SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tripadvisor is seeking a Cloud Security Engineer II to serve as the first line of defense for the Tripadvisor Experiences platform. This is a hands-on, mid-level role combining proactive security engineering with reactive incident response in a production AWS environment.
You will monitor and investigate security alerts from AWS infrastructure, application logs, and security tooling (WAF, SIEM, cloud-native tools). Responsibilities include responding to security incidents affecting the Experiences application—such as potential data breaches, application-layer attacks, or infrastructure compromises—and triaging vulnerabilities from bug bounty programs and external sources.
On the engineering side, you will build and maintain security monitoring and alerting capabilities, automate security operations tasks using Python or Go, and configure security tools like WAF, AWS GuardDuty, and Security Hub. You'll operationalize findings from application security tools (SAST, DAST, SCA) by collaborating with engineering teams to prioritize and remediate vulnerabilities. Threat modeling for new features and guidance on secure coding practices are also core responsibilities.
Required skills include hands-on AWS security operations experience in production environments, deep understanding of core AWS services (VPC, EC2, RDS, S3, Lambda, EKS), proficiency with Terraform for infrastructure-as-code, proven incident response lifecycle experience, scripting proficiency (Python, Go, Bash), and solid application security fundamentals (OWASP Top 10). You should demonstrate ability to use AI tools for efficiency and operate with a global-first mindset.
Tripadvisor offers competitive compensation with base salary and annual bonuses, remote-friendly work arrangements with optional on-site flexibility, flexible scheduling, charitable donation matching, tuition assistance, and annual lifestyle benefits.