SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer

WeTravel - Amsterdam, North Holland, Netherlands - Hybrid - posted 2026-09-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

WeTravel is a B2C platform empowering travel entrepreneurs to launch and scale their own travel businesses. The platform simplifies trip creation, payment processing, and customer management for organizers running adventures globally. Last year, 8,000 organizers used WeTravel to lead over a million travelers across 150+ countries, with the company scaling from $1B to $10B in annual travel experiences. As Senior Security Engineer reporting to the Head of Platform & Infrastructure, you will own infrastructure security and detection across WeTravel's production environment. Your responsibilities include: **Core Responsibilities:** - Own infrastructure vulnerability management: maintain a centralized register of infrastructure dependencies, containers, images, and cloud infrastructure with risk-based SLAs, tracking to closure, exception handling, and reporting for engineering leadership and enterprise customers. - Prioritize infrastructure remediation using contextual risk signals (KEV, EPSS, exposure, asset criticality, compensating controls) within a common severity model. - Automate infrastructure-security workflows: scanner integrations, finding pipelines, normalization, ticket routing, and reporting. Eliminate manual quarterly reporting. - Build the detection foundation: establish security logging coverage and retention across production, cloud, and identity systems; select and operate the managed detection and response partner; ensure required telemetry exists and is retained. - Lead infrastructure and cloud security posture management with the platform team: cloud account guardrails, hardening baselines, CSPM findings triage, internet-facing surface inventory, image and container security. - Coordinate security incident response: develop incident classification runbooks, conduct tabletop exercises, and drive post-incident corrective actions. Partner with Product Security on product-security vulnerabilities and customer-facing product risk. - Partner with product, platform engineering, and IT on remediation, ensuring findings are triaged, deduplicated, and explained to build team trust. - Supply technical evidence for SOC 2, PCI DSS, and customer due diligence obligations: access reviews, scan results, patch compliance. - Collaborate with Product and Platform teams; support customer-facing security discussions with accurate technical evidence and context. **AI-Related Responsibilities:** - Participate in maintaining and operationalizing the Internal AI Use Policy and application. - Secure internal AI tooling and agentic workflows: control data agent access, scope identities/credentials/tool permissions, establish logging, and detect inappropriate agent behavior. - Make agentic workflows auditable: track who/what acted, what data and tools were accessed, and under which identity. **Requirements:** - 8+ years in security engineering with real depth in security operations: vulnerability management, cloud security posture, detection, or incident response. - Experience with AWS and Kubernetes, and ability to reason about infrastructure as code. - Expertise with security logging and SIEM-class tooling, and working through a managed detection provider. - Hands-on experience running infrastructure vulnerability management at scale: scanning fleets, images, containers, and dependencies; prioritizing by exploitability (KEV, EPSS, exposure, asset criticality); driving remediation through owning teams. - Experience with SOC 2 and/or PCI DSS technical controls. **Nice to Have:** - Experience securing payments or regulated fintech systems. - Detection engineering, threat modeling, or DFIR experience. - Exposure to EU regulatory obligations (GDPR Art. 33/34, Cyber Resilience Act) and ISO27001. - Experience in a product company scaling from mid-market to enterprise customers.

Similar roles