Senior Security Engineer, Enterprise Security

United States

Airbnb

Get an Airbnb for every kind of trip → 7 million vacation rentals → 2 million Guest Favorites → 220+ countries and regions worldwide

View all jobs at Airbnb

Apply now Apply later

Airbnb was born in 2007 when two Hosts welcomed three guests to their San Francisco home, and has since grown to over 4 million Hosts who have welcomed more than 1 billion guest arrivals in almost every country across the globe. Every day, Hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more authentic way.

The Community You Will Join:

Airbnb’s Enterprise Security team is focused on proactive security and is looking for a hands-on Security Engineer who is passionate about building, defending and enabling our customers with seamless user experiences. Enterprise Security partners closely with IT and Infrastructure teams to secure Airbnb’s corporate systems, network, applications and data. Our philosophy is to enable new business functions by reducing the friction often associated with security controls. Airbnb is a community built on trust, and we are integral to that foundation.

Our team provides security expertise from the design to the implementation stage, builds and / or deploys tools to enhance Airbnb’s security posture, conducts assessments, and automates operational workflows.

The Difference You Will Make:

  • Deploy cloud security solutions and controls in a multi-cloud (e.g. GCP, Azure, AWS) and on-premise infrastructure.
  • Build secure access controls using modern-era tools and techniques (e.g. WebAuthn, SSH over HTTP, Ephemeral access)
  • Utilize infrastructure management tooling (Puppet / Chef, Ansible,Terraform) to enable consistent hardening configs and code-driven security configurations in a multi-cloud, on-prem environment (e.g. GCP, Azure, AWS)
  • Deploy Data Loss Prevention (DLP) solutions focusing on PII and PCI related data that may be in SaaS applications (e.g. GSuite, SalesForce, Box) and consider additional DLP strategies.
  • Deploy vulnerability management tools across CI/CD, compute, and container infrastructure to detect vulnerabilities and security misconfigurations.
  • Enable deployment of Chrome OS at scale for customer support agents to significantly reduce attack surface and improve endpoint management.
  • Orchestrate security posture checks on all new infrastructure deployments.
  • Implement endpoint state attestation tooling.
  • Scale proactive security controls to new environments (e.g. acquisitions).

Additionally, some high-level areas we’re investing in include:

  • Orchestration for security posture checks on all new infrastructure deployments.
  • Endpoint state attestation and hardening.
  • Scale proactive security controls to new environments (e.g. acquisitions).
  • Development of custom and open source security solutions.
  • Cloud Security Architecture and posture management.

A Typical Day: 

  • Provide security expertise and guidance on new projects and technologies.
  • Design and drive implementation of secure infrastructure at scale.
  • Perform risk assessments and build threat models of core corporate and cloud infrastructure.
  • Harden our clients, servers, and networks against exploitation.
  • Build and / or implement tools that aid in enhancing the security posture of corporate infrastructure and services.
  • Collaborate with CSIRT and Production Security teams on cross-functional projects to secure our services and data.

Your Expertise:

  • B.S. or M.S. in Computer Science or related field, or equivalent experience.
  • Knowledge of the threat landscape, common attacks and mitigation methods.
  • Ability to develop tools using an interpreted programming language (Golang, Python, Ruby, etc.).
  • Familiarity with DevOps toolchain (e.g. Puppet / Chef / Ansible, Terraform, Jenkins)
  • A firm grasp of or meaningful experience in the following areas:
    • Operating systems internals and hardening (macOS, Linux, or Windows).
    • Networking protocols and operations
    • Cloud infrastructure and services platforms (AWS and GCP strongly preferred)
    • Authentication, authorization and directory services.
    • Vulnerability management and remediation

We understand that experience and exposure to the technologies listed above are subjective to the opportunities you have been presented during your career. If you have some of these qualifications, but not necessarily all of them, we would still love to hear from you. We value lifetime learners who aspire to take on new opportunities and who can provide diverse perspectives to our Security Engineering team. 

Your Location:

This position is US - Remote Eligible. The role may include occasional work at an Airbnb office or attendance at offsites, as agreed to with your manager. While the position is Remote Eligible, you must live in a state where Airbnb, Inc. has a registered entity. Click here for the up-to-date list of excluded states. This list is continuously evolving, so please check back with us if the state you live in is on the exclusion list. If your position is employed by another Airbnb entity, your recruiter will inform you what states you are eligible to work from.

Our Commitment To Inclusion & Belonging:

Airbnb is committed to working with the broadest talent pool possible. We believe diverse ideas foster innovation and engagement, and allow us to attract creatively-led people, and to develop the best products, services and solutions. All qualified individuals are encouraged to apply.

We strive to also provide a disability inclusive application and interview process. If you are a candidate with a disability and require reasonable accommodation in order to submit an application, please contact us at: reasonableaccommodations@airbnb.com. Please include your full name, the role you’re applying for and the accommodation necessary to assist you with the recruiting process. 

We ask that you only reach out to us if you are a candidate whose disability prevents you from being able to complete our online application.

How We'll Take Care of You:

Our job titles may span more than one career level. The actual base pay is dependent upon many factors, such as: training, transferable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future. This role may also be eligible for bonus, equity, benefits, and Employee Travel Credits.  

Pay Range$185,000—$223,000 USD
Apply now Apply later
Job stats:  3  0  0

Tags: Ansible AWS Azure CI/CD Cloud Computer Science CSIRT DevOps GCP Golang Jenkins Linux MacOS Open Source Puppet Python Risk assessment Ruby SaaS SSH Terraform Vulnerabilities Vulnerability management Windows

Perks/benefits: Career development Equity / stock options Salary bonus

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.