About this role
The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world’s most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global audience with partners through rich content, travel guidance, and two-sided marketplaces for experiences, accommodations, restaurants, and other travel categories. The subsidiaries of Tripadvisor, Inc. (Nasdaq: TRIP), include a portfolio of travel brands and businesses, including Tripadvisor, Viator, and TheFork
We are seeking a Cloud Security Engineer II to build, automate, and scale security guardrails across our cloud environment (primary focus on AWS, with secondary exposure to Azure and GCP). In this mid-level role, you will move beyond basic alert monitoring to actively design security controls, embed security into CI/CD pipelines, and partner with DevOps and engineering teams to ensure secure-by-default infrastructure.
Location: Needham - MA or Remote - United States
What You’ll Do
• Cloud Infrastructure Guardrails: Design, deploy, and enforce scalable cloud security controls, IAM least-privilege policies, and encryption standards across multi-account AWS environments.
• DevSecOps Integration: Embed automated security tools (IaC scanning, SAST, secret detection) directly into CI/CD pipelines to catch vulnerabilities pre-deployment.
• Security Automation: Develop automated detection and remediation workflows using Python, Bash, or Go alongside IaC tools (Terraform, CloudFormation).
• Container & Workload Security: Implement and maintain security practices for containerized workloads (Docker, Kubernetes/EKS) and serverless architectures.
• Posture Management & Triage: Manage CSPM/CNAPP platforms, investigate high-priority alerts, and reduce noise through automated risk scoring and alert tuning.
• Threat Modeling & Reviews: Conduct architectural security reviews and threat modeling for new cloud features, infrastructure changes, and third-party integrations.
• Incident Escalation: Act as a secondary point of contact for cloud security incidents, assisting with forensic collection, root-cause analysis, and post-mortem actions.
Skills & Experience
• Experience: 3–5 years of dedicated hands-on experience in cloud security, DevSecOps, or infrastructure security engineering.
• Cloud Expertise: Deep working knowledge of core AWS security services (IAM, GuardDuty, Security Hub, KMS, CloudTrail, Organizations).
• IaC & Code: Strong proficiency in Infrastructure as Code (Terraform preferred) and at least one scripting language (Python, Go, or Bash).
• Container & Pipeline Security: Practical experience securing Kubernetes/EKS and configuring CI/CD security scanners (e.g., GitHub Actions, GitLab CI).
• Networking & Identity: Solid understanding of cloud networking (VPCs, Transit Gateways, WAF, DNS) and identity management (OAuth2, OIDC, SAML).
• Compliance & Frameworks: F