Cloud Security Engineer II
New
T
TripadvisorTravel Technology
Remote - United StatesFull-TimeMiddle
Salary$135,000 -$155,000
Apply NowOpens the employer's application page
Job Details
- Experience
- 3–5 years of dedicated hands-on experience
- Required Skills
- AWSDockerPythonBashKubernetesGoCI/CDTerraform
Requirements
- 3–5 years of dedicated hands-on experience in cloud security, DevSecOps, or infrastructure security engineering.
- Deep working knowledge of core AWS security services including IAM, GuardDuty, Security Hub, KMS, CloudTrail, and Organizations.
- Strong proficiency in Infrastructure as Code, with Terraform preferred.
- At least one scripting language proficiency in Python, Go, or Bash.
- Practical experience securing Kubernetes/EKS and configuring CI/CD security scanners such as GitHub Actions or GitLab CI.
- Solid understanding of cloud networking including VPCs, Transit Gateways, WAF, and DNS.
- Understanding of identity management including OAuth2, OIDC, and SAML.
- Familiarity with mapping cloud controls to industry frameworks such as CIS Benchmarks, NIST CSF, and SOC 2.
- Preferred certifications: AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), or CCSP.
- Prior experience in travel, experiences, or marketplace businesses is a plus.
Responsibilities
- Design, deploy, and enforce scalable cloud security controls, IAM least-privilege policies, and encryption standards across multi-account AWS environments.
- Embed automated security tools like IaC scanning, SAST, and secret detection into CI/CD pipelines to catch vulnerabilities pre-deployment.
- Develop automated detection and remediation workflows using Python, Bash, or Go alongside IaC tools like Terraform and CloudFormation.
- Implement and maintain security practices for containerized workloads using Docker and Kubernetes/EKS, as well as serverless architectures.
- Manage CSPM/CNAPP platforms, investigate high-priority alerts, and reduce noise through automated risk scoring and alert tuning.
- Conduct architectural security reviews and threat modeling for new cloud features, infrastructure changes, and third-party integrations.
- Act as a secondary point of contact for cloud security incidents, assisting with forensic collection, root-cause analysis, and post-mortem actions.
View Full Description & ApplyYou'll be redirected to the employer's site