eligible employees with up to four weeks per calendar year to work temporarily from another approved location.
  • 2-week cross-functional onboarding program.
  • Annual team off-site (often somewhere sunny 🌊).
  • Cycle-to-work scheme (Swapfiets subscription) or commuting reimbursement.
  • Extensive paid family leave.
  • Three paid volunteer days per year - take time to give back to causes you care about, on us.
  • Cutting-edge equipment and tools to set you up for success.
  • Join an international, travel-loving team with a passion for adventure and innovation.

Equal Opportunities

WeTravel is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We welcome applicants from all backgrounds, experiences, and perspectives. If you're excited about this opportunity and believe you're a good fit, we encourage you to apply and join us in transforming the travel industry!

Before You Apply
️
remote Be aware of the location restriction for this remote position: Europe
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Engineer @WeTravel
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Europe
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,070+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later