Senior Security Engineer

WeTravel

3h ago β€’ 0 views β€’ 0 applications
Full-time Remote
Bulgaria
Competitive
Full-time
Security Engineer

Job Description

πŸ‘‹ Hey there! I'm George, Head of Platform & Infrastructure here at WeTravel. I joined WeTravel to architect and fortify a secure, reliable, and scalable IT environment as we embark on an ambitious growth journey. Our team's mission is clear: empower every WeTravel employee with the seamless, secure, and efficient tools they need to thrive, no matter their location across the globe.

About WeTravel: Powering the World's Most Amazing Adventures
Imagine the most breathtaking adventures: summiting Machu Picchu, cycling through Tuscany's rolling hills, or embarking on a thrilling Kenyan safari. For too long, the brilliant small businesses and local experts who craft these unforgettable experiences have been bogged down by antiquated tools – messy spreadsheets, endless emails, and convoluted payment systems.
WeTravel is revolutionizing this. We build the cutting-edge platform that empowers entrepreneurs to launch, manage, and scale their travel businesses with ease. Our intuitive tools enable organizers to create stunning trip proposals, securely process payments, and efficiently manage their customers, freeing them to do what they do best: create extraordinary memories.
This is one of the final frontiers of travel to truly come online, and as the undisputed category leader, we are at the vanguard of this transformation. Last year alone, our platform was trusted by 8,000 organizers to guide over a million travelers on adventures spanning 150+ countries. Now, we're on an exhilarating trajectory to grow from powering $1B to an astounding $10B in travel experiences per year.
We firmly believe that every trip, when executed thoughtfully, can be a profound force for good – and we are building the engine to make exponentially more of that possible.

Your Mission: Forge the Future of Infrastructure Security
As our Infrastructure Security Engineer, you'll be instrumental in securing the foundation of our rapidly expanding global platform. This isn't just about maintaining; it's about building, automating, and owning critical security functions that enable our growth and protect our mission.

Own Infrastructure Vulnerability Management: Architect and manage a centralized, risk-based vulnerability management program across all infrastructure dependencies, containers, images, and cloud infrastructure. Establish clear, trackable SLAs for remediation, handle exceptions, and deliver actionable reporting for engineering leadership and enterprise security teams, all within our Product Security severity and risk framework. One register, one unified scoring model.
Strategic Remediation Prioritization: Drive infrastructure remediation efforts by leveraging contextual risk signals such as KEV (Known Exploited Vulnerabilities), EPSS (Exploit Prediction Scoring System), exposure analysis, asset criticality, and relevant compensating controls, aligning with our common severity model.
Automate Security Workflows: Design and implement automated infrastructure-security workflows, including scanner integrations, finding pipelines, normalization, intelligent ticket routing, and comprehensive reporting. If a metric requires manual assembly, it's not done. Contribute to shared security finding workflows to enhance overall efficiency.
Build Our Detection Foundation: Establish robust security logging coverage and retention across production, cloud, and identity systems. Select and manage our detection and response (MDR) partner, ensuring they have the essential telemetry to detect and respond effectively. You cannot detect what you do not record – closing this gap is your critical responsibility.
Lead Cloud Security Posture Management (CSPM): Partner closely with our platform team to implement and enforce cloud account guardrails, define hardening baselines, triage CSPM findings, maintain an accurate internet-facing surface inventory, and secure our image and container ecosystem.
Coordinate Security Incident Response: Develop and refine incident classification runbooks, lead tabletop exercises, and ensure effective post-incident corrective actions. Collaborate with Product Security on incidents involving product-security vulnerabilities or customer-facing product risks.
Drive Effective Remediation Partnerships: Work hand-in-hand with product, platform engineering, and IT teams to ensure findings are triaged, deduplicated, and clearly explained, fostering trust and efficient resolution within engineering queues.
Technical Compliance Evidence: Supply the necessary technical evidence for our SOC 2, PCI DSS, and customer due diligence obligations, including access reviews, scan results, and patch compliance. You will focus on the technical execution, not the audit relationship or questionnaires.
Strategic Collaboration: Partner with Product & Platform teams, providing accurate technical evidence and context to support critical customer-facing security discussions.

Securing the AI Frontier:

AI Policy Operationalization: Actively participate in maintaining and operationalizing our Internal AI Use Policy and its application across the organization.
Secure AI Tooling: Implement robust security measures for internal AI tooling and agentic workflows, meticulously scoping data access for agents, defining identity, credential, and tool permissions, ensuring comprehensive logging, and establishing detection mechanisms for inappropriate agent behavior.
Auditable Agentic Workflows: Engineer agentic workflows to be fully auditable, tracking who or what acted, what data and tools were accessed, and under which identity.

How We Work: Impact-Driven & Future-Focused
Our focus is on tangible impact. We don’t adhere to rigid frameworks or ideologies; instead, we adapt based on what drives the most meaningful outcomes. We're committed to leveraging the latest hardware and are always on the lookout for superior tools and innovative ways to work.
Our Stack: We build with React/ReactNative/TypeScript and Ruby on Rails, Go, and Python Microservices on Kubernetes. We harness the power of MongoDB, MySQL, Postgres, Snowflake, and are actively integrating with major LLM providers.

Who You Are: Your Expertise & Impact
You're a seasoned security professional ready to make a significant impact on a growing, category-leading platform.

You bring 8+ years of dedicated experience in security engineering, with profound depth in security operations across vulnerability management, cloud security posture, detection, or incident response.
You possess hands-on expertise with AWS and Kubernetes, and a strong ability to reason about infrastructure as code.
You're an expert in security logging and SIEM-class tooling, with proven experience collaborating effectively with managed detection providers.
You have practical, at-scale experience running infrastructure vulnerability management: managing scanning fleets, securing images, containers, and dependencies, prioritizing by exploitability (KEV, EPSS, exposure, asset criticality), and successfully driving remediation through system-owning teams.
You have direct experience with SOC 2 and/or PCI DSS technical controls.

Bonus Points If You Have:

Experience securing payments or regulated fintech systems.
Detection engineering, threat modeling, or DFIR (Digital Forensics and Incident Response) experience.
Exposure to EU regulatory obligations (GDPR Art. 33/34, the Cyber Resilience Act) and ISO27001.
Experience in a product company scaling from mid-market to enterprise customers.

Perks & Benefits: Thrive With Us

Competitive Salary: Your expertise is valued and rewarded.
Generous "Time to Recharge" Policy: Enjoy unlimited paid time off to rest, recharge, and bring your best self to work.
Work From Anywhere Perk: Eligible employees can work temporarily from another approved location for up to four weeks per calendar year.
Comprehensive Onboarding: A 2-week cross-functional program to set you up for success.
Annual Team Off-site: Join us for an unforgettable team off-site (often somewhere sunny 🌊!).
Commuting Support: Cycle-to-work scheme (Swapfiets subscription) or commuting reimbursement.
Extensive Paid Family Leave: Supporting you through life's most important moments.
Volunteer Days: Three paid volunteer days per year to give back to causes you care about.
Cutting-Edge Equipment: We provide the best tools to ensure your success.
International, Adventure-Loving Team: Join a passionate team united by a love for travel and innovation.

Equal Opportunities: We Celebrate Diversity
WeTravel is a proud equal opportunity employer. We celebrate diversity in all its forms and are deeply committed to fostering an inclusive environment for every employee. We enthusiastically welcome applicants from all backgrounds, experiences, and perspectives. If you're excited by this opportunity and believe you're a great fit, we encourage you to apply and join us in transforming the travel industry!

CyberJob.app

Your trusted source for cybersecurity job opportunities worldwide.


© 2026 CyberJob.app. All rights reserved.