Security Operations (SecOps) Engineer
About Travala
Founded in 2017 and now backed by industry giant Binance, Travala is the leading crypto-native travel booking service, offering 2,200,000+ properties across 230 countries, 600+ airlines, 50,000+ car rental locations, and 400,000+ activities globally.
Travala is a champion of cryptocurrency adoption, accepting over 100 leading cryptocurrencies alongside traditional payment methods. In addition to unbeatable prices via its Best Price Guarantee, Smart members on Travala can also enjoy additional discounts and loyalty rewards for eligible bookings made on the platform.
By incorporating next-generation blockchain technology and tokenised loyalty rewards, Travala.com is creating a cutting-edge experience at the intersection of Web3 and travel.
Position Overview
Location: Hanoi, Vietnam (Hybrid)
We're looking for a Security Operations (SecOps) Engineer to help build and scale Security Operations at Travala.
Working closely with the Security Engineering Lead, you'll monitor security events, investigate alerts, respond to security incidents, and help protect our AWS infrastructure and global travel platform.
As a foundational member of our newly expanding Hanoi security hub, you'll have the opportunity to shape operational processes, improve detection and response capabilities, and make a meaningful impact on the security of a fast-growing Web3 business.
Key Responsibilities
- Security Monitoring & Investigation: Monitor and investigate security events across cloud infrastructure, applications, endpoints, and network environments using SIEM and security monitoring tools.
- Incident Response: Perform Tier 1–2 incident triage, execute incident response playbooks, and escalate complex incidents when required.
- Threat Containment: Carry out containment actions such as updating WAF rules, blocking malicious traffic, isolating compromised endpoints, and disabling compromised accounts.
- Vulnerability Management: Conduct routine vulnerability scans, validate remediation, and coordinate patch deployment with engineering teams.
- Identity & Access Management: Administer day-to-day IAM activities, including user provisioning, permission reviews, and access validation following Zero Trust and least-privilege principles.
- Security Automation: Develop lightweight automation scripts using Python or Bash to improve operational efficiency.
- Documentation & Continuous Improvement: Maintain incident documentation, operational runbooks, and contribute to improving Security Operations processes and playbooks.
Requirements
- 2-4+ years of experience in Security Operations (SecOps), SOC, Incident Response, or Blue Team roles within technology, SaaS, FinTech, Web3, or eCommerce environments.
- Proven ability to independently investigate and respond to security incidents in production environments.
- SIEM & Log Analysis: Experience with SIEM platforms such as Splunk, Datadog, Microsoft Sentinel, ELK, or similar.
- Security Operations: Experience investigating security alerts and analyzing system, application, or network logs.
- Network Security: Familiarity with Web Application Firewalls (Cloudflare, AWS WAF, or equivalent) and networking fundamentals (TCP/IP, DNS, HTTP/S).
- Operating Systems: Working knowledge of Linux systems.
- Automation: Basic scripting skills in Python or Bash.
Nice to Have:
- Endpoint Security: Experience with EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender.
- Cloud Security: Exposure to AWS security services and vulnerability management tools.
- Web3: Basic understanding of blockchain, cryptocurrency, or Web3 ecosystems.
- English: Professional English proficiency is an advantage, particularly for reading technical documentation, writing incident reports, and collaborating with international teams.
Benefits
- Compensation: Competitive base salary commensurate with experience and technical proficiency, plus a 13th-month salary and performance bonus.
- Health & Wellness: Social insurance, 24/7 accident insurance, annual health check-up, and premium private healthcare coverage.
- Premium Tools: High-end MacBook and all necessary peripherals.
- Travel Perks: Access to Smart Platinum tier on Travala.com for exclusive discounts and rewards.
- Work-Life Balance: Hybrid working mode and a dynamic, international company culture.
- Growth: Dedicated annual budget for courses, certifications, and tech conferences.
- Community: Free snacks/coffee, team bonding activities, domestic and overseas company trips, and year-end celebrations.