Senior Cloud Security Engineer (Viator)
Viator, a Tripadvisor company, is the leading marketplace for travel experiences. We believe that making memories is what travel is all about. And with 300,000+ travel experiences to explore—everything from simple tours to extreme adventures (and all the niche, interesting stuff in between)—making memories that will last a lifetime has never been easier. With industry-leading flexibility and last-minute availability, it's never too late to make any day extraordinary. Viator. One app, 300,000+ travel experiences you’ll remember.As part of Viator, you'll be joining a dedicated team focused on building and securing our unique platform. While our parent company, Tripadvisor, manages group-level enterprise security, our team has a laser focus on one thing: protecting the Viator product, its infrastructure, and our customers' data.
We are looking for a hands-on Senior Cloud Security Engineer to be the first line of defense for the Viator platform. This is a critical role that blends proactive security engineering with reactive incident response. You will live and breathe in our product's cloud environment, monitoring for threats, responding to security incidents, automating defenses, and working closely with our engineering teams to build a more resilient platform.
Viator is a remote-first company. This role is based remotely in Portugal / Poland.
What You'll DoProduct-Focused Incident Response:
- Monitor, analyze, and investigate security alerts originating from our AWS infrastructure, application logs, and security tooling (WAF, SIEM, Cloud-Native tools).
- Lead the response to security incidents that directly impact the Viator application, such as potential data breaches, application-layer attacks, or infrastructure compromises.
- Manage and triage vulnerabilities reported through our bug bounty program and other external sources.
Security Engineering & Automation:
- Build and maintain security monitoring and alerting capabilities within our production environment.
- Automate security operations tasks using scripting languages like Python or Go to improve our detection and response times.
- Configure, tune, and manage security tools like our Web Application Firewall (WAF), AWS GuardDuty, and Security Hub.
Vulnerability Management & Collaboration:
- Operationalize findings from application security tools (SAST, DAST, SCA) by working with engineering teams to prioritize and remediate vulnerabilities in our codebase and dependencies.
- Conduct threat modeling for new features to identify and mitigate risks before they reach production.
- Act as a security subject matter expert for our product and engineering teams, providing guidance on secure coding practices and architecture.
Required Experience (Must-Haves):
- AWS Security Operations: Deep, hands-on experience securing a production environment in AWS. You must be comfortable with its core security services (e.g., GuardDuty, Security Hub, WAF, CloudTrail).
- AWS Cloud Infrastructure: Comprehensive understanding of core AWS services beyond just security tools (e.g., VPC networking, EC2, RDS, S3, Lambda, EKS). You must be capable of understanding and spinning up a full infrastructure stack to effectively secure it.
- Infrastructure as Code: Strong proficiency with Terraform for managing and securing cloud infrastructure. You should be able to read, write, and review Terraform code, ensuring that the infrastructure you define is secure by design.
- Incident Response: Proven experience managing the full lifecycle of security incidents, from initial detection and analysis to containment, remediation, and post-mortem.
- Scripting for Automation: Proficiency in at least one scripting language (e.g., Python, Go, Bash) to automate security operations and analysis tasks.
- Application Security Fundamentals: A solid understanding of common web application vulnerabilities (OWASP Top 10) and how to defend against them.