WeTravel

Senior Security Engineer

WeTravel
Apply
4 hours ago
Amsterdam, NetherlandsSenior

Responsibilities

  • Own infrastructure vulnerability management across dependencies, containers, images, and cloud infrastructure, including risk-based SLAs, exception handling, reporting, and tracking remediation to closure.
  • Prioritize infrastructure remediation using KEV, EPSS, exposure, asset criticality, and compensating controls.
  • Automate security workflows such as scanner integrations, finding pipelines, normalization, ticket routing, and reporting.
  • Build security logging and retention coverage across production, cloud, and identity systems, and manage the managed detection and response partner.
  • Lead cloud and infrastructure security posture management, including cloud guardrails, hardening baselines, CSPM triage, internet-facing asset inventory, and image and container security.
  • Coordinate incident response through classification runbooks, tabletop exercises, and post-incident corrective actions.
  • Partner with product, platform engineering, and IT teams to explain findings and drive remediation.
  • Provide technical evidence for SOC 2, PCI DSS, and customer due diligence requirements.
  • Support customer-facing security discussions with accurate technical evidence and context.
  • Help maintain the Internal AI Use Policy and secure internal AI tooling and agentic workflows through scoped access, logging, detection, and auditability.

Requirements

  • 8+ years of experience in security engineering, with depth in vulnerability management, cloud security posture, detection, or incident response.
  • Experience with AWS and Kubernetes, plus the ability to reason about infrastructure as code.
  • Expertise with security logging, SIEM-class tooling, and managed detection providers.
  • Hands-on experience operating infrastructure vulnerability management at scale across fleets, images, containers, and dependencies.
  • Ability to prioritize vulnerabilities using exploitability, KEV, EPSS, exposure, asset criticality, and related risk signals.
  • Experience with SOC 2 and/or PCI DSS technical controls.
  • Experience securing payments or regulated fintech systems is preferred.
  • Detection engineering, threat modeling, or DFIR experience is preferred.
  • Exposure to GDPR Articles 33/34, the Cyber Resilience Act, and ISO27001 is preferred.
  • Experience in a product company scaling from mid-market to enterprise customers is preferred.

Benefits

  • Competitive salary.
  • Unlimited paid time off through the Time to Recharge policy.
  • Eligible employees can work temporarily from another approved location for up to four weeks per calendar year through the Work From Anywhere perk.
  • Two-week cross-functional onboarding program.
  • Annual team off-site.
  • Cycle-to-work scheme through a Swapfiets subscription or commuting reimbursement.
  • Monday and Thursday team lunches and after-work social events.
  • Extensive paid family leave.
  • Three paid volunteer days per year.
  • Cutting-edge equipment and tools.
  • International, travel-loving team environment.

Tech Stack

AWSGoKubernetesMongoDBMySQLPostgreSQLPythonReactReact NativeRuby on RailsSnowflakeTypeScript

Categories

WeTravel

About WeTravel

201-500 employees

WeTravel builds a payment and booking platform for multi-day and group travel businesses, with tools for custom itineraries, deposits, installment plans, and supplier payouts. It monetizes through software subscriptions and payment processing fees. Founded in 2016 and headquartered in San Francisco, it serves tour operators, retreat organizers, and student-trip providers worldwide, with growing adoption across Europe, including the UK, Ireland, and Italy.

Contact me