Security Engineer

EngineeringSecurity Engineer
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Find and fix vulnerabilities across our stack. Work directly in the application repositories and in Terraform, open the pull requests, and drive them to merge with the owning squads.

Technical Tools
EngineeringSecurity Engineer

At Cloudbeds, we're not just building software, we’re transforming hospitality. Our platform powers hotels across 150 countries, processing billions in bookings annually. From boutique properties to large hotel groups, we help hoteliers transform operations and uplevel their commercial strategy through a unified platform that integrates with hundreds of partners. And we do it with a completely remote team. Imagine working alongside global innovators to build AI-powered solutions that solve hoteliers' biggest challenges. Since our founding in 2012, we've continually been recognized for excellence, most recently earning top honors at the 2026 HotelTechAwards for Best Hotel Management Software and landing on Deloitte's Technology Fast 500 again, but we're just getting started.

As a Security Engineer on our Security Squad, you will fix the problems you find. Not file them. You will work inside our AWS environment and inside our application repositories, writing and shipping the changes that close real vulnerabilities. You will build the detections that tell us when something is wrong. And you will run point when an incident lands.

Cloudbeds is a PCI DSS certified service provider moving real money for properties in 150 countries. This role’s priority is protecting our customers and our business. Three things: vulnerability remediation across the stack, detection engineering in our SIEM, and hands-on incident response. Security here takes a cross-functional mindset. You should be comfortable talking to individuals at every level of the organization, from Engineering to Sales to Executives.

We are a small, senior, globally distributed team that owns security end to end, with no handoff to a separate ops group. The person who writes the detection is the person who works the alert and the person who ships the fix. We value automation and efficiency, and we give people room to go deep on the things that actually matter.

  • Find and fix vulnerabilities across our stack. Work directly in the application repositories and in Terraform, open the pull requests, and drive them to merge with the owning squads.
  • Build and tune detections in Datadog Cloud SIEM. Own detection coverage, write the rules, cut the false positives, and map what we can and cannot see against MITRE ATT&CK.
  • Respond to security incidents. Investigate, contain, and write the RCA, then track the remediation actions until they are genuinely closed.
  • Harden our AWS estate. GuardDuty, Security Hub, Config, CloudTrail, KMS, Secrets Manager, IAM least privilege, and full log coverage across every account.
  • Secure the delivery pipeline. GitHub Advanced Security, code scanning, Dependabot, secret scanning and push protection, Crowdstrike container and image scanning, and Kubernetes admission policy.
  • Automate the repetitive work. Build workflows and scripts that triage, enrich, and remediate without a human in the loop.
  • Write the runbooks, standards, and detection documentation engineers will actually use, and produce the technical evidence behind our PCI DSS Level 1, GDPR, and SOC 2 obligations.
  • A Bachelor's degree in a relevant field and 4 years of experience, or a minimum of 6 years of practical experience in security engineering, detection engineering, or incident response.
  • You write code. You can read an unfamiliar application repository, reason about the vulnerability, and ship the fix as a pull request rather than a ticket.
  • Deep AWS security experience. IAM and least-privilege design, GuardDuty, CloudTrail, KMS, VPC controls, and securing container and serverless workloads.
  • Hands-on detection engineering in a SIEM. You have written rules, tuned them against real noise, and can explain what you deliberately chose not to alert on.
  • Real incident response experience in cloud environments, covering investigation, containment, evidence handling, and the write-up afterward.
  • Application security fundamentals: OWASP Top 10, dependency and secrets risk, and practical CI/CD security integration (SAST, DAST, SCA, IaC scanning).
  • Strong written communication and diplomacy. Our teams communicate in English. You will need to win arguments with evidence rather than authority.

Nice to Have

~1 min read
  • Production experience with Datadog Cloud SIEM, CrowdStrike, Okta, or GitHub Advanced Security.
  • PCI DSS Level 1 or SOC 2 experience as the engineer supporting the audit, not just as the person answering questionnaires.
  • Kubernetes and ArgoCD security, or automation and policy-as-code with Python and Terraform.

Work Authorization: Please note that applicants must be currently authorized to work in the location where the position is located without requiring visa sponsorship. At this time, Cloudbeds is unable to provide sponsorship for work visas.

Depending on your skills and experience, you can expect your annual compensation to be between $120,000 and $150,000 USD. Please note that we maintain high flexibility, and packages above this range will be considered. (The salary is only for US-based candidates).

#LI-IK1

  • Winner – Hotel Management Software | HotelTechAwards (2026)
  • Overall 10 Best Places to Work | HotelTechAwards (2026)
  • Overall Top 10 Hotelier's Choice | HotelTechAwards (2026)
  • Finalist – Property Management Systems (PMS) & Channel Managers | HotelTechAwards (2026)
  • Most Loved Workplace® Certified (2024)
  • Deloitte Technology Fast 500 (2024)

What We Offer

~1 min read
✓Remote First, Remote Always
✓PTO in accordance with local labor requirements
✓Fully Paid Parental Leave
✓Home office stipend based on country of residency
✓Professional development courses in Cloudbeds University
✓Access to professional development, including manager training, upskilling, and knowledge transfer

Cloudbeds is proud to be an Equal Opportunity Employer that celebrates the diversity in our global team! We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

Cloudbeds is committed to the full inclusion of all qualified individuals. As part of this commitment, Cloudbeds will ensure that persons with disabilities are provided reasonable accommodations in the hiring process. We encourage deaf, hard-of-hearing, deaf-blind, and deaf-disabled individuals to apply. If reasonable accommodation is needed to participate in the job application or interview process or to perform essential job functions, please contact our HR team by phone at (858) 201-7832 or via email at accommodations@cloudbeds.com. Cloudbeds will provide an American Sign Language (ASL) interpreter where needed as a reasonable accommodation for the hiring process.

To all Staffing and Recruiting Agencies: Our Careers Site is only for individuals seeking a job at Cloudbeds. Staffing, recruiting agencies, and individuals being represented by an agency are not authorized to use this site or to submit applications, and any such submissions will be considered unsolicited. Cloudbeds does not accept unsolicited resumes or applications from agencies. Please do not forward resumes to our jobs alias, Cloudbeds employees, or any other company location. Cloudbeds is not responsible for any fees related to unsolicited resumes/applications.

#LI-REMOTE

Location & Eligibility

Where is the job
United States
On-site within the country
Who can apply
Open to applicants worldwide

Listing Details

Posted
September 28, 2026
First seen
September 28, 2026
Last seen
September 28, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
60%
Scored at
September 28, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Security Engineer