DevSecOps Engineer (Cloud Security, AWS)
Core
First line of defense for the Tripadvisor Experiences platform, blending proactive security engineering with reactive incident response in the cloud environment.
Role type
Mid-level hands-on Cloud Security Engineer (AWS, SecOps)
Builds
Security monitoring and alerting capabilities within the production environment
Domain
Travel technology, Cloud Security (AWS)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
AWS core security services (GuardDuty, Security Hub, WAF, CloudTrail), AWS infrastructure (VPC, EC2, RDS, S3, Lambda, EKS), Terraform, incident response lifecycle, scripting (Python, Go, Bash), web application security (OWASP Top 10), threat modeling
Preferred skills
AI tools for efficiency, global-first mindset
Technologies
AWS, Terraform, Python, Go, Bash, WAF, SIEM, CloudTrail, GuardDuty, Security Hub, SAST, DAST, SCA
Responsibilities
Monitor, analyze, and investigate security alerts from AWS infrastructure and application logs; Respond to security incidents impacting the application; Triage vulnerabilities from bug bounty programs; Build and maintain security monitoring and alerting capabilities; Automate security operations tasks using scripting; Configure and manage security tools (WAF, GuardDuty, Security Hub); Operationalize findings from application security tools to remediate vulnerabilities; Conduct threat modeling for new features
Seniority
Mid-level, hands-on IC