Security Engineer III

Expedia Inc.
Seattle, WA, United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$146,000.0 - $233,500.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Artificial Intelligence Software System Penetration Testing Code Review Software Design Documents Github Issue Tracking Systems Python (Programming Language) Machine Learning Open Source Technology Open Web Application Security Secure Coding
+14 more
Software Engineering Spinnaker Software Vulnerability Management Large Language Models Software Security Information Technology Api Design Devsecops Serverless Computing Qualys Jenkins Static Application Security Testing Programming Languages Dynamic Application Security Testing

Job description

  • Drive shift-left security practices by embedding security requirements and controls throughout the software development lifecycle, from design through deployment.
  • Integrate, maintain, and continuously improve security tooling and automation across CI/CD pipelines, including capabilities such as SAST, DAST, SCA, dependency scanning, and software supply chain protections.
  • Configure, tune, and triage security tools and vulnerability management platforms to reduce false positives, improve signal quality, and strengthen remediation workflows for developers.
  • Partner closely with product, engineering, platform, privacy, compliance, infrastructure, and security stakeholders to identify, assess, and remediate application security risks across the services and components you support.
  • Conduct threat modeling, security code reviews, and system design reviews, including low-level design, API design, and data modeling, for new and existing features and services.
  • Safely integrate and operate AI/ML-enabled solutions that improve security outcomes, applying familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products.

Requirements

  • Bachelor’s degree in Computer Science or a related technical field; or equivalent related professional experience.
  • 5+ years of relevant professional experience.
  • Experience in application security, product security, DevSecOps, or security engineering supporting modern CI/CD pipelines, cloud-native services, and secure software delivery practices across multiple services or domains.
  • Practical experience with software supply chain security, including areas such as SBOMs, signing or attestation, secure build pipelines, and using SAST, DAST, and SCA to protect against open-source and supply chain risks.
  • Practical experience operating and tuning vulnerability management and security tooling platforms (e.g., Qualys, SCA, Wiz, GHAS, Ox security, integrating them with CI/CD pipelines (e.g., GitHub Actions, Jenkins, Spinnaker), ticketing systems, and developer workflows, and using modern programming languages such as Java or Python to automate security outcomes., * Experience applying AI/ML and agentic AI techniques to vulnerability management, including autonomous triage workflows, intelligent prioritization, classification, enrichment, or AI-assisted security tooling that improves detection, prioritization, and remediation effectiveness.
  • Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real-world products, including a working understanding of AI/ML security implications such as the OWASP LLM Top 10 and basic penetration testing concepts.
  • Demonstrated success enabling developers on secure development practices and influencing secure engineering decisions within a team, product area, or domain through practical guidance, standards, and playbooks.
  • Strong communication skills with the ability to distill complex security topics for broad technical and non-security audiences, operate effectively in fast-paced environments, and navigate ambiguity with sound judgment.
  • Proven impact reducing vulnerability backlogs and improving remediation SLAs through automation, tool tuning, stronger signal-to-noise ratios, and data-driven operational improvement.

The total cash range for this position in Seattle is $146,000.00 to $204,500.00. Employees in this role have the potential to increase their pay up to $233,500.00, which is the top of the range, based on ongoing, demonstrated, and sustained performance in the role.

Starting pay for this role will vary based on multiple factors, including location, available budget, and an individual’s knowledge, skills, and experience. Pay ranges may be modified in the future.

Benefits & conditions

3.83.8 out of 5 stars Seattle, WA $146,000 - $233,500 a year - Full-time, Pulled from the full job description

  • Health insurance
  • Paid time off
  • Employee discount
  • Vision insurance
  • Dental insurance
  • Employee assistance program, Expedia Group offers benefits and perks designed to support employees and their families, including medical, dental, and vision coverage, paid time off, an Employee Assistance Program, wellness and travel reimbursement, travel discounts, and International Airlines Travel Agent Network (IATAN) membership. Learn more about life at Expedia Group at https://careers.expediagroup.com/life .

About the company

At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.

Here, you’ll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.

Security Engineer III

Our Technology Team partners with teams across Expedia Group to create innovative products, services, and tools to deliver high-quality experiences for travelers, partners, and our employees. A singular technology platform powered by data and machine learning provides secure, differentiated, and personalized experiences that drive loyalty and traveler satisfaction.

Our Product Security organization is on a mission to transform how cybersecurity is built and delivered at Expedia Group. We are building the security infrastructure, platforms, and services that empower our engineering teams to ship products faster - with security embedded by default, not bolted on after the fact. We believe that great security accelerates product velocity, and we are looking for a deeply technical, hands-on individual contributor who will help us architect and realize that vision at scale. If you are passionate about reimagining what a modern product security organization looks like - and have the technical depth to make it real - this role is for you., Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · WWC 2023

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

57 sec

Extracting API schemas automatically during continuous integration builds

Axel Barbier · WWC 2023

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all