远程工作雷达

安全工程师

Security Engineer

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Cloudbeds
薪资未公开
工作地点Canada
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间今天
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 Canada 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

**Cloudbeds 的独特之处**

在 Cloudbeds,我们不仅仅是开发软件,我们正在改变酒店业。我们智能设计的平台为全球 150 个国家的物业提供支持,每年处理数十亿美元的预订。从独立物业到酒店集团,我们帮助酒店业主通过一个统一的平台提升运营和商业策略,该平台与数百家合作伙伴集成。而且我们是一个完全远程的团队。想象一下,与全球创新者一起,打造人工智能驱动的解决方案,解决酒店业主最大的挑战。自 2012 年成立以来,我们已成为全球最佳酒店 PMS 解决方案提供商,并再次入选 2024 年 Deloitte 技术 Fast 500,但我们现在才刚刚开始。

**地点:远程 - 加拿大**

**你将如何产生影响:**

作为我们安全小组的一名 **安全工程师**,你将解决你发现的问题,而不是提交问题。你将在我们的 AWS 环境和应用代码仓库中工作,编写并发布修复真实漏洞的更改。你将构建能告诉我们哪里出错的检测机制。在事件发生时,你将负责处理。

Cloudbeds 是一家获得 PCI DSS 认证的服务提供商,在 150 个国家为物业处理真实资金。这个职位的首要任务是保护我们的客户和业务。三件事:跨整个技术栈的漏洞修复、在 SIEM 中进行检测工程,以及亲自参与事件响应。这里的安全需要跨职能的思维方式。你应该能够与组织中的各个层级的人交流,从工程到销售再到高管。

**我们的安全小组:**

我们是一个小型、资深、全球分布的团队,负责端到端的安全,没有与其他运维团队的交接。编写检测的人就是处理警报和发布修复的人。我们重视自动化和效率,并给予人们深入研究真正重要的事情的空间。

**你将为团队带来什么:**

- 在我们的技术栈中发现并修复漏洞。直接在应用代码仓库和 Terraform 中工作,打开 pull requests,并推动它们被所属团队合并。
- 在 Datadog Cloud SIEM 中构建和优化检测。负责检测覆盖率,编写规则,减少误报,并根据 MITRE ATT&CK 映射我们能看到和看不到的内容。
- 响应安全事件。调查、遏制并撰写根本原因分析,然后跟踪后续措施。

查看英文原文

**What Makes Cloudbeds Unique**

At Cloudbeds, we're not just building software, we’re transforming hospitality. Our intelligently designed platform powers properties across 150 countries, processing billions in bookings annually. From independent properties to hotel groups, we help hoteliers transform operations and uplevel their commercial strategy through a unified platform that integrates with hundreds of partners. And we do it with a completely remote team. Imagine working alongside global innovators to build AI-powered solutions that solve hoteliers' biggest challenges. Since our founding in 2012, we've become the World's Best Hotel PMS Solutions Provider and landed on Deloitte's Technology Fast 500 again in 2024, but we're just getting started.

**Location: Remote - Canada**

**How You'll Make an Impact:**

As a **Security Engineer** on our Security Squad, you will fix the problems you find. Not file them. You will work inside our AWS environment and inside our application repositories, writing and shipping the changes that close real vulnerabilities. You will build the detections that tell us when something is wrong. And you will run point when an incident lands.

Cloudbeds is a PCI DSS certified service provider moving real money for properties in 150 countries. This role’s priority is protecting our customers and our business. Three things: vulnerability remediation across the stack, detection engineering in our SIEM, and hands-on incident response. Security here takes a cross-functional mindset. You should be comfortable talking to individuals at every level of the organization, from Engineering to Sales to Executives.

**Our Security Squad:**

We are a small, senior, globally distributed team that owns security end to end, with no handoff to a separate ops group. The person who writes the detection is the person who works the alert and the person who ships the fix. We value automation and efficiency, and we give people room to go deep on the things that actually matter.

**What You Bring to the Team:**

- Find and fix vulnerabilities across our stack. Work directly in the application repositories and in Terraform, open the pull requests, and drive them to merge with the owning squads.
- Build and tune detections in Datadog Cloud SIEM. Own detection coverage, write the rules, cut the false positives, and map what we can and cannot see against MITRE ATT&CK.
- Respond to security incidents. Investigate, contain, and write the RCA, then track the remediation actions until they are genuinely closed.
- Harden our AWS estate. GuardDuty, Security Hub, Config, CloudTrail, KMS, Secrets Manager, IAM least privilege, and full log coverage across every account.
- Secure the delivery pipeline. GitHub Advanced Security, code scanning, Dependabot, secret scanning and push protection, Crowdstrike container and image scanning, and Kubernetes admission policy.
- Automate the repetitive work. Build workflows and scripts that triage, enrich, and remediate without a human in the loop.
- Write the runbooks, standards, and detection documentation engineers will actually use, and produce the technical evidence behind our PCI DSS Level 1, GDPR, and SOC 2 obligations.

**What Sets You Up for Success:**

- A Bachelor's degree in a relevant field and 4 years of experience, or a minimum of 6 years of practical experience in security engineering, detection engineering, or incident response.
- You write code. You can read an unfamiliar application repository, reason about the vulnerability, and ship the fix as a pull request rather than a ticket.
- Deep AWS security experience. IAM and least-privilege design, GuardDuty, CloudTrail, KMS, VPC controls, and securing container and serverless workloads.
- Hands-on detection engineering in a SIEM. You have written rules, tuned them against real noise, and can explain what you deliberately chose not to alert on.
- Real incident response experience in cloud environments, covering investigation, containment, evidence handling, and the write-up afterward.
- Application security fundamentals: OWASP Top 10, dependency and secrets risk, and practical CI/CD security integration (SAST, DAST, SCA, IaC scanning).
- Strong written communication and diplomacy. Our teams communicate in English. You will need to win arguments with evidence rather than authority.

**Bonus Skills to Stand Out (Optional):**

- Production experience with Datadog Cloud SIEM, CrowdStrike, Okta, or GitHub Advanced Security.
- PCI DSS Level 1 or SOC 2 experience as the engineer supporting the audit, not just as the person answering questionnaires.
- Kubernetes and ArgoCD security, or automation and policy-as-code with Python and Terraform.

#LI-IK1

**What to Expect - Your Journey with Us**

Behind Cloudbeds' revolutionary technology is a team of redefining what's possible in hospitality. We're 650+ employees across 40+ countries, bringing together elite engineers, AI architects, world-class designers, and hospitality veterans to solve challenges others haven't dared to tackle. Our diverse team speaks 30+ languages, but we all share one language: a passion for innovation and travel. From pioneering breakthroughs in machine learning to revolutionizing how hotels operate, we're not just watching the future of hospitality unfold – we're coding it, designing it, writing it, and shipping it. If you're ready to work alongside some of the brightest minds in tech who are obsessed with using AI to transform a trillion-dollar industry, this is your chance to be part of something extraordinary.

Learn more online at [cloudbeds.com](https://www.cloudbeds.com/)

**Company [Awards](https://www.cloudbeds.com/press/?press_type=company-news&news_category=awards):**

- Best All-In-One Hotel Management System | HotelTechAwards (2025)
- Overall 10 Best Places to Work | HotelTechAwards (2025)
- Most Loved Workplace® Certified (2024)
- Top 10 People’s Choice (2024)
- Deloitte Technology Fast 500 (2024)

**Discover our Benefits:**

- Remote First, Remote Always
- PTO in accordance with local labor requirements
- Monthly Wellness Fridays - enjoy an extra-long weekend every month
- Fully Paid Parental Leave
- Home office stipend based on country of residency
- Professional development courses in Cloudbeds University
- Access to professional development, including manager training, upskilling and knowledge transfer

**Everyone is Welcome - A Culture of Inclusion**

Cloudbeds is proud to be an Equal Opportunity Employer that celebrates the diversity in our global team! We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

Cloudbeds is committed to the full inclusion of all qualified individuals. As part of this commitment, Cloudbeds will ensure that persons with disabilities are provided reasonable accommodations in the hiring process. We encourage deaf, hard-of-hearing, deaf-blind, and deaf-disabled individuals to apply. If reasonable accommodation is needed to participate in the job application or interview process or to perform essential job functions, please contact our HR team by phone at (858) 201-7832 or via email at [accommodations@cloudbeds.com](mailto:accommodations@cloudbeds.com). Cloudbeds will provide an American Sign Language (ASL) interpreter where needed as a reasonable accommodation for the hiring processes.

To all Staffing and Recruiting Agencies: Our Careers Site is only for individuals seeking a job at Cloudbeds. Staffing, recruiting agencies, and individuals being represented by an agency are not authorized to use this site or to submit applications, and any such submissions will be considered unsolicited. Cloudbeds does not accept unsolicited resumes or applications from agencies. Please do not forward resumes to our jobs alias, Cloudbeds employees, or any other company location. Cloudbeds is not responsible for any fees related to unsolicited resumes/applications.

#LI-REMOTE

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

全球人才招聘经理

Cloudbeds远程$180,000 - $195,000/年permanent2026-07-15
职能支持全球可投(据职位描述推断)

高级软件工程师

CloudbedsLATAM, Europe, USAFull-Time今天
开发工程限定地区(需当地身份)

← 返回全部职位