Security Engineering III
Listed on 2026-09-02
-
IT/Tech
Cybersecurity, AI Engineer (Applied/Software)
Security Engineer III
Our Technology Team partners with teams across Expedia Group to create innovative products, services, and tools to deliver high-quality experiences for travelers, partners, and our employees. A singular technology platform powered by data and machine learning provides secure, differentiated, and personalized experiences that drive loyalty and traveler satisfaction. Our Product Security organization is on a mission to transform how cybersecurity is built and delivered at Expedia Group.
We are building the security infrastructure, platforms, and services that empower our engineering teams to ship products faster — with security embedded by default, not bolted on after the fact. We believe that great security accelerates product velocity, and we are looking for a deeply technical, hands-on individual contributor who will help us architect and realize that vision you are passionate about reimagining what a modern product security organization looks like — and have the technical depth to make it real — this role is for you.
In this role, you will:
Minimum Qualifications:
- Bachelor's degree in Computer Science or a related technical field; or equivalent related professional experience.
- 5+ years of relevant professional experience.
- Experience in application security, product security, Dev Sec Ops , or security engineering supporting modern CI/CD pipelines, cloud-native services, and secure software delivery practices across multiple services or domains.
- Practical experience with software supply chain security, including areas such as SBOMs, signing or attestation, secure build pipelines, and using SAST, DAST, and SCA to protect against open-source and supply chain risks.
- Practical experience operating and tuning vulnerability management and security tooling platforms (e.g., Qualys, SCA, Wiz, GHAS, Ox security, integrating them with CI/CD pipelines (e.g., Git Hub Actions, Jenkins, Spinnaker), ticketing systems, and developer workflows, and using modern programming languages such as Java or Python to automate security outcomes.
Preferred Qualifications:
- Experience applying AI/ML and agentic AI techniques to vulnerability management, including autonomous triage workflows, intelligent prioritization, classification, enrichment, or AI-assisted security tooling that improves detection, prioritization, and remediation effectiveness.
- Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real-world products, including a working understanding of AI/ML security implications such as the OWASP LLM Top 10 and basic penetration testing concepts.
- Demonstrated success enabling developers on secure development practices and influencing secure engineering decisions within a team, product area, or domain through practical guidance, standards, and playbooks.
- Strong communication skills with the ability to distill complex security topics for broad technical and non-security audiences, operate effectively in fast-paced environments, and navigate ambiguity with sound judgment.
- Proven impact reducing vulnerability backlogs and improving remediation SLAs through automation, tool tuning, stronger signal-to-noise ratios, and data-driven operational improvement.
The total cash range for this position in Seattle is $ to $. Employees in this role have the potential to increase their pay up to $, which is the top of the range, based on ongoing, demonstrated, and sustained performance in the role.
Starting pay for this role will vary based on multiple factors, including location, available budget, and an individual's knowledge, skills, and experience. Pay ranges may be modified in the future.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).