> Markdown version of [/jobs/ext/1424581-security-engineer-iii](https://www.wearedevelopers.com/jobs/ext/1424581-security-engineer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer III - **Company:** Expedia Inc. - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $146,000.0 - $233,500.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Software System Penetration Testing, Code Review, Software Design Documents, Github, Issue Tracking Systems, Python (Programming Language), Machine Learning, Open Source Technology, Open Web Application Security, Secure Coding, Software Engineering, Spinnaker, Software Vulnerability Management, Large Language Models, Software Security, Information Technology, Api Design, Devsecops, Serverless Computing, Qualys, Jenkins, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d5bf53dd34fcf437 ## About the Role * Bachelor's degree in Computer Science or a related technical field; or equivalent related professional experience. * 5+ years of relevant professional experience. * Experience in application security, product security, DevSecOps, or security engineering supporting modern CI/CD pipelines, cloud-native services, and secure software delivery practices across multiple services or domains. * Practical experience with software supply chain security, including areas such as SBOMs, signing or attestation, secure build pipelines, and using SAST, DAST, and SCA to protect against open-source and supply chain risks. * Practical experience operating and tuning vulnerability management and security tooling platforms (e.g., Qualys, SCA, Wiz, GHAS, Ox security, integrating them with CI/CD pipelines (e.g., GitHub Actions, Jenkins, Spinnaker), ticketing systems, and developer workflows, and using modern programming languages such as Java or Python to automate security outcomes., * Experience applying AI/ML and agentic AI techniques to vulnerability management, including autonomous triage workflows, intelligent prioritization, classification, enrichment, or AI-assisted security tooling that improves detection, prioritization, and remediation effectiveness. * Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real-world products, including a working understanding of AI/ML security implications such as the OWASP LLM Top 10 and basic penetration testing concepts. * Demonstrated success enabling developers on secure development practices and influencing secure engineering decisions within a team, product area, or domain through practical guidance, standards, and playbooks. * Strong communication skills with the ability to distill complex security topics for broad technical and non-security audiences, operate effectively in fast-paced environments, and navigate ambiguity with sound judgment. * Proven impact reducing vulnerability backlogs and improving remediation SLAs through automation, tool tuning, stronger signal-to-noise ratios, and data-driven operational improvement. The total cash range for this position in Seattle is $146,000.00 to $204,500.00. Employees in this role have the potential to increase their pay up to $233,500.00, which is the top of the range, based on ongoing, demonstrated, and sustained performance in the role. Starting pay for this role will vary based on multiple factors, including location, available budget, and an individual's knowledge, skills, and experience. Pay ranges may be modified in the future. ## Description * Drive shift-left security practices by embedding security requirements and controls throughout the software development lifecycle, from design through deployment. * Integrate, maintain, and continuously improve security tooling and automation across CI/CD pipelines, including capabilities such as SAST, DAST, SCA, dependency scanning, and software supply chain protections. * Configure, tune, and triage security tools and vulnerability management platforms to reduce false positives, improve signal quality, and strengthen remediation workflows for developers. * Partner closely with product, engineering, platform, privacy, compliance, infrastructure, and security stakeholders to identify, assess, and remediate application security risks across the services and components you support. * Conduct threat modeling, security code reviews, and system design reviews, including low-level design, API design, and data modeling, for new and existing features and services. * Safely integrate and operate AI/ML-enabled solutions that improve security outcomes, applying familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)