远程工作雷达

高级安全工程师

Senior Security Engineer

开发工程限定地区(需当地身份)
公司WeTravel
薪资未公开
工作地点Bulgaria、Italy、Ireland、Spain、Poland、Portugal、Lithuania
地域资格限定地区(需当地身份)
时区要求日间重叠约 3 小时,需偶尔早起或晚睡
用工类型permanent
发布时间今天
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 Bulgaria、Italy、Ireland、Spain、Poland、Portugal、Lithuania 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

嗨!我是George 👋 WeTravel平台与基础设施部门负责人。

我加入WeTravel是为了帮助我们在增长过程中构建安全、可靠且可扩展的IT环境。我们团队的使命是为每位WeTravel员工提供他们需要的工具和支持,让他们无论身处世界何处都能高效、安全且无摩擦地工作。

### **关于WeTravel:**

想象一下最令人惊叹的冒险:徒步前往马丘比丘,骑车穿越托斯卡纳,或是在肯尼亚进行野生动物探险。多年来,运营这些旅行的小企业和当地专家一直使用混乱的电子表格、无数邮件和复杂的支付方式。

WeTravel正在改变这一现状。我们打造了工具,使任何企业家都能启动并发展自己的旅游业务。我们的平台让组织者可以轻松创建精美的旅行提案,安全处理支付,并管理客户,这样他们就可以专注于自己最擅长的事情:创造精彩的体验。

这是旅游领域最后一个尚未在线化的前沿,作为该领域的领导者,我们正处于这场变革的最前沿。仅去年一年,我们的平台就受到8000名组织者的信赖,带领超过一百万名旅行者前往150多个国家的冒险之旅。现在,我们正踏上激动人心的旅程,将我们所支持的旅行体验价值从每年10亿美元增长到100亿美元。

我们认为,每一次正确的旅行都可以成为一种向善的力量——而我们正在打造实现更多这种力量的引擎。

### **这个职位的职责:**

- 负责基础设施漏洞管理。在基础设施依赖项、容器、镜像和云基础设施之间建立一个统一的注册表。基于风险的SLA,跟踪至关闭,异常处理和报告,可以展示给工程领导层和企业客户的安全部门——在产品安全严重性和风险框架内运作。一个注册表,一个评分模型。

- 使用上下文相关的风险信号(如KEV、EPSS、暴露程度、资产关键性以及相关的补偿控制措施),在通用严重性模型内对基础设施修复进行优先级排序。

- 自动化基础设施安全工作流程:扫描器集成、发现流水线、标准化、工单路由和报告。如果一个数字每季度都需要手动组装,那就没有完成。在适当的情况下,为共享的安全发现工作流程做出贡献。

- 构建我们的检测基础。在生产环境、云环境中实现安全日志的覆盖和保留。

查看英文原文

Hi! I’m George 👋 Head of Platform & Infrastructure here at WeTravel.

I joined WeTravel to help build a secure, reliable, and scalable IT environment as we grow. Our team’s mission is to empower every WeTravel employee with the tools and support they need to work efficiently, securely, and without friction - no matter where they are in the world.

### **About WeTravel:**

Think of the most incredible adventures imaginable: trekking to Machu Picchu, cycling through Tuscany, or going on a safari in Kenya. For years, the small businesses and local experts who run these trips have been stuck using messy spreadsheets, countless emails, and complicated payment methods.

WeTravel is changing that. We build the tools that empower any entrepreneur to launch and grow their own travel business. Our platform makes it simple for organizers to create beautiful trip proposals, securely process payments, and manage their customers, so they can focus on what they do best: creating amazing experiences.

This is one of the last great frontiers of travel to come online, and as the category leader, we are at the forefront of this change. Last year alone, our platform was trusted by 8,000 organizers to lead over a million travelers on adventures in 150+ countries. Now, we're on an exciting journey to grow from powering $1B to $10B in travel experiences per year.

We believe that every trip, when done right, can be a force for good - and we're building the engine to make more of that possible.

### **What's the role:**

- Own infrastructure vulnerability management. One central register across infrastructure dependencies, containers, images, and cloud infrastructure. Risk-based SLAs, tracking to closure, exception handling, and reporting we can put in front of engineering leadership and an enterprise customer's security team — operating within the Product Security severity and risk framework. One register, one scoring model.

- Prioritize infrastructure remediation using contextual risk signals such as KEV, EPSS, exposure, asset criticality, and relevant compensating controls, within the common severity model..

- Automate infrastructure-security workflows: scanner integrations, finding pipelines, normalization, ticket routing, and reporting. If a number has to be assembled by hand every quarter, it's not done. Contribute to shared security finding workflows where appropriate.

- Build our detection foundation. Security logging coverage and retention across production, cloud, and identity systems; select and run the managed detection and response partner; make sure the telemetry they need exists and survives. You cannot detect what you do not record, and closing that gap is yours.

- Lead infrastructure and cloud security posture management with our platform team: cloud account guardrails, hardening baselines, CSPM findings triage, internet-facing surface inventory, image and container security.

- Coordinate security incident response: incident classification runbooks, tabletop exercises, and post-incident corrective actions.. Partner with Product Security on incidents involving product-security vulnerabilities or customer-facing product risk.

- Partner with product, platform engineering and IT on remediation. Findings arrive triaged, deduplicated, and explained. A queue engineers don't trust is worse than no queue.

- Supply the technical evidence behind our SOC 2, PCI DSS, and customer due diligence obligations — access reviews, scan results, patch compliance. You won't own the questionnaires or the audit relationship.

- Collaborate with Product & Platform teams, and support customer-facing security discussions with accurate technical evidence and context.

**AI Related**

- Participate in maintaining and operationalizing the Internal AI Use Policy and application

- Secure internal AI tooling and agentic workflows: what data agents can reach, how identities, credentials and tool permissions are scoped, what gets logged, and how inappropriate agent behavior is detected

- Make agentic workflows auditable: who or what acted, what data and tools were accessed, and under which identity.

### **How We Work:**

We’re focused on the impact. We don’t subscribe to any one framework or execution ideology, and we adapt based on what’s impactful.We’re using the latest hardware and constantly on the look out for better tools & ways to work

Stack: We’re using React/ReactNative/TypeScript + Ruby on Rails, Go and Python Microservices on Kubernetes. We also use and love MongoDB, MySQL, Postgres, Snowflake and we’re working with the major LLM providers.

### **You should apply if you have:**

- 8+ years in security engineering, with real depth in security operations: vulnerability management, cloud security posture, detection, or incident response.

- Experience with AWS and Kubernetes, and the ability to reason about infrastructure as code.

- Expertise with security logging and SIEM-class tooling, and with working through a managed detection provider.

- Hands-on experience running infrastructure vulnerability management at scale: scanning fleets, images, containers and dependencies, prioritizing by exploitability (KEV, EPSS, exposure, asset criticality), and driving remediation through the teams that own the systems

- Experience with SOC 2 and/or PCI DSS technical controls.

**Nice to have**

- Experience securing payments or regulated fintech systems.

- Detection engineering, threat modeling, or DFIR experience.

- Exposure to EU regulatory obligations (GDPR Art. 33/34, the Cyber Resilience Act), and ISO27001

- Experience in a product company scaling from mid-market to enterprise customers.

### Benefits Section

- Competitive salary

- Generous "Time to Recharge" policy - enjoy unlimited paid time off to rest, recharge, and show up as your best self.

- Our Work From Anywhere perk provides eligible employees with up to four weeks per calendar year to work temporarily from another approved location.

- 2-week cross-functional onboarding program.

- Annual team off-site (often somewhere sunny 🌊).

- Cycle-to-work scheme (Swapfiets subscription) or commuting reimbursement.

- Extensive paid family leave.

- Three paid volunteer days per year - take time to give back to causes you care about, on us.

- Cutting-edge equipment and tools to set you up for success.

- Join an international, travel-loving team with a passion for adventure and innovation.

### Equal Opportunities

WeTravel is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We welcome applicants from all backgrounds, experiences, and perspectives. If you're excited about this opportunity and believe you're a good fit, we encourage you to apply and join us in transforming the travel industry!

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

活动运营专员

WeTravelMexico$20,000 - $25,000/年contract11 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位