DevSecOps Engineer (Cloud Security, AWS)

1 month ago
Full-time
Mid Level
DevOps and Infrastructure
Tripadvisor

Tripadvisor

Tripadvisor is the world's largest travel guidance platform, offering over a billion reviews and recommendations for hotels, attractions, restaurants, and more. Travelers rely on Tripadvisor to plan their trips, find savings on accommodations, book exp...

Consumer Services
1K-5K
Founded 2000

Description

  • Monitor, analyze, and investigate security alerts from AWS infrastructure, application logs, and security tooling.
  • Respond to security incidents affecting the Tripadvisor Experiences application, including breaches, application-layer attacks, and infrastructure compromises.
  • Triage vulnerabilities reported through the bug bounty program and other external sources.
  • Build and maintain security monitoring and alerting capabilities in the production environment.
  • Automate security operations tasks using scripting to improve detection and response times.
  • Configure, tune, and help manage security tools including WAF, AWS GuardDuty, and Security Hub.
  • Operationalize findings from SAST, DAST, and SCA tools by prioritizing and remediating vulnerabilities with engineering teams.
  • Conduct threat modeling for new features to identify and mitigate risk before production.
  • Collaborate with engineering teams on secure coding practices and secure architecture.

Requirements

  • Hands-on experience securing a production AWS environment.
  • Comfort with AWS security services such as GuardDuty, Security Hub, WAF, and CloudTrail.
  • Good understanding of core AWS services including VPC networking, EC2, RDS, S3, Lambda, and EKS.
  • Proficiency with Terraform for reading, writing, and reviewing infrastructure as code.
  • Proven experience across the full incident response lifecycle, from detection to post-mortem.
  • Proficiency in at least one scripting language such as Python, Go, or Bash.
  • Solid understanding of common web application vulnerabilities and OWASP Top 10 defenses.
  • Demonstrated ability to use AI tools to improve efficiency, quality, and decision-making.
  • Ability to operate effectively with a global-first mindset.
  • Experience with cloud-native security tools or SecOps tools is preferred.

Benefits

  • Competitive compensation with base salary and annual bonuses.
  • Remote-friendly work with flexible options to work on-site when desired or required.
  • Flexible schedule supporting work-life balance.
  • Annual donation matching.
  • Annual tuition assistance for qualified programs.
  • Annual lifestyle benefit for travel, wellness, or personal use.
  • Travel discounts and other travel perks.
  • Employee assistance program and support resources.
  • Health benefits with competitive coverage and premiums.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Detection Engineer

DoorDash 10K-50K Air Freight & Logistics

DoorDash is hiring a Senior Detection Engineer to help build and operate detection engineering for its global cyber defense function across DoorDash, Deliveroo, and Wolt.

Go Python SIEM Snowflake SQL
1 day, 8 hours ago

Senior Golang + .Net Engineer (with AWS)

Coforge 10K-50K IT Services

Coforge is seeking a Senior Golang + .NET Engineer to develop and support cloud-based software solutions on AWS for a remote, distributed team operating on Central Time.

Agile AWS Go .NET
1 day, 8 hours ago

Senior Technical Consultant | Cloud & Platform Engineering

AHEAD 1K-5K IT Services

AHEAD is hiring a Rapid Solutions Pod Lead within its AI & Cloud Practice to lead client engagements, manage a small engineering pod, and evolve repeatable delivery offerings for multi-cloud and AI-driven modernization work.

AWS Azure GCP Git
1 day, 9 hours ago

Staff Security Engineer

Redox 51-250 Internet Software & Services

Redox is hiring a Staff Security Engineer to own cloud-native and application security for its remote healthcare data exchange platform, with a focus on hardening systems and driving secure-by-default engineering practices.

Argo CD AWS CI/CD CrowdStrike Docker GitHub Actions Go HashiCorp Vault Helm Kafka Kubernetes LLM Node.js PostgreSQL Python Redis Terraform TypeScript
1 day, 9 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers