SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
WeTravel is a travel-tech platform empowering entrepreneurs to launch and grow travel businesses. The platform processes payments and manages operations for trip organizers globally, with 8,000+ organizers leading over a million travelers annually across 150+ countries. The company is scaling from $1B to $10B in annual travel experiences.
As Senior Security Engineer, you will own infrastructure security and detection across WeTravel's platform. Your responsibilities include:
**Core Responsibilities:**
- Own infrastructure vulnerability management: build and maintain a centralized register of infrastructure dependencies, containers, images, and cloud infrastructure with risk-based SLAs, tracking, exception handling, and reporting for engineering leadership and enterprise customers.
- Prioritize infrastructure remediation using contextual risk signals (KEV, EPSS, exposure, asset criticality, compensating controls) within a common severity model.
- Automate infrastructure-security workflows: scanner integrations, finding pipelines, normalization, ticket routing, and reporting. Eliminate manual quarterly reporting.
- Build the detection foundation: establish security logging coverage and retention across production, cloud, and identity systems; select and operate the managed detection and response partner; ensure required telemetry exists and is retained.
- Lead infrastructure and cloud security posture management with the platform team: cloud account guardrails, hardening baselines, CSPM findings triage, internet-facing surface inventory, image and container security.
- Coordinate security incident response: develop incident classification runbooks, conduct tabletop exercises, and drive post-incident corrective actions. Partner with Product Security on product-security vulnerabilities and customer-facing risks.
- Partner with product, platform engineering, and IT on remediation, ensuring findings are triaged, deduplicated, and explained to build team trust.
- Supply technical evidence for SOC 2, PCI DSS, and customer due diligence obligations (access reviews, scan results, patch compliance).
- Collaborate with Product and Platform teams; support customer-facing security discussions with accurate technical evidence.
**AI-Related Responsibilities:**
- Participate in maintaining and operationalizing the Internal AI Use Policy and application.
- Secure internal AI tooling and agentic workflows: control data access, scope identities/credentials/tool permissions, establish logging, and detect inappropriate agent behavior.
- Make agentic workflows auditable: track who/what acted, what data and tools were accessed, and under which identity.
**Technical Context:**
Stack includes React/ReactNative/TypeScript, Ruby on Rails, Go and Python microservices on Kubernetes, MongoDB, MySQL, Postgres, Snowflake, and major LLM providers.
**Requirements:**
- 8+ years in security engineering with real depth in security operations: vulnerability management, cloud security posture, detection, or incident response.
- Experience with AWS and Kubernetes; ability to reason about infrastructure as code.
- Expertise with security logging and SIEM-class tooling; experience working with managed detection providers.
- Hands-on experience running infrastructure vulnerability management at scale: scanning fleets, images, containers, and dependencies; prioritizing by exploitability (KEV, EPSS, exposure, asset criticality); driving remediation through owning teams.
- Experience with SOC 2 and/or PCI DSS technical controls.
**Nice to Have:**
- Experience securing payments or regulated fintech systems.
- Detection engineering, threat modeling, or DFIR experience.
- Exposure to EU regulatory obligations (GDPR Art. 33/34, Cyber Resilience Act) and ISO27001.
- Experience in a product company scaling from mid-market to enterprise customers.