> Markdown version of [/jobs/ext/3167993-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/3167993-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** WeTravel - **Location:** Amsterdam, Netherlands - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), PostgreSQL, MongoDB, MySQL, PCI Data Security Standards, Ruby on Rails, Security Information and Event Management, TypeScript, Software Vulnerability Management, Data Logging, ReactJS, Large Language Models, Snowflake, Software Security, Kubernetes, Infrastructure Automation Frameworks, Golang, Microservices - **Published:** September 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fa5465f26471b3df ## About the Role * 8+ years in security engineering, with real depth in security operations: vulnerability management, cloud security posture, detection, or incident response. * Experience with AWS and Kubernetes, and the ability to reason about infrastructure as code. * Expertise with security logging and SIEM-class tooling, and with working through a managed detection provider. * Hands-on experience running infrastructure vulnerability management at scale: scanning fleets, images, containers and dependencies, prioritizing by exploitability (KEV, EPSS, exposure, asset criticality), and driving remediation through the teams that own the systems * Experience with SOC 2 and/or PCI DSS technical controls. Nice to have * Experience securing payments or regulated fintech systems. * Detection engineering, threat modeling, or DFIR experience. * Exposure to EU regulatory obligations (GDPR Art. 33/34, the Cyber Resilience Act), and ISO27001 * Experience in a product company scaling from mid-market to enterprise customers. ## Description * Own infrastructure vulnerability management. One central register across infrastructure dependencies, containers, images, and cloud infrastructure. Risk-based SLAs, tracking to closure, exception handling, and reporting we can put in front of engineering leadership and an enterprise customer's security team - operating within the Product Security severity and risk framework. One register, one scoring model. * Prioritize infrastructure remediation using contextual risk signals such as KEV, EPSS, exposure, asset criticality, and relevant compensating controls, within the common severity model.. * Automate infrastructure-security workflows: scanner integrations, finding pipelines, normalization, ticket routing, and reporting. If a number has to be assembled by hand every quarter, it's not done. Contribute to shared security finding workflows where appropriate. * Build our detection foundation. Security logging coverage and retention across production, cloud, and identity systems; select and run the managed detection and response partner; make sure the telemetry they need exists and survives. You cannot detect what you do not record, and closing that gap is yours. * Lead infrastructure and cloud security posture management with our platform team: cloud account guardrails, hardening baselines, CSPM findings triage, internet-facing surface inventory, image and container security. * Coordinate security incident response: incident classification runbooks, tabletop exercises, and post-incident corrective actions.. Partner with Product Security on incidents involving product-security vulnerabilities or customer-facing product risk. * Partner with product, platform engineering and IT on remediation. Findings arrive triaged, deduplicated, and explained. A queue engineers don't trust is worse than no queue. * Supply the technical evidence behind our SOC 2, PCI DSS, and customer due diligence obligations - access reviews, scan results, patch compliance. You won't own the questionnaires or the audit relationship. * Collaborate with Product & Platform teams, and support customer-facing security discussions with accurate technical evidence and context. AI Related * Participate in maintaining and operationalizing the Internal AI Use Policy and application * Secure internal AI tooling and agentic workflows: what data agents can reach, how identities, credentials and tool permissions are scoped, what gets logged, and how inappropriate agent behavior is detected * Make agentic workflows auditable: who or what acted, what data and tools were accessed, and under which identity. How We Work: We're focused on the impact. We don't subscribe to any one framework or execution ideology, and we adapt based on what's impactful.We're using the latest hardware and constantly on the look out for better tools & ways to work Stack: We're using React/ReactNative/TypeScript + Ruby on Rails, Go and Python Microservices on Kubernetes. We also use and love MongoDB, MySQL, Postgres, Snowflake and we're working with the major LLM providers. ## Related Videos - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)