$249,000 – $348,500
Listed on Expedia Group’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
This is a hands-on security engineering leadership role focused on designing and operating enterprise-scale security platforms, infrastructure controls, and developer-friendly security tooling across cloud and AI systems. It suits experienced security architects and engineers who thrive building systems rather than managing people, and who can translate complex security requirements into practical controls that engineering teams actually adopt.
Our summary, not Expedia Group’s wording. The full posting is on their site.
Skills this role names
- AI Security
- Amazon Macie
- Amazon Virtual Private Cloud (VPC)
- Amazon Web Services (AWS)
- CI/CD
- GDPR
- Infrastructure as Code
- Istio
- Kubernetes
- OWASP
- PCI DSS
- Retrieval-Augmented Generation (RAG)
Log in to see which of these are already on your profile.
What they ask for
Required
- 15+ years hands-on cybersecurity experience building and operating systems at enterprise scale
- Deep AWS expertise with IAM, VPC, GuardDuty, Security Hub, Macie, Inspector, Control Tower, Secrets Manager, and KMS at scale
- SDLC security architecture delivery across large engineering organizations including CI/CD, developer tooling, and SAST/DAST/SCA deployment
- Hands-on service mesh implementation experience with mTLS, workload identity, and zero-trust network enforcement using Istio, Envoy, or Linkerd in production
- Demonstrated proficiency in AI security with controls for LLM applications, RAG systems, and agentic AI pipelines in production
- Operational experience running CSPM and DSPM programs at scale with finding triage and remediation velocity ownership
- Ability to influence engineering teams without formal authority and translate security into engineering-compatible designs
- Ability to contribute to security strategy and roadmap direction through technical depth and execution experience
- Exceptional technical communication skills for architectural documentation and executive summaries
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience
Nice to have
- Experience in large-scale, multi-cloud e-commerce or travel technology environment with global operations and high release frequency
- Hands-on experience building, deploying, or securing agentic AI systems and LLM applications in enterprise production including red-teaming
- Experience building security-as-a-platform services and self-service security tooling for large engineering organizations
- Prior people leadership or tech lead experience
- Relevant certifications: CISSP, CCSP, CSSLP, AWS Security Specialty, or GCP Security Engineer
- Applied experience with PCI-DSS, SOC 2, GDPR, and ISO 27001 as a practitioner building compliant systems