Expedia Group Logo

Expedia Group

Application Security Engineer III

Reposted An Hour Ago
Be an Early Applicant
Hybrid
Seattle, WA
146K-234K Annually
Senior level
Hybrid
Seattle, WA
146K-234K Annually
Senior level
Embed security across the SDLC by integrating and automating SAST/DAST/SCA and supply-chain protections, operating and tuning vulnerability management tooling, conducting threat modeling and security/code reviews, partnering with engineering and product teams to remediate risks, and safely applying AI/ML to improve security automation and triage.
The summary above was generated by AI

At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.


Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.

Application Security Engineer III
Our Technology Team partners with teams across Expedia Group to create innovative products, services, and tools to deliver high-quality experiences for travelers, partners, and our employees. A singular technology platform powered by data and machine learning provides secure, differentiated, and personalized experiences that drive loyalty and traveler satisfaction.
Our Product Security organization is on a mission to transform how cybersecurity is built and delivered at Expedia Group. We are building the security infrastructure, platforms, and services that empower our engineering teams to ship products faster — with security embedded by default, not bolted on after the fact. We believe that great security accelerates product velocity, and we are looking for a deeply technical, hands-on individual contributor who will help us architect and realize that vision at scale. If you are passionate about reimagining what a modern product security organization looks like — and have the technical depth to make it real — this role is for you.
In this role, you will:

  • Drive shift-left security practices by embedding security requirements and controls throughout the software development lifecycle, from design through deployment.

  • Integrate, maintain, and continuously improve security tooling and automation across CI/CD pipelines, including capabilities such as SAST, DAST, SCA, dependency scanning, and software supply chain protections.

  • Configure, tune, and triage security tools and vulnerability management platforms to reduce false positives, improve signal quality, and strengthen remediation workflows for developers.

  • Partner closely with product, engineering, platform, privacy, compliance, infrastructure, and security stakeholders to identify, assess, and remediate application security risks across the services and components you support.

  • Conduct threat modeling, security code reviews, and system design reviews, including low-level design, API design, and data modeling, for new and existing features and services.

  • Safely integrate and operate AI/ML-enabled solutions that improve security outcomes, applying familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products.

Minimum Qualifications:

  • Bachelor’s degree in Computer Science or a related technical field; or equivalent related professional experience.

  • 5+ years of relevant professional experience.

  • Experience in application security, product security, DevSecOps, or security engineering supporting modern CI/CD pipelines, cloud-native services, and secure software delivery practices across multiple services or domains.

  • Practical experience with software supply chain security, including areas such as SBOMs, signing or attestation, secure build pipelines, and using SAST, DAST, and SCA to protect against open-source and supply chain risks.

  • Practical experience operating and tuning vulnerability management and security tooling platforms (e.g., Qualys, SCA, Wiz, GHAS, Ox security, integrating them with CI/CD pipelines (e.g., GitHub Actions, Jenkins, Spinnaker), ticketing systems, and developer workflows, and using modern programming languages such as Java or Python to automate security outcomes.

Preferred Qualifications:

  • Experience applying AI/ML and agentic AI techniques to vulnerability management, including autonomous triage workflows, intelligent prioritization, classification, enrichment, or AI-assisted security tooling that improves detection, prioritization, and remediation effectiveness.

  • Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real-world products, including a working understanding of AI/ML security implications such as the OWASP LLM Top 10 and basic penetration testing concepts.

  • Demonstrated success enabling developers on secure development practices and influencing secure engineering decisions within a team, product area, or domain through practical guidance, standards, and playbooks.

  • Strong communication skills with the ability to distill complex security topics for broad technical and non-security audiences, operate effectively in fast-paced environments, and navigate ambiguity with sound judgment.

  • Proven impact reducing vulnerability backlogs and improving remediation SLAs through automation, tool tuning, stronger signal-to-noise ratios, and data-driven operational improvement.

The total cash range for this position in Seattle is $146,000.00 to $204,500.00. Employees in this role have the potential to increase their pay up to $233,500.00, which is the top of the range, based on ongoing, demonstrated, and sustained performance in the role.

Starting pay for this role will vary based on multiple factors, including location, available budget, and an individual’s knowledge, skills, and experience. Pay ranges may be modified in the future.


Benefits and perks

Expedia Group offers benefits and perks designed to support employees and their families, including medical, dental, and vision coverage, paid time off, an Employee Assistance Program, wellness and travel reimbursement, travel discounts, and International Airlines Travel Agent Network (IATAN) membership. Learn more about life at Expedia Group at https://careers.expediagroup.com/life.


Accommodation requests

Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.


About Expedia Group

Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.


Important notice

Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.


Equal Opportunity

Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other characteristic protected by law. This employer participates in E-Verify. The employer will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's I-9 to confirm work authorization.

Expedia Group Austin, Texas, USA Office

11920 Alterra Pkwy, Austin, Texas, United States, 78758 1115

Similar Jobs at Expedia Group

An Hour Ago
Hybrid
173K-277K Annually
Senior level
173K-277K Annually
Senior level
AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Own the vision and roadmap for Expedia Group’s sponsored listings auction marketplace. Lead auction mechanics, bidding, pricing, relevance, and optimization initiatives to improve traveler experience, partner ROI, marketplace efficiency, and revenue. Partner with engineering, machine learning, data science, and business teams to develop technical solutions, define metrics, analyze performance, run experiments, and communicate strategy to leadership. Apply AI and GenAI tools to accelerate product development and decision-making.
Top Skills: Agent-Based SystemsGenerative AiLarge Language Models (Llms)Machine LearningProgrammatic Advertising
An Hour Ago
Hybrid
146K-234K Annually
Senior level
146K-234K Annually
Senior level
AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Design, build, and operate high-throughput backend services and scalable APIs for insurance and fintech products. Lead cross-team initiatives across pricing, checkout, booking, and servicing systems. Launch zero-to-one products, iterate post-launch, write maintainable performant code, troubleshoot distributed systems, leverage AI-assisted development tools, and participate in quarterly on-call rotation.
Top Skills: Ai-Assisted Development Tools (CopilotAPIsBackend ServicesClaude)Cloud-Based EnvironmentsDistributed SystemsJavaKotlinPricing Engines
Yesterday
Hybrid
146K-252K Annually
Mid level
146K-252K Annually
Mid level
AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Designs and operates scalable batch and real-time machine learning pipelines for advertising systems. Responsibilities include deploying models, building large-scale data pipelines, enabling low-latency inference, developing APIs and orchestration workflows, monitoring production systems, and optimizing performance. The role collaborates with engineering, data science, product, analytics, and business teams while contributing to technical direction and mentoring others.
Top Skills: AWSDatabricksMlopsPythonPyTorchSparkSQLTensorFlow

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account