$146,000 – $204,500
Listed on Expedia Group’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
This role focuses on embedding security directly into Expedia's development processes rather than adding it afterward, managing security tools across CI/CD pipelines, and helping engineers ship faster without compromising protection. It suits experienced security engineers who want to bridge development and security teams and have hands-on expertise with modern tooling and cloud practices.
Our summary, not Expedia Group’s wording. The full posting is on their site.
Skills this role names
Log in to see which of these are already on your profile.
What they ask for
Required
- Bachelor's degree in Computer Science or related technical field, or equivalent professional experience
- 5+ years of professional experience in security
- Application security, product security, DevSecOps, or security engineering experience with modern CI/CD pipelines and cloud-native services
- Practical experience with software supply chain security including SBOMs, signing, attestation, and secure build pipelines
- Experience operating and tuning vulnerability management platforms and integrating them with CI/CD pipelines and developer workflows
- Proficiency in modern programming languages such as Java or Python for security automation
Nice to have
- Experience applying AI/ML and agentic AI to vulnerability management and triage workflows
- Familiarity with AI-driven security tools and understanding of AI/ML security implications like OWASP LLM Top 10
- Track record enabling developers on secure practices and influencing secure engineering decisions
- Strong communication skills for complex security topics across technical and non-technical audiences
- Proven success reducing vulnerability backlogs and improving remediation SLAs through automation and data-driven improvements