Expedia Group · 채용 중 28건
Security Engineer III , Vulnerability Management
Security Engineer III , Vulnerability Management
보안 엔지니어정규직시니어 · 5년 이상
Expedia Group은 취약점 관리를 주도할 Security Engineer III를 채용합니다. 클라우드 및 애플리케이션 환경에서 위험 평가와 우선순위 결정을 담당하며, 5년 이상의 관련 경력이 필수입니다. 데이터 분석을 통해 보안 지표를 도출하고 리더십 보고서를 작성하는 능력이 중요합니다. AI 기반 보안 워크플로우 개선에 기여할 전문가를 찾습니다.
Hello!
You’re now leaving the Expedia Group careers site and will be directed to our supplier partner’s website to explore and apply for contract job opportunities with Expedia Group. The website is operated by Expedia Group’s employment partner.
*currently only offered in USA & UK
Full-Time Regular
07/17/2026
ID # R-107533
Share this position
Already Applied? View Your Account
At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.
Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.
Risk Intelligence and Orchestration is redefining vulnerability management at Expedia Group through AI-driven risk intelligence, security orchestration, and automation. The team identifies and prioritizes exploitable attack paths (toxic combinations), and security findings across applications, cloud, infrastructure, and containerized environments, ensuring risks are remediated according to business impact, compliance obligations, and defined SLAs. We also partner closely with engineering and compliance teams to support critical security programs, including PCI DSS and SOC 2. Our mission is to make security the easiest path for engineers. By leveraging modern AI technologies, agentic workflows, intelligent ownership attribution, and automated remediation orchestration, we transform fragmented security signals into actionable insights and scalable workflows. We are building toward a future of autonomous, risk-based remediation - reducing noise, eliminating critical attack paths, and enabling engineering teams to focus on delivering trusted experiences for travellers.
Own security risk decisions and exploitability prioritization across cloud, application, and infrastructure environments, translating vulnerability and threat signals into clear, actionable outcomes.
Evaluate critical and high-risk findings, applying SLA governance, escalation judgment, and exploitability, blast radius, recurrence patterns, and business impact.
Analyze vulnerability, threat intelligence, and exposure data to determine real-world
Produce leadership-ready narratives and metrics (MTTR, recurrence, exception debt, aging vulnerabilities) that communicate risk posture, trends, and program effectiveness beyond dashboards outcome tracking aligned to organizational objectives.
Lead and support risk campaigns, including go/no-go decisions, prioritization logic, and stakeholders to influence risk outcomes and drive alignment.
Partner closely with threat intelligence, cloud security, product security, and engineering improvements back into tooling, workflows, and policy.Identify false positives, systemic detection gaps, and process inefficiencies, feeding improvement of decision frameworks.
Contribute to reporting automation, Organizational Security metrics, and continuous active incidents or emerging threat scenarios.
Participate in daily and ad-hoc risk assessments, providing authoritative guidance during and process clarity.Support GRC, SOC2, PCI, and internal audit activities by providing evidence, explanations,
Participate in an on-call rotation to provide expert risk assessment, decision support, and guidance during active incidents, emerging threats, or time-sensitive security events
Bachelor’s degree in Computer Science or a related technical field; or Equivalent related professional experience.
5+ years of relevant professional experience
Strong ability to interpret vulnerability, exploit, and threat data across cloud, application, identity, and infrastructure layers.
Experience producing executive-level security narratives, risk summaries, and metric-based insights.
Working knowledge of cloud platforms, modern application architectures, and enterprise security tooling.
Experience operating in high-scale or global environments with formal SLA, exception, and escalation frameworks.
Demonstrated ability to balance security risk, operational capacity, and business impact in decision-making.
Strong background in building or improving security detection, incident response workflows, and metrics, using data to continuously refine coverage, reduce false positives, and improve time to detect and respond.
Familiarity with AI-driven systems, tools, or workflows and practical experience applying AI/ML concepts to enhance or secure real world products and platforms.
Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.
Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.
Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.
Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, gender, sexual orientation, national origin, disability or age.
At Expedia Group, we're committed to providing an inclusive and accessible recruiting experience for candidates with disabilities. If you require an accommodation or adjustment for any part of the application or hiring process, please let us know by completing our Accommodation Request form.
Request a disability accommodation
at Expedia Group!
Full-Time Regular
07/17/2026
ID # R-107533
Share this position