Cloud Security Engineer II
Tripadvisor · Needham- MA
About this role
**Cloud Security Engineer II — Tripadvisor Group** **Location:** Needham, MA or Remote (United States) --- ### What You’ll Do - **Cloud Infrastructure Guardrails:** Design, deploy, and enforce scalable cloud security controls, including **IAM least-privilege** policies and **encryption standards** across multi-account **AWS** environments. - **DevSecOps Integration:** Embed automated security tools (e.g., **IaC scanning, SAST, secret detection**) into **CI/CD pipelines** to catch vulnerabilities pre-deployment. - **Security Automation:** Build automated detection and remediation workflows using **Python, Bash, or Go** alongside **IaC tools** like **Terraform** and **CloudFormation**. - **Container & Workload Security:** Implement and maintain security practices for **containerized workloads** (**Docker, Kubernetes/EKS**) and **serverless** architectures. - **Posture Management & Triage:** Manage **CSPM/CNAPP** platforms, investigate high-priority alerts, and reduce noise via automated **risk scoring** and **alert tuning**. - **Threat Modeling & Reviews:** Conduct architectural security reviews and threat modeling for new cloud features, infrastructure changes, and third-party integrations. - **Incident Escalation:** Serve as a secondary point of contact for cloud security incidents, supporting forensic collection, root-cause analysis, and post-mortems. --- ### Skills & Experience - **Experience:** 3–5 years of hands-on experience in **cloud security**, **DevSecOps**, or **infrastructure security engineering**. - **Cloud Expertise:** Strong working knowledge of core **AWS security services** (**IAM, GuardDuty, Security Hub, KMS, CloudTrail, Organizations**). Secondary exposure to **Azure** and **GCP**. - **IaC & Code:** Proficiency in **Infrastructure as Code** (**Terraform preferred**) and at least one scripting language (**Python, Go, or Bash**). - **Container Pipeline Security:** Experience securing **Kubernetes/EKS** and configuring CI/CD security scanners (e.g., **GitHub Actions, GitLab CI**). - **Networking & Identity:** Understanding of **VPCs, Transit Gateways, WAF, DNS** and identity management (**OAuth2, OIDC, SAML**). - **Compliance Frameworks:** Familiarity mapping controls to **CIS Benchmarks, NIST CSF, SOC 2**. - **Certifications (Preferred):** **AWS Certified Security – Specialty**, **CKS**, **CCSP**, or equivalent. - **Bonus:** Experience in travel, experiences, or marketplace businesses. --- ### What We Offer - Competitive compensation (base salary + annual bonuses) - Flexible, remote-friendly collaboration (with optional on-site as needed) - Flexible schedule and strong work-life balance culture - Donation matching - Tuition assistance - Lifestyle benefit - Travel perks - Employee assistance program - Health benefits - Generous referral scheme --- ### Salary Range **$135,000 – $155,000** (may vary based on factors such as experience, qualifications, certifications, location, and business needs). --- ### Accessibility If you need a reasonable accommodation during the application or recruiting process, contact **AccessibleRecruiting@tripadvisor.com**. For additional questions, email **recruitment@tripadvisor.com**.
Listing freshness
CronJobs last confirmed this listing 13h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.