Senior Security Engineer

WeTravel
Amsterdam
Workplace: HybridFull timeFunction: CybersecuritySkills: []

Own and automate infrastructure vulnerability management, detection, and incident response across cloud, identity, containers, and images. Prioritize remediation using risk signals (KEV, EPSS, exposure, asset criticality), build security logging coverage for detection, and manage infrastructure/cloud security posture. Coordinate incident response and provide technical evidence for SOC 2 and PCI DSS while partnering with Product, Platform, Engineering, and IT. Also help secure internal AI tooling and agent workflows.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
WeTravel
WeTravel
1 day ago

Senior Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Own and automate infrastructure vulnerability management, detection, and incident response across cloud, identity, containers, and images. Prioritize remediation using risk signals (KEV, EPSS, exposure, asset criticality), build security logging coverage for detection, and manage infrastructure/cloud security posture. Coordinate incident response and provide technical evidence for SOC 2 and PCI DSS while partnering with Product, Platform, Engineering, and IT. Also help secure internal AI tooling and agent workflows.
Location: Amsterdam
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own infrastructure vulnerability management with a centralized register, risk-based SLAs, tracking to closure, exception handling, and reporting within the Product Security risk framework.
  • •Prioritize infrastructure remediation using contextual risk signals (KEV, EPSS, exposure, asset criticality, compensating controls).
  • •Automate infrastructure-security workflows, including scanner integrations, finding pipelines, normalization, ticket routing, and reporting.
  • •Build detection foundations by improving security logging coverage and retention across production, cloud, and identity systems and managing the detection/response partner’s telemetry needs.
  • •Lead infrastructure and cloud security posture management and coordinate incident response, partnering with Product Security for product/customer-facing risk and corrective actions.

Pay and Benefits

Perks:Paid LeaveRemote WorkVolunteer Days

Key Requirements

  • •8+ years in security engineering with depth in security operations, including vulnerability management, cloud security posture, detection, and/or incident response.
  • •Experience with AWS and Kubernetes and reasoning about infrastructure as code.
  • •Expertise with security logging and SIEM-class tooling, including working with a managed detection provider.
  • •Hands-on infrastructure vulnerability management at scale: scanning fleets, images, containers, and dependencies; prioritizing by exploitability (KEV, EPSS, exposure, asset criticality) and driving remediation.
  • •Experience with SOC 2 and/or PCI DSS technical controls.
Experience:Security operationsCloud securityIncident responseSOC 2PCI DSS
Tech Stack:AWSKubernetesReactReactNativeTypeScriptRuby on RailsGoPythonMicroservicesContainersImagesMongoDBMySQLPostgresSnowflakeSIEMSOC 2PCI DSSLLM providers

Company Brief

WeTravel
WeTravel provides an online booking, payment, and management platform for tour operators, travel agencies, and group travel organizers, enabling itinerary management, secure payments, and customer invoicing to streamline group travel operations.
Industry: TravelTech
Company Size: Medium (51 to 250 employees)
Growth: Growth Stage Startup
Headquarters: San Francisco, United States
Founded: 2014
WebsiteLinkedIn