# Senior Security Engineer

[Wetravel](https://gurify.com/jobs?q=Wetravel) · Amsterdam · Posted today

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/wetravel/07b157da-4973-4fe4-9ca5-5177ea0e254f)

## Job description

Hi! I’m George 👋 Head of Platform & Infrastructure here at WeTravel.

I joined WeTravel to help build a secure, reliable, and scalable IT environment as we grow. Our team’s mission is to empower every WeTravel employee with the tools and support they need to work efficiently, securely, and without friction - no matter where they are in the world.

### ABOUT WETRAVEL:

Think of the most incredible adventures imaginable: trekking to Machu Picchu, cycling through Tuscany, or going on a safari in Kenya. For years, the small businesses and local experts who run these trips have been stuck using messy spreadsheets, countless emails, and complicated payment methods.

WeTravel is changing that. We build the tools that empower any entrepreneur to launch and grow their own travel business. Our platform makes it simple for organizers to create beautiful trip proposals, securely process payments, and manage their customers, so they can focus on what they do best: creating amazing experiences.

This is one of the last great frontiers of travel to come online, and as the category leader, we are at the forefront of this change. Last year alone, our platform was trusted by 8,000 organizers to lead over a million travelers on adventures in 150+ countries. Now, we're on an exciting journey to grow from powering $1B to $10B in travel experiences per year.

We believe that every trip, when done right, can be a force for good - and we're building the engine to make more of that possible.

### WHAT'S THE ROLE:

- Own infrastructure vulnerability management. One central register across infrastructure dependencies, containers, images, and cloud infrastructure. Risk-based SLAs, tracking to closure, exception handling, and reporting we can put in front of engineering leadership and an enterprise customer's security team — operating within the Product Security severity and risk framework. One register, one scoring model.

- Prioritize infrastructure remediation using contextual risk signals such as KEV, EPSS, exposure, asset criticality, and relevant compensating controls, within the common severity model..

- Automate infrastructure-security workflows: scanner integrations, finding pipelines, normalization, ticket routing, and reporting. If a number has to be assembled by hand every quarter, it's not done. Contribute to shared security finding workflows where appropriate.

- Build our detection foundation. Security logging coverage and retention across production, cloud, and identity systems; select and run the managed detection and response partner; make sure the telemetry they need exists and survives. You cannot detect what you do not record, and closing that gap is yours.

- Lead infrastructure and cloud security posture management with our platform team: cloud account guardrails, hardening baselines, CSPM findings triage, internet-facing surface inventory, image and container security.

- Coordinate security incident response: incident classification runbooks, tabletop exercises, and post-incident corrective actions.. Partner with Product Security on incidents involving product-security vulnerabilities or customer-facing product risk.

- Partner with product, platform engineering and IT on remediation. Findings arrive triaged, deduplicated, and explained. A queue engineers don't trust is worse than no queue.

- Supply the technical evidence behind our SOC 2, PCI DSS, and customer due diligence obligations — access reviews, scan results, patch compliance. You won't own the questionnaires or the audit relationship.

- Collaborate with Product & Platform teams, and support customer-facing security discussions with accurate technical evidence and context.

### AI Related

- Participate in maintaining and operationalizing the Internal AI Use Policy and application

- Secure internal AI tooling and agentic workflows: what data agents can reach, how identities, credentials and tool permissions are scoped, what gets logged, and how inappropriate agent behavior is detected

- Make agentic workflows auditable: who or what acted, what data and tools were accessed, and under which identity.

### HOW WE WORK:

We’re focused on the impact. We don’t subscribe to any one framework or execution ideology, and we adapt based on what’s impactful.We’re using the latest hardware and constantly on the look out for better tools & ways to work

Stack: We’re using React/ReactNative/TypeScript + Ruby on Rails, Go and Python Microservices on Kubernetes. We also use and love MongoDB, MySQL, Postgres, Snowflake and we’re working with the major LLM providers.

### YOU SHOULD APPLY IF YOU HAVE:

- 8+ years in security engineering, with real depth in security operations: vulnerability management, cloud security posture, detection, or incident response.

- Experience with AWS and Kubernetes, and the ability to reason about infrastructure as code.

- Expertise with security logging and SIEM-class tooling, and with working through a managed detection provider.

- Hands-on experience running infrastructure vulnerability management at scale: scanning fleets, images, containers and dependencies, prioritizing by exploitability (KEV, EPSS, exposure, asset criticality), and driving remediation through the teams that own the systems

- Experience with SOC 2 and/or PCI DSS technical controls.

### Nice to have

- Experience securing payments or regulated fintech systems.

- Detection engineering, threat modeling, or DFIR experience.

- Exposure to EU regulatory obligations (GDPR Art. 33/34, the Cyber Resilience Act), and ISO27001

- Experience in a product company scaling from mid-market to enterprise customers.

### BENEFITS SECTION

- Competitive salary

- Generous "Time to Recharge" policy - enjoy unlimited paid time off to rest, recharge, and show up as your best self.

- Our Work From Anywhere perk provides eligible employees with up to four weeks per calendar year to work temporarily from another approved location.

- 2-week cross-functional onboarding program.

- Annual team off-site (often somewhere sunny 🌊).

- Cycle-to-work scheme (Swapfiets subscription) or commuting reimbursement.

- Monday/Thursday team lunches and after-work social events.

- Extensive paid family leave.

- Three paid volunteer days per year - take time to give back to causes you care about, on us.

- Cutting-edge equipment and tools to set you up for success.

- Join an international, travel-loving team with a passion for adventure and innovation.

### EQUAL OPPORTUNITIES

WeTravel is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We welcome applicants from all backgrounds, experiences, and perspectives. If you're excited about this opportunity and believe you're a good fit, we encourage you to apply and join us in transforming the travel industry!

**Live in Wetravel’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- DA [Senior Specialist Solutions Engineer - Platform Security and Cloud ...](https://gurify.com/job/senior-specialist-solutions-engineer-platform-security-and-cloud-at-c1616db887cb) Databricks · Amsterdam, Netherlands · 6 weeks ago
- RE [Lead Physical Security Engineer](https://gurify.com/job/lead-physical-security-engineer-at-reddit-e1db18b35616) Reddit · Amsterdam, Netherlands · 6 weeks ago
- CN [Customer Success Engineer – AI Security](https://gurify.com/job/customer-success-engineer-ai-security-at-cato-networks-7520a3059408) Cato Networks · Amsterdam, Netherlands · 2 months ago
- FL [Product Security Engineer II](https://gurify.com/job/product-security-engineer-ii-at-flexport-434522279c39) Flexport · Amsterdam, Netherlands · 2 months ago
- RT [Staff Security Engineer](https://gurify.com/job/staff-security-engineer-at-rtbhouse-14f338af67a4) Rtbhouse · Warsaw, Poland · last week
- AT [Staff Security Engineer, Cloud Security](https://gurify.com/job/staff-security-engineer-cloud-security-at-attentive-f08cba401a13) Attentive · United States · 3 days ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Security Engineer","description":"\u003Cp\u003EHi! I\u2019m George \u0026#128075; Head of Platform \u0026amp; Infrastructure here at WeTravel.\u003C/p\u003E\u003Cp\u003EI joined WeTravel to help build a secure, reliable, and scalable IT environment as we grow. Our team\u2019s mission is to empower every WeTravel employee with the tools and support they need to work efficiently, securely, and without friction - no matter where they are in the world.\u003C/p\u003E\u003Ch3\u003EABOUT WETRAVEL:\u003C/h3\u003E\u003Cp\u003EThink of the most incredible adventures imaginable: trekking to Machu Picchu, cycling through Tuscany, or going on a safari in Kenya. For years, the small businesses and local experts who run these trips have been stuck using messy spreadsheets, countless emails, and complicated payment methods.\u003C/p\u003E\u003Cp\u003EWeTravel is changing that. We build the tools that empower any entrepreneur to launch and grow their own travel business. Our platform makes it simple for organizers to create beautiful trip proposals, securely process payments, and manage their customers, so they can focus on what they do best: creating amazing experiences.\u003C/p\u003E\u003Cp\u003EThis is one of the last great frontiers of travel to come online, and as the category leader, we are at the forefront of this change. Last year alone, our platform was trusted by 8,000 organizers to lead over a million travelers on adventures in 150\u002B countries. Now, we\u0026#39;re on an exciting journey to grow from powering $1B to $10B in travel experiences per year.\u003C/p\u003E\u003Cp\u003EWe believe that every trip, when done right, can be a force for good - and we\u0026#39;re building the engine to make more of that possible.\u003C/p\u003E\u003Ch3\u003EWHAT\u0026#39;S THE ROLE:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EOwn infrastructure vulnerability management. One central register across infrastructure dependencies, containers, images, and cloud infrastructure. Risk-based SLAs, tracking to closure, exception handling, and reporting we can put in front of engineering leadership and an enterprise customer\u0026#39;s security team \u2014 operating within the Product Security severity and risk framework. One register, one scoring model.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrioritize infrastructure remediation using contextual risk signals such as KEV, EPSS, exposure, asset criticality, and relevant compensating controls, within the common severity model..\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAutomate infrastructure-security workflows: scanner integrations, finding pipelines, normalization, ticket routing, and reporting.  If a number has to be assembled by hand every quarter, it\u0026#39;s not done. Contribute to shared security finding workflows where appropriate.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild our detection foundation. Security logging coverage and retention across production, cloud, and identity systems; select and run the managed detection and response partner; make sure the telemetry they need exists and survives. You cannot detect what you do not record, and closing that gap is yours.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead infrastructure and cloud security posture management with our platform team: cloud account guardrails, hardening baselines, CSPM findings triage, internet-facing surface inventory, image and container security.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECoordinate security incident response: incident classification runbooks, tabletop exercises, and post-incident corrective actions.. Partner with Product Security on incidents involving product-security vulnerabilities or customer-facing product risk.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with product, platform engineering and IT on remediation. Findings arrive triaged, deduplicated, and explained. A queue engineers don\u0026#39;t trust is worse than no queue.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupply the technical evidence behind our SOC 2, PCI DSS, and customer due diligence obligations \u2014 access reviews, scan results, patch compliance. You won\u0026#39;t own the questionnaires or the audit relationship.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaborate with Product \u0026amp; Platform teams, and support customer-facing security discussions with accurate technical evidence and context.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EAI Related\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EParticipate in maintaining and operationalizing the Internal AI Use Policy and application\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecure internal AI tooling and agentic workflows: what data agents can reach, how identities, credentials and tool permissions are scoped, what gets logged, and how inappropriate agent behavior is detected\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMake agentic workflows auditable: who or what acted, what data and tools were accessed, and under which identity.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EHOW WE WORK:\u003C/h3\u003E\u003Cp\u003EWe\u2019re focused on the impact. We don\u2019t subscribe to any one framework or execution ideology, and we adapt based on what\u2019s impactful.We\u2019re using the latest hardware and constantly on the look out for better tools \u0026amp; ways to work\u003C/p\u003E\u003Cp\u003EStack: We\u2019re using React/ReactNative/TypeScript \u002B Ruby on Rails, Go and Python Microservices on Kubernetes. We also use and love MongoDB, MySQL, Postgres, Snowflake and we\u2019re working with the major LLM providers.\u003C/p\u003E\u003Ch3\u003EYOU SHOULD APPLY IF YOU HAVE:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E8\u002B years in security engineering, with real depth in security operations: vulnerability management, cloud security posture, detection, or incident response.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with AWS and Kubernetes, and the ability to reason about infrastructure as code.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExpertise with security logging and SIEM-class tooling, and with working through a managed detection provider.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on experience running infrastructure vulnerability management at scale: scanning fleets, images, containers and dependencies, prioritizing by exploitability (KEV, EPSS, exposure, asset criticality), and driving remediation through the teams that own the systems\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience  with SOC 2 and/or PCI DSS technical controls.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENice to have\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience securing payments or regulated fintech systems.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDetection engineering, threat modeling, or DFIR experience.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExposure to EU regulatory obligations (GDPR Art. 33/34, the Cyber Resilience Act), and ISO27001\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience in a product company scaling from mid-market to enterprise customers.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EBENEFITS SECTION\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ECompetitive salary\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EGenerous \u0026quot;Time to Recharge\u0026quot; policy - enjoy unlimited paid time off to rest, recharge, and show up as your best self.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOur Work From Anywhere perk provides eligible employees with up to four weeks per calendar year to work temporarily from another approved location.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E2-week cross-functional onboarding program.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAnnual team off-site (often somewhere sunny \u0026#127754;).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECycle-to-work scheme (Swapfiets subscription) or commuting reimbursement.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMonday/Thursday team lunches and after-work social events.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExtensive paid family leave.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThree paid volunteer days per year - take time to give back to causes you care about, on us.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECutting-edge equipment and tools to set you up for success.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EJoin an international, travel-loving team with a passion for adventure and innovation.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EEQUAL OPPORTUNITIES\u003C/h3\u003E\u003Cp\u003EWeTravel is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We welcome applicants from all backgrounds, experiences, and perspectives. If you\u0026#39;re excited about this opportunity and believe you\u0026#39;re a good fit, we encourage you to apply and join us in transforming the travel industry!\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-security-engineer-at-wetravel-3f868b4d24ac"},"url":"https://gurify.com/job/senior-security-engineer-at-wetravel-3f868b4d24ac","datePosted":"2026-09-17","validThrough":"2026-11-01T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Wetravel","sameAs":"https://jobs.ashbyhq.com/wetravel"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"NL","addressLocality":"Amsterdam"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Netherlands","item":"https://gurify.com/jobs/netherlands"},{"@type":"ListItem","position":3,"name":"Senior Security Engineer","item":"https://gurify.com/job/senior-security-engineer-at-wetravel-3f868b4d24ac"}]}
```
