Senior Security Engineer
Job description
About the role
Agoda is hiring a hands-on Senior Security Engineer to protect cloud and platform infrastructure. You will partner directly with engineering teams to build, audit, and operate security controls through Infrastructure as Code, Kubernetes, and custom services developed in Go and TypeScript. The company is part of Booking Holdings and operates with a global team of over 7,000 people across 90 countries. In this position, you will serve as a critical link between security posture and delivery velocity, ensuring that security is embedded into the fabric of the platform rather than bolted on as an afterthought. You will own the design and implementation of security mechanisms that allow the business to move fast while maintaining a strong security posture across distributed environments. Your work will directly influence how security is perceived and practiced across engineering organizations by providing pragmatic, scalable, and maintainable solutions. You will be responsible for not only responding to threats but also proactively shaping the security roadmap through automation, tooling, and architectural guidance.
Key facts
What you'll do
- Architect and maintain secure cloud deployments on AWS and GCP using Terraform to enforce consistent and repeatable security baselines.
- Deploy and manage internal and third-party security tools within Kubernetes clusters to ensure continuous protection of containerized workloads.
- Operate GitOps workflows with Argo CD, Flux, and Helm charts to synchronize desired state and automate secure deployments.
- Develop security automation and tooling in Go and TypeScript to reduce manual effort and improve detection accuracy.
- Identify, investigate, and fix cloud misconfigurations before they become incidents through proactive scanning and assessment.
- Advise engineering teams on secure architecture patterns to help them build services that are secure by design.
- Create and tune cloud-native detection rules and alerting pipelines to catch suspicious activity across cloud and container workloads in real time.
- Integrate security controls into CI/CD pipelines to shift security left and provide fast feedback to developers.
- Collaborate with cross-functional teams to define security requirements and acceptance criteria for new features and services.
- Contribute to the improvement of security documentation, runbooks, and playbooks to support incident response and compliance efforts.
- Monitor security trends and emerging threats to ensure that the platform defenses evolve alongside the threat landscape.
- Participate in on-call rotations to respond to security incidents and provide technical leadership during critical events.
- Evaluate new security technologies and tools, conducting proof-of-concept assessments to determine their applicability and value.
- Partner with product and platform teams to embed security capabilities into customer-facing features without compromising usability.
Requirements
- 8+ years in security engineering, cloud security, or platform engineering with a proven track record of delivering security outcomes in complex environments.
- Practical experience protecting production workloads in AWS and GCP, including identity and access management, network security, and data protection.
- Solid background designing and securing Infrastructure as Code with Terraform, including modules, state management, and remote backends.
- Deep knowledge of Kubernetes security, including Helm troubleshooting and GitOps workflows, to ensure deployments are both secure and reliable.
- Strong coding ability in Go and TypeScript, with Python for automation tasks, enabling the development of custom security tools and integrations.
- Certified Kubernetes Administrator (CKA) certification to validate your ability to manage and troubleshoot Kubernetes clusters at scale.
- Certified Kubernetes Security Specialist (CKS) certification to demonstrate your expertise in securing Kubernetes clusters and applications.
- Experience implementing security controls in cloud environments using native services and APIs to enforce compliance and governance.
- Understanding of security principles such as zero trust, least privilege, and defense in depth as they apply to cloud and containerized systems.
- Familiarity with networking concepts, including VPCs, subnets, firewalls, and load balancers, to design secure network topologies.
- Ability to work effectively in a fast-paced, agile environment where priorities change frequently and adaptability is essential.
- Strong problem-solving skills and a methodical approach to diagnosing and resolving complex security issues under time constraints.
- Excellent communication skills, both written and verbal, to articulate technical risks and recommendations to both technical and non-technical stakeholders.
- Willingness to follow established security processes and contribute to the continuous improvement of security practices and standards.
- Commitment to staying current with industry best practices, certifications, and emerging threats through ongoing learning and professional development.
Nice to have
- AWS Certified Security Specialty
- Google Professional Cloud Security Engineer
- HashiCorp Certified: Terraform Associate
- Familiarity with Policy-as-Code tools such as Open Policy Agent (OPA)
- Experience securing service mesh environments like Istio
- Prior background in software engineering or platform engineering before transitioning to security
Practical notes
- Review the company Hiring Process Guidelines before interviewing at careersatagoda.com/interview
- Agoda is an equal opportunity employer and considers candidates regardless of background
- Your application may be kept on file for future roles; you can request removal at any time