Principal Analyst - Security Operations

Expedia Inc.
Seattle, WA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$231,000.0 - $369,500.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cloud Computing Security Cyber Security Decision Support Systems Distributed Systems Data Intelligence Intrusion Detection and Prevention Machine Learning Security Information and Event Management Information Technology Security Orchestration, Automation & Response

Job description

Our Cyber Security organization works across Expedia Group to protect the travelers, partners, employees, and platforms that power global travel. We build and operate resilient, intelligence-driven security capabilities spanning security operations, threat detection and response, security engineering, identity, data, and cloud security-reducing cyber risk while enabling trusted, secure innovation at scale.

The Security Operations team partners with technology, product, and platform teams to detect, investigate, contain, and recover from threats while continuously improving the automation, telemetry, and operating models that keep Expedia Group secure. As part of this team, a Principal Security Operations leader will help set the technical direction for modern, AI-enabled defense capabilities, turn complex signals into decisive action, and strengthen a proactive, measurable security posture across the enterprise.

In this role you will:

  • Lead complex security operations analyses to detect, investigate, and respond to sophisticated threats across Expedia Group’s environments, driving clear, measurable risk reduction.
  • Design, optimize, and standardize security monitoring and incident response workflows, including runbooks, playbooks, and escalation paths, to improve speed, quality, and consistency of response.
  • Partner with engineering, incident management, and product teams to translate security findings into actionable technical requirements and remediation plans, influencing roadmaps across multiple domains.
  • Develop and maintain advanced analytics, detections, dashboards, and reporting that provide deep visibility into security posture, threat trends, and operational performance for senior stakeholders.
  • Provide technical leadership and mentorship across global security operations, shaping best practices for log management, alert tuning, investigation techniques, and use of SOAR/SIEM and related tooling.
  • Safely integrate and operate AI/ML-enabled solutions that improve detection, triage, and response outcomes, building familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world security operations scenarios.

Requirements

  • Bachelor’s degree in computer science, Information Security, Engineering, or a related technical field, or equivalent practical experience in security operations.
  • Extensive experience in security operations, including hands-on incident detection, investigation, and response across large-scale or complex environments.
  • Proven ownership of security operations across multiple services or domains, including responsibility for end-to-end monitoring, alerting, and incident handling processes.
  • Strong technical expertise in security tooling and infrastructure such as SIEM, EDR, log management, and security analytics platforms, and in interpreting complex telemetry for threat detection.
  • Familiarity with AI-driven systems, tools, or workflows in a security context, and the ability to work effectively with data, detections, and automation to improve operational outcomes., * Advanced experience operating global, large-scale security operations, including designing and refining detection strategies and incident response capabilities for highly distributed systems.
  • Demonstrated leadership in shaping the architecture and integration of security operations tools (for example SIEM, SOAR, EDR, ticketing, and automation platforms) across multiple technical domains.
  • Proven track record of driving operational excellence through continuous improvement of metrics, processes, automation, and data-driven decision making in security operations.
  • Experience designing, implementing, and tuning AI/ML-supported detections, triage workflows, or automated response actions, ensuring safe and effective use of AI/ML-enabled solutions in production security environments.Ability to influence senior technical and business stakeholders using clear, data-backed insights from security operations, and to mentor others in advanced investigation, threat hunting, and incident management practices.

Benefits & conditions

Pulled from the full job description Health insurance Paid time off Employee discount Vision insurance Dental insurance Employee assistance program, The total cash range for this position in Seattle is $231,000.00 to $323,500.00. Employees in this role have the potential to increase their pay up to $369,500.00, which is the top of the range, based on ongoing, demonstrated, and sustained performance in the role.

Starting pay for this role will vary based on multiple factors, including location, available budget, and an individual’s knowledge, skills, and experience. Pay ranges may be modified in the future.

Benefits and perks

Expedia Group offers benefits and perks designed to support employees and their families, including medical, dental, and vision coverage, paid time off, an Employee Assistance Program, wellness and travel reimbursement, travel discounts, and International Airlines Travel Agent Network (IATAN) membership. Learn more about life at Expedia Group at https://careers.expediagroup.com/life .

About the company

At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.

Here, you’ll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:36 min

Applying supervised machine learning for practical rule extraction

Katja Träumner

1:22 min

Four essential pillars for enterprise application governance scaling

Neena Thomas Neena Thomas · World Congress 2026 Europe

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · World Congress 2024

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all