Senior Security Engineer

🔥 0 minutes ago

🌐 Bulgaria, Portugal, +5 more countries – Remote

infoinfo

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 17%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of WeTravel

WeTravel

51 - 200 employees

Founded 2016

💼 Consulting

📦 Logistics

✈️ Travel

💰 $27M Series B on 2022-10

Consulting • Logistics • Travel

WeTravel is a comprehensive booking and payments platform designed specifically for multi-day and group travel businesses. It enables over 5,000 travel companies to accept payments instantly, manage bookings efficiently, and facilitate global supplier transfers. The platform offers tools for creating stunning trip pages, payment processing with low fees, and easy booking management to enhance the customer journey and streamline operations for travel advisors and agencies.

📋 Description

• Own infrastructure vulnerability management, including a central register, risk-based SLAs, exception handling, closure tracking, and reporting • Prioritize infrastructure remediation using contextual risk signals such as KEV, EPSS, exposure, asset criticality, and compensating controls • Automate scanner integrations, finding pipelines, normalization, ticket routing, and reporting • Contribute to shared security finding workflows • Build security logging coverage and retention across production, cloud, and identity systems • Select and operate a managed detection and response partner • Lead cloud security posture management with the platform team, including account guardrails, hardening baselines, CSPM triage, internet-facing surface inventory, and image/container security • Coordinate security incident response, runbooks, tabletop exercises, and post-incident corrective actions • Partner with Product Security on product-security vulnerabilities and customer-facing product risk • Partner with product, platform engineering, and IT on remediation • Provide technical evidence for SOC 2, PCI DSS, and customer due diligence obligations • Collaborate with Product & Platform teams and support customer-facing security discussions • Help maintain and operationalize the Internal AI Use Policy and application • Secure internal AI tooling and agentic workflows, including data access, identity, credentials, tool permissions, logging, and detection of inappropriate behavior • Make agentic workflows auditable

🎯 Requirements

• 8+ years in security engineering, with depth in vulnerability management, cloud security posture, detection, or incident response • Experience with AWS and Kubernetes • Ability to reason about infrastructure as code • Expertise with security logging and SIEM-class tooling • Experience working through a managed detection provider • Hands-on experience running infrastructure vulnerability management at scale across fleets, images, containers, and dependencies • Experience prioritizing remediation using KEV, EPSS, exposure, asset criticality, and compensating controls • Experience driving remediation through system-owning teams • Experience with SOC 2 and/or PCI DSS technical controls • Experience securing payments or regulated fintech systems • Detection engineering, threat modeling, or DFIR experience • Exposure to EU regulatory obligations including GDPR Art. 33/34 and the Cyber Resilience Act, and ISO27001 • Experience in a product company scaling from mid-market to enterprise customers

🏖️ Benefits

• Competitive salary • Generous "Time to Recharge" policy with unlimited paid time off • Work From Anywhere perk: up to four weeks per calendar year to work temporarily from another approved location • 2-week cross-functional onboarding program • Annual team off-site • Cycle-to-work scheme (Swapfiets subscription) or commuting reimbursement • Extensive paid family leave • Three paid volunteer days per year • Cutting-edge equipment and tools • International, travel-loving team

Apply Now

Similar Jobs

🕒 September 4

Netrix Global

501 - 1000

💼 Consulting

📣 Marketing

Information Security Engineer securing Netrix Global’s managed customer environments. Handling SOC incidents, SIEM analysis, penetration testing, and vulnerability remediation.

Azure

Linux

Python

Shell Scripting

Splunk

SQL

🕒 August 21

MWDN

51 - 200

💼 Consulting

📦 Logistics

🏥 Healthcare

Security Researcher researching browser and mobile attack surfaces for a passwordless IAM company. Developing security signals and SDK requirements to detect fraud, automation, and AI agents.

Android

Cyber Security

iOS

Java

JavaScript

Kotlin

Objective-C

Python

Swift

TypeScript

🕒 July 29

Cision France

1001 - 5000

🤝 B2B

📱 Media

📣 Marketing

Senior Security Engineer responsible for monitoring and investigating security events across various platforms. Cision seeks expertise in cloud security and incident response.

AWS

Cloud

Google Cloud Platform

Linux

Python

Splunk

🕒 June 29

emerchantpay

201 - 500

💼 Consulting

📦 Logistics

✈️ Travel

Information Security Lead at emerchantpay focusing on cloud-native security and incident response. Overseeing security strategy and mentoring a security team in a fast-growing payment company.

AWS

Cloud

Cyber Security

Microservices

SDLC