KAYAK, part of Booking Holdings (NASDAQ: BKNG), is a leading travel search engine. With billions of queries across our platforms, we help people find their perfect flight, stay, rental car and vacation package. We're also transforming business travel with a new corporate travel solution, KAYAK for Business.
As an employee of KAYAK, you will be part of a travel company that operates a portfolio of global metasearch brands including momondo, Cheapflights and HotelsCombined, among others. From start-up to industry leader, innovation is in our DNA and every employee has an opportunity to make their mark. Our focus is on building the best travel search engine to make it easier for everyone to experience the world.
Security at KAYAK is a team effort — we protect the people, systems, and data that power travel for millions of users worldwide, and we do it by working closely with engineering, operations, and product teams. As an Associate Security Engineer, you will help to drive our vulnerability management program while contributing across multiple security domains in a collaborative, globally distributed environment. You can find more information about our security program at https://www.kayak.com/security.
This role is required to work from our Berlin, Germany office 3 days per week.
In this role, you will:Support and continuously improve the vulnerability management program — defining processes for identifying, prioritizing, tracking, and driving remediation of security findings across infrastructure and applications. This includes working closely with engineering, operations, and IT teams to ensure findings are understood, assigned, and resolved in a timely manner, and reporting on program health and trends to security leadership.
Participate in incident response activities, including triage, investigation, containment, and post-incident documentation.
Support application security initiatives, including automated code scanning, dependency analysis, and working with engineering teams to address security findings early in the development process.
Help configure, monitor, and improve security tooling across areas such as endpoint protection, email security, identity and access management, and cloud security posture.
Contribute to security automation and orchestration workflows that reduce manual effort and improve response times.
Collaborate with engineering, operations, and compliance teams to embed security thinking into development workflows and infrastructure changes.
Document processes, runbooks, and findings to support team knowledge sharing and continuity.
Participate in access reviews and support identity and access management processes in line with established policies.
Stay current with the evolving threat landscape and contribute ideas for improving the team's detection and response capabilities.
A solid understanding of cybersecurity fundamentals — including networking, operating systems (Linux, macOS, or Windows), and cloud environments — gained through any combination of formal education, self-study, bootcamps, or professional experience.
Hands-on experience in at least one security domain, such as vulnerability management, incident response, application security, endpoint security, or identity and access management.
Experience working with security tooling (e.g., vulnerability scanners, endpoint detection and response platforms, SIEM systems, or similar); familiarity with specific tools is a plus, but willingness to learn our stack matters more than exact tool experience.
Familiarity with AI tools and how they can be applied in a security context — whether for automating workflows, triaging alerts, or improving detection and response. Experience working with AI models or building AI-assisted workflows is a plus.
The ability to communicate clearly in writing and in conversation — our team is globally distributed and works primarily in English (professional working proficiency is sufficient; native fluency is not required).
A collaborative approach to problem-solving — you ask questions, share what you learn, and support your teammates.
Comfort working with some degree of autonomy on assigned tasks and projects, while knowing when to ask for input.
Familiarity with the NIST Cybersecurity Framework or similar security frameworks.
Experience with cloud environments (AWS or GCP) or container security.
Exposure to security automation or scripting (e.g., Python, workflow automation tools).
Experience working in a regulated environment (e.g., SOC 2, PCI).
Work from (almost) anywhere for up to 20 days per year
Focus on mental health and well-being:
Company-paid therapy sessions through SpringHealth
Company-paid subscription to HeadSpace
Company-wide week off a year - the whole team fully recharges (and returns without a pile-up of work!)
No meeting Fridays
Paid parental leave
Generous paid vacation + time off for your birthday
Paid volunteer time
Focus on your career growth:
Development Dollars
Leadership development
Access to thousands of on-demand e-learnings
Travel Discounts
Employee Resource Groups
6 weeks paid vacation
Free lunch 2 days per week
Pension plan contributions
Public transportation subsidies
Bike leasing program
Monthly social events, Thursday happy hours, sports teams
An awesome office in Friedrichshain, Berlin
At KAYAK, we want everyone to have the space to grow, share ideas and do great work. That’s why we’re focused on hiring the best talent from all walks of life and experiences, supporting them well and making sure no one feels like they have to fit a mold to belong here.
Need any adjustments for the interview, application or on the job? No problem - just give us a heads-up. We’ve got you.
#LI-AS1
Skills Required
- Understanding of cybersecurity fundamentals, including networking, operating systems, and cloud environments
- Hands-on experience in at least one security domain, such as vulnerability management, incident response, application security, endpoint security, or identity and access management
- Experience working with security tooling, such as vulnerability scanners, endpoint detection and response platforms, or SIEM systems
- Familiarity with AI tools and their application in security contexts
- Clear written and verbal communication skills in English at a professional working level
- Collaborative problem-solving approach
- Ability to work autonomously while knowing when to seek input
- Familiarity with the NIST Cybersecurity Framework or similar security frameworks
- Experience with AWS or GCP cloud environments or container security
- Exposure to security automation or scripting, such as Python or workflow automation tools
- Experience working in a regulated environment, such as SOC 2 or PCI
KAYAK Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about KAYAK and has not been reviewed or approved by KAYAK.
-
Leave & Time Off Breadth — Time off is positioned as generous, with team‑wide downtime, paid volunteer time, and location‑specific vacation allotments in certain offices. Public descriptions also highlight generous PTO and paid sick days.
-
Healthcare Strength — Health coverage is described as comprehensive, including medical, dental, vision, and mental‑health support such as Headspace and access to counseling in some programs. Employer-verified listings also reference wellness resources and related benefits.
-
Fair & Transparent Compensation — Compensation philosophy emphasizes Equal Pay and a commitment to closing the global pay gap. Some job postings disclose salary ranges and note equity or bonus eligibility, reinforcing transparency for certain roles and locations.
KAYAK Insights
What We Do
KAYAK, part of Booking Holdings (NASDAQ: BKNG), is the world's leading travel search engine. With billions of queries across our platforms, we help people find their perfect flight, stay, rental car, cruise, vacation package. We also support business travelers with KAYAK for Business, our free corporate travel solution and are transforming the in-travel experience with our app and new hotel and accommodation software. Want to join a talented team that’s eager to solve the world’s travel problems (and have a bit of fun)? As an employee of KAYAK, you’ll be part of a global network including OpenTable and a portfolio of travel metasearch brands like Swoodoo, checkfelix, momondo, Cheapflights, Mundi and Hotels Combined. So join us, and help others experience the world through dining and travel.
Why Work With Us
What's most unique about KAYAK is the way we empower our team to lead their best lives - in and out of the workplace. Our Work from Almost Anywhere policy is built for and by our team. It gives us the flexibility to choose where and how we work best.







