28 sep
|
WeTravel
|
La Mancha
28 sep
WeTravel
La Mancha
Senior Security Engineer at WeTravel in ES. Apply for Senior Security Engineer at WeTravel in ES. This Full time on site position offers great opportunities for career growth. I joined WeTravel to help build a secure, reliable, and scalable IT environment as we grow.
Think of the most incredible adventures imaginable: trekking to Machu Picchu, cycling through Tuscany, or going on a safari in Kenya. For years, the small businesses and local experts who run these trips have been stuck using messy spreadsheets, countless emails, and complicated payment methods. Our platform makes it simple for organizers to create beautiful trip proposals, securely process payments, and manage their customers, so they can focus on what they do best: creating amazing experiences.
This is one of the last great frontiers of travel to come online, and as the category leader, we are at the forefront of this change. One central register across infrastructure dependencies, containers, images, and cloud infrastructure. Risk-based SLAs, tracking to closure, exception handling, and reporting we can put in front of engineering leadership and an enterprise customer's security team — operating within the Product Security severity and risk framework.
Prioritize infrastructure remediation using contextual risk signals such as KEV, EPSS, exposure, asset criticality, and relevant compensating controls, within the common severity model.. Automate infrastructure-security workflows: scanner integrations, finding pipelines, normalization, ticket routing, and reporting. If a number has to be assembled by hand every quarter, it's not done.
Contribute to shared security finding workflows where appropriate. Security logging coverage and retention across production, cloud, and identity systems; Lead infrastructure and cloud security posture management with our platform team: cloud account guardrails, hardening baselines,
CSPM findings triage, internet-facing surface inventory, image and container security.
Coordinate security incident response: incident classification runbooks, tabletop exercises, and post-incident corrective actions.. Partner with Product Security on incidents involving product-security vulnerabilities or customer-facing product risk. Partner with product, platform engineering and IT on remediation.
Collaborate with Product & Platform teams, and support customer-facing security discussions with accurate technical evidence and context. Participate in maintaining and operationalizing the Internal AI Use Policy and application Secure internal AI tooling and agentic workflows: what data agents can reach, how identities, credentials and tool permissions are scoped, what gets logged, and how inappropriate agent behavior is detected Make agentic workflows auditable: who or what acted, what data and tools were accessed, and under which identity. We're using React/ReactNative/TypeScript + Ruby on Rails, Go and Python Microservices on Kubernetes.
We also use and love MongoDB, MySQL, Postgres, Snowflake and we're working with the major LLM providers. 8+ years in security engineering, with real depth in security operations: vulnerability management, cloud security posture, detection, or incident response.
Experience with AWS and Kubernetes, and the ability to reason about infrastructure as code. Expertise with security logging and SIEM-class tooling, and with working through a managed detection provider. Hands-on experience running infrastructure vulnerability management at scale: scanning fleets, images, containers and dependencies, prioritizing by exploitability (KEV, EPSS, exposure, asset criticality), and driving remediation through the teams that own the systems Experience with SOC 2 and/or PCI DSS technical controls.
Join an international, travel-loving team with a passion for adventure and innovation.
📌 Senior AWS Security Engineer (La Mancha)
🏢 WeTravel
📍 La Mancha