> Markdown version of [/jobs/ext/134279-senior-product-security-architect](https://www.wearedevelopers.com/jobs/ext/134279-senior-product-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Product Security Architect - **Company:** Expedia Inc. - **Location:** Austin, TX, United States - **Experience:** Expert - **Salary:** $184,500.0 - $295,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing, Static Program Analysis, Cyber Security, Continuous Integration, Machine Learning, Software Engineering, SSL Certificate Management, Software Security, Generative AI, Containerization, Kubernetes, Information Technology, Data Analytics, Docker, Security Orchestration, Automation & Response, Microservices - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d064fb44fcccc440 ## About the Role * Bachelor's degree in Computer Science or a related technical field; or equivalent related professional experience. * 10+ years of product security and development experience * Extensive experience performing application threat modeling * Extensive experience conducting architecture reviews to find and evaluate application and infrastructure security risks * Significant experience in the last several years applying Generative AI in software development and for end users, ideally in the context of a medium or large enterprise. * Deep understanding of modern product development practices and CI/CD and how AI can change and improve these practices to increase both quality and velocity. * Familiarity with 'agentic' architectures including SDKs, context engineering, MCPs, authorization., * Expertise in public cloud platforms (AWS is preferred), containerization and orchestration (Kubernetes, Docker), and related technologies. * Excellent communication and collaboration skills, with the ability to work effectively with both technical and non-technical stakeholders. * Track record of setting and evolving security architecture standards, patterns, and guardrails for complex, multi-tenant or multi-domain platforms, and driving their adoption across diverse engineering teams. * Experience operating product security at scale in cloud-native environments (such as large microservices architectures), including secure service-to-service communication, token-based auth, and secret and certificate management. * Deep experience conducting and scaling threat modeling, security design reviews, and architecture risk assessments, and using insights to shape platform capabilities, reusable controls, and security automation. * Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products, including leveraging AI/ML-enabled code analysis, anomaly detection, or security automation; safely integrates and operates AI/ML-enabled solutions that improve security posture, detection, and response. * Demonstrated experience taking products from concept to scaled adoption by partnering with product and engineering leadership to embed security requirements into product vision, architecture, and roadmaps, and to measure and report on security outcomes. ## Description The Product Security Architecture team partners with product, engineering, and platform teams to ensure security and privacy are built into Expedia Group products by design, from ideation through operations. We enable our business partners to build resilient, future-ready solutions that advance Expedia Group's security posture and operational velocity. We focus on secure-by-design product architecture, security assessments, threat modeling, and continuous verification of security requirements across our business products and platforms. You will join a small, senior team of hands-on product security architects who work across domains and technologies, helping teams make pragmatic security decisions that enable innovation at scale. In this role, you will: * Serve as a trusted product security architecture advisor to product, engineering, and platform teams, helping them design secure, highly available, and privacy-aware products and services. * Lead and facilitate threat modeling and security assessments for new and evolving products, services, and platforms, translating findings into clear, actionable recommendations. * Partner closely with product and engineering leaders to embed security requirements into product roadmaps, design reviews, and delivery processes without slowing down innovation. * Provide thought leadership around enabling and applying AI across the Product Security org. * Be a change agent influencing and scaling the adoption of AI-enabled security tooling and best practices across the product security organization. * Drive continuous verification of product security controls and requirements through AI-enabled automation and integration with existing product security tooling. * Communicate complex product security and architecture trade-offs in a clear, outcome-focused way to both technical and non-technical stakeholders, from senior ICs to senior leadership. * Mentor and coach product managers, engineers, and architects to raise the bar on product security literacy and design thinking across the organization. * Contribute to the broader Expedia Group security strategy by identifying emerging product security risks and technology trends and proposing pragmatic, long-term architecture approaches. * Contribute to creating a culture of continuous learning, data-driven decisions, and improvements. * Collaborate across IT and Information Security teams to ensure end to end coverage across the product lifecycle - from concept and design through build, launch and operations. ## Related Videos - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)