Cloud Security Engineer II
Job description
About the role
Tripadvisor is actively seeking a Cloud Security Engineer II to safeguard the integrity and availability of the Tripadvisor Experiences platform. This role represents a critical position responsible for designing and implementing security measures directly within the cloud environment. The successful candidate will blend proactive engineering with rapid incident response to ensure the platform remains resilient against evolving threats. You will serve as a key defender, monitoring cloud infrastructure, automating security workflows, and collaborating closely with development teams. This position requires a balance of technical depth and communication skills to translate security findings into tangible improvements. Ultimately, you will own the security posture of critical services, ensuring customer trust is maintained through robust technical controls.
Key facts
What you'll do
- Continuously monitor AWS infrastructure, application logs, WAF rules, SIEM data, and cloud-native services to identify anomalous behavior and potential security threats.
- Lead the investigation of security incidents impacting the Experiences application, including data breaches, application-layer attacks, and infrastructure compromises, from initial alert to resolution.
- Perform detailed analysis and triage of vulnerabilities reported through the bug bounty program and other external disclosure channels, determining scope and impact.
- Design, implement, and maintain monitoring, alerting, and observability systems within production environments to improve detection accuracy and reduce noise.
- Author automation scripts using Python, Go, or Bash to streamline repetitive security tasks, accelerate response times, and minimize manual errors.
- Manage the configuration, tuning, and optimization of security tools such as Web Application Firewalls, AWS GuardDuty, and AWS Security Hub to maximize effectiveness.
- Translate findings from Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools into clear remediation tasks for engineering teams.
- Conduct threat modeling exercises for new features and architectural changes to identify risks early in the development lifecycle.
- Provide actionable security guidance to engineering teams regarding secure coding practices, deployment configurations, and architectural decisions.
- Collaborate with cross-functional partners to ensure security controls are integrated seamlessly into development pipelines and operational workflows.
- Evaluate emerging security tools and techniques to recommend improvements to the overall security strategy.
- Maintain up-to-date knowledge of cloud security best practices, compliance frameworks, and industry standards relevant to the role.
Requirements
- Possess hands-on experience with AWS security operations in a live production environment, including practical use of GuardDuty, Security Hub, WAF, and CloudTrail for monitoring and response.
- Demonstrate a solid understanding of core AWS services beyond security-specific tools, including VPC networking, EC2 instances, RDS databases, S3 storage, Lambda functions, and EKS orchestration.
- Show the ability to rapidly spin up and comprehend a complete infrastructure stack, including networking, compute, storage, and identity components.
- Exhibit proficiency with Terraform for defining, managing, and reviewing infrastructure as code with a strong focus on security controls and compliance.
- Have proven experience managing the full incident response lifecycle, encompassing detection, analysis, containment, remediation, and thorough post-mortem analysis.
- Display scripting competence in at least one high-level programming or shell scripting language such as Python, Go, or Bash to automate security investigations and tasks.
- Maintain a strong grasp of the OWASP Top Ten web application vulnerabilities and common defensive strategies to mitigate risks effectively.
- Demonstrate the use of AI-powered tools to enhance efficiency, improve code quality, and support better decision-making in day-to-day security operations.
- Thrive in a global-first environment, communicating effectively across distributed teams and time zones with clarity and professionalism.
- Commit to adhering to company policies, security standards, and ethical guidelines in all aspects of the work.
Practical notes
- Compensation packages are benchmarked against current industry data and include base salary plus annual bonus.
- Flexible schedule with a remote-friendly approach; join on-site as often as you prefer or as your team requires.
- Annual donation matching for qualifying charitable contributions.
- Tuition assistance for approved programs.
- Annual lifestyle benefit for travel, wellness, or personal use.
- Travel discounts and perks.
- Employee assistance program and health benefits with competitive premiums.
- Accommodation requests can be sent to AccessibleRecruiting@tripadvisor.com.
- General career questions can be directed to recruitment@tripadvisor.com