HBX Group operates a global B2B travel technology marketplace connecting 60,000 high-value clients across 140 source markets. The platform processes 7 billion searches daily against a 450TB data lake, spanning 300,000 hotels in 171 countries. That kind of volume - transaction-heavy, latency-sensitive, and geographically distributed - creates an attack surface that's both wide and deep: payment flows across multiple verticals, PII at scale, and cloud-native infrastructure running multi-brand ecosystems including Hotelbeds, Bedsonline, and Roiback.
The security challenge here isn't theoretical. Travel platforms are high-value targets for credential stuffing, payment fraud, and supply-chain compromise. With operations across 55 countries and 31 offices, compliance complexity alone - GDPR, PCI-DSS, regional data residency - demands serious engineering. The team of roughly 3,500 works across cloud-native technology platforms and data-driven insights, meaning security spans infrastructure hardening, API security across marketplace integrations, data protection at the lake level, and fraud detection in real-time transaction flows.
Based in Palma de Mallorca, Spain, HBX Group runs verticals covering accommodation, transport, activities, and payments - each with distinct threat models. Securing a multi-brand ecosystem at this scale means dealing with third-party integrations, partner access controls, and the kind of distributed-system complexity where misconfigurations compound fast. The focus is on building resilient systems that can handle the operational reality of a marketplace moving billions of data points per day across a fragmented global travel supply chain.





