SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tripadvisor is seeking a Cloud Security Engineer II to design, build, and automate security controls across a multi-cloud environment with primary focus on AWS, secondary exposure to Azure and GCP. This mid-level role moves beyond alert monitoring to actively embed security into infrastructure and CI/CD pipelines.
Key responsibilities include:
- Design and deploy scalable cloud security controls, IAM least-privilege policies, and encryption standards across multi-account AWS environments
- Embed automated security tools (IaC scanning, SAST, secret detection) into CI/CD pipelines to catch vulnerabilities before deployment
- Develop automated detection and remediation workflows using Python, Bash, or Go alongside Infrastructure as Code tools (Terraform, CloudFormation)
- Implement and maintain security practices for containerized workloads (Docker, Kubernetes/EKS) and serverless architectures
- Manage CSPM/CNAPP platforms, investigate high-priority security alerts, and reduce noise through automated risk scoring
- Conduct architectural security reviews and threat modeling for new cloud features and infrastructure changes
- Act as secondary point of contact for cloud security incidents, assisting with forensic collection and root-cause analysis
Required experience includes 3–5 years in cloud security, DevSecOps, or infrastructure security engineering. Deep working knowledge of AWS security services (IAM, GuardDuty, Security Hub, KMS, CloudTrail, Organizations) is essential. Strong proficiency in Infrastructure as Code (Terraform preferred) and at least one scripting language (Python, Go, Bash) required. Practical experience securing Kubernetes/EKS and configuring CI/CD security scanners is expected. Solid understanding of cloud networking (VPCs, Transit Gateways, WAF, DNS) and identity management (OAuth2, OIDC, SAML) needed. Familiarity with mapping cloud controls to industry frameworks (CIS Benchmarks, NIST CSF, SOC 2) is important. Preferred certifications include AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), or CCSP.