About this role
At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.
Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.
Introduction to the Team
We are seeking a Security Engineer II to help drive the evolution of our vulnerability management and risk intelligence capabilities through automation, cloud-native solutions, and data-driven decision making. This role focuses on reducing organizational risk by improving how vulnerabilities are identified, prioritized, triaged, and remediated across cloud, application, infrastructure, and identity environments.
The ideal candidate combines strong security fundamentals with systems thinking, cloud engineering knowledge, and an automation mindset. While coding and AI-assisted development tools are increasingly available, success in this role requires the ability to design scalable solutions, determine appropriate deployment architectures, validate automated outcomes, and operate security services in production environments.
In This Role, You Will
- Own security risk decisions and exploitability prioritization across cloud, application, infrastructure, and identity environments, translating vulnerability and threat signals into clear, actionable outcomes.
- Analyze vulnerability, threat intelligence, and exposure data to determine real-world exploitability, blast radius, recurrence patterns, and business impact.
- Design and implement scalable security automation solutions that improve vulnerability identification, ownership attribution, prioritization, triage, and remediation workflows.
- Evaluate security challenges and determine the appropriate combination of automation, AI-assisted capabilities, engineering controls, and human review required to achieve effective risk reduction.
- Design, deploy, and operate cloud-native security services and automation workflows while ensuring reliability, scalability, observability, and security.
- Partner with engineering teams to accelerate remediation through actionable insights, workflow improvements, and automation.
- Review and validate code, recommendations, and remediation actions generated by automation platforms and AI-assisted development tools prior to production use.
- Produce leadership-ready narratives and metrics such as MTTR, vulnerability aging, exception debt, recurrence rates, and remediation effectiveness to communicate risk posture and program impact.
- Lead and support risk reduction campaigns, including prioritization decisions, execution tracking, and outcome measurement aligned to organizational security objectives.
- Collaborate with Product Security, Cloud Security, Threat Intelligence, Architecture, and Engineering teams to improve security outcomes through scalable solutions and automation.
- Identify false positives, detection gaps, data quality issues, and process inefficiencies; drive improvements across tooling, workflows, data pipelines, and governance processes.
- Contribute to the development and operationalization of AI-assisted security workflows and intelligent automation solutions that reduce manual effort and improve decision quality.
- Support compliance, audit, and regulatory activities by providing evidence, technical explanations, and process documentation.
- Participate in daily and ad hoc risk assessments, providing guidance during active incidents, emerging threats, and time-sensitive security events.
- Participate in an on-call rotation to provide risk assessment, decision support, and technical guidance during security incidents and emerging threats.
Minimum Qualifications
- Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
- 2+ years of experience in vulnerability management, security engineering, cloud security, security operations, risk assessment, or related security disciplines.
- Demonstrated understanding of cloud platforms such as AWS, Azure, or GCP and modern application architectures.
- Experience deploying, operating, troubleshooting, or supporting applications and services in cloud environments.
- Understanding of systems architecture, APIs, data flows, service integrations, and distributed systems concepts.
- Ability to evaluate security challenges and design scalable solutions that balance risk reduction, operational efficiency, and business impact.
- Familiarity with scripting, automation, or programming languages (such as Python, PowerShell, Go, or Java) sufficient to automate workflows, integrate systems, and validate generated code.
- Experience working with APIs, automation workflows, and security tooling integrations.
- Strong analytical, troubleshooting, and problem-solving skills.
- Strong written and verbal communication skills with the ability to translate technical findings into actionable business outcomes.
Preferred Qualifications
- Experience designing, deploying, or supporting cloud-native solutions using containers, Kubernetes, serverless platforms, or Infrastructure as Code.
- Experience building or operating security automation platforms, vulnerability management systems, workflow orchestration solutions, or security services.
- Familiarity with AI-assisted development tools, intelligent automation platforms, and agentic AI concepts.
- Experience evaluating and validating AI-generated recommendations, remediation actions, or code changes before production deployment.
- Understanding of observability, monitoring, logging, resiliency, and operational excellence practices.
- Experience integrating, correlating, and enriching security data from multiple sources to improve prioritization, signal quality, ownership attribution, or remediation effectiveness.
- Demonstrated ability to identify opportunities where automation and AI can reduce operational effort and improve security outcomes.
- Strong curiosity, learning agility, and passion for solving complex security problems at scale.
Accommodation requests
Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation .
About Expedia Group
Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.
Important notice
Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/ .
Equal Opportunity
Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, gender, sexual orientation, national origin, disability or age.