Security Engineer Vulnerability Management

Expedia Group

Gurgaon

On-site

INR 1,500,000 - 2,500,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Expedia Group is seeking a Security Engineer II to advance vulnerability management and risk intelligence using automation and cloud-native solutions. You will reduce organizational risk by prioritizing vulnerabilities and triaging across cloud, application, infrastructure, and identity environments.

The role emphasizes scalable solutions, production security services, and collaboration with product security, cloud security, and engineering teams.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • 2+ years of experience in vulnerability management, security engineering, cloud security, security operations, risk assessment, or related security disciplines.
  • Demonstrated understanding of cloud platforms such as AWS, Azure, or GCP and modern application architectures.
  • Experience deploying, operating, troubleshooting, or supporting applications and services in cloud environments.
  • Understanding of systems architecture, APIs, data flows, service integrations, and distributed systems concepts.
  • Ability to evaluate security challenges and design scalable solutions that balance risk reduction, operational efficiency, and business impact.
  • Familiarity with scripting, automation, or programming languages (such as Python, PowerShell, Go, or Java) sufficient to automate workflows, integrate systems, and validate generated code.
  • Experience working with APIs, automation workflows, and security tooling integrations.
  • Strong analytical, troubleshooting, and problem‑solving skills.
  • Strong written and verbal communication skills with the ability to translate technical findings into actionable business outcomes.

Responsibilities

  • Own security risk decisions and exploitability prioritization across cloud, application, infrastructure, and identity environments.
  • Analyze vulnerability, threat intelligence, and exposure data to determine real-world exploitability and business impact.
  • Design and implement scalable security automation solutions that improve vulnerability identification, prioritization, triage, and remediation workflows.
  • Evaluate security challenges and determine the appropriate combination of automation, AI-assisted capabilities, and engineering controls to reduce risk.
  • Design, deploy, and operate cloud-native security services and automation workflows with reliability and security.
  • Partner with engineering teams to accelerate remediation through actionable insights and workflow improvements.
  • Review and validate code, recommendations, and remediation actions generated by automation platforms and AI tools.
  • Produce leadership-ready metrics to communicate risk posture and program impact.
  • Lead risk reduction campaigns with prioritization and outcome measurement.
  • Collaborate with cross-functional teams to improve security outcomes through scalable solutions and automation.
  • Identify false positives and data quality issues; drive governance improvements across tooling and data pipelines.
  • Contribute to AI-assisted security workflows and evidence-based documentation for audits.

Skills

Vulnerability management
Cloud security
Automation scripting
Python/PowerShell/Go/Java
Cloud platforms AWS/Azure/GCP
Security instrumentation & tooling
On-call incident response
Data-driven decision making
Risk assessment & prioritization
Communication of risk to stakeholders

Education

Bachelor's degree in Computer Science/Engineering or equivalent

Tools

Kubernetes
APIs & automation tooling integrations

Job description

Job Description

At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.

Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.

Introduction to the Team

We are seeking a Security Engineer II to help drive the evolution of our vulnerability management and risk intelligence capabilities through automation, cloud-native solutions, and data-driven decision making. This role focuses on reducing organizational risk by improving how vulnerabilities are identified, prioritized, triaged, and remediated across cloud, application, infrastructure, and identity environments.

The ideal candidate combines strong security fundamentals with systems thinking, cloud engineering knowledge, and an automation mindset. While coding and AI-assisted development tools are increasingly available, success in this role requires the ability to design scalable solutions, determine appropriate deployment architectures, validate automated outcomes, and operate security services in production environments.

In This Role, You Will
  • Own security risk decisions and exploitability prioritization across cloud, application, infrastructure, and identity environments, translating vulnerability and threat signals into clear, actionable outcomes.
  • Analyze vulnerability, threat intelligence, and exposure data to determine real-world exploitability, blast radius, recurrence patterns, and business impact.
  • Design and implement scalable security automation solutions that improve vulnerability identification, ownership attribution, prioritization, triage, and remediation workflows.
  • Evaluate security challenges and determine the appropriate combination of automation, AI-assisted capabilities, engineering controls, and human review required to achieve effective risk reduction.
  • Design, deploy, and operate cloud-native security services and automation workflows while ensuring reliability, scalability, observability, and security.
  • Partner with engineering teams to accelerate remediation through actionable insights, workflow improvements, and automation.
  • Review and validate code, recommendations, and remediation actions generated by automation platforms and AI-assisted development tools prior to production use.
  • Produce leadership-ready narratives and metrics such as MTTR, vulnerability aging, exception debt, recurrence rates, and remediation effectiveness to communicate risk posture and program impact.
  • Lead and support risk reduction campaigns, including prioritization decisions, execution tracking, and outcome measurement aligned to organizational security objectives.
  • Collaborate with Product Security, Cloud Security, Threat Intelligence, Architecture, and Engineering teams to improve security outcomes through scalable solutions and automation.
  • Identify false positives, detection gaps, data quality issues, and process inefficiencies; drive improvements across tooling, workflows, data pipelines, and governance processes.
  • Contribute to the development and operationalization of AI-assisted security workflows and intelligent automation solutions that reduce manual effort and improve decision quality.
  • Support compliance, audit, and regulatory activities by providing evidence, technical explanations, and process documentation.
  • Participate in daily and ad hoc risk assessments, providing guidance during active incidents, emerging threats, and time-sensitive security events.
  • Participate in an on‑call rotation to provide risk assessment, decision support, and technical guidance during security incidents and emerging threats.
Minimum Qualifications
  • Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • 2+ years of experience in vulnerability management, security engineering, cloud security, security operations, risk assessment, or related security disciplines.
  • Demonstrated understanding of cloud platforms such as AWS, Azure, or GCP and modern application architectures.
  • Experience deploying, operating, troubleshooting, or supporting applications and services in cloud environments.
  • Understanding of systems architecture, APIs, data flows, service integrations, and distributed systems concepts.
  • Ability to evaluate security challenges and design scalable solutions that balance risk reduction, operational efficiency, and business impact.
  • Familiarity with scripting, automation, or programming languages (such as Python, PowerShell, Go, or Java) sufficient to automate workflows, integrate systems, and validate generated code.
  • Experience working with APIs, automation workflows, and security tooling integrations.
  • Strong analytical, troubleshooting, and problem‑solving skills.
  • Strong written and verbal communication skills with the ability to translate technical findings into actionable business outcomes.
Preferred Qualifications
  • Experience designing, deploying, or supporting cloud-native solutions using containers, Kubernetes, serverless platforms, or Infrastructure as Code.
  • Experience building or operating security automation platforms, vulnerability management systems, workflow orchestration solutions, or security services.
  • Familiarity with AI-assisted development tools, intelligent automation platforms, and agentic AI concepts.
  • Experience evaluating and validating AI-generated recommendations, remediation actions, or code changes before production deployment.
  • Understanding of observability, monitoring, logging, resiliency, and operational excellence practices.
  • Experience integrating, correlating, and enriching security data from multiple sources to improve prioritization, signal quality, ownership attribution, or remediation effectiveness.
  • Demonstrated ability to identify opportunities where automation and AI can reduce operational effort and improve security outcomes.
  • Strong curiosity, learning agility, and passion for solving complex security problems at scale.
Accommodation requests

Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.

About Expedia Group

Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.

Important notice

Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com.

Equal Opportunity

Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, gender, sexual orientation, national origin, disability or age.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer , Vulnerability management
Security Engineer , Vulnerability management

Traveltechessentialist • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Security Engineer , Vulnerability management
Security Engineer , Vulnerability management

Expedia, Inc. • Gurugram District

On-site
INR 1,200,000 - 2,000,000
Security Engineer , Vulnerability management
Security Engineer , Vulnerability management

11550 Expedia Online Travel Sv • Gurgaon

On-site
INR 1,300,000 - 2,300,000
Senior Devops Engineer
Senior Devops Engineer

Expedia Group • Gurgaon

On-site
INR 4,000,000 - 7,000,000
Senior DevOps Engineer
Senior DevOps Engineer

Expedia, Inc. • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Senior DevOps Engineer
Senior DevOps Engineer

Traveltechessentialist • Gurugram District

On-site
INR 3,000,000 - 5,500,000
Software Develpment Engineer III
Software Develpment Engineer III

11550 Expedia Online Travel Sv • Gurgaon

On-site
INR 1,800,000 - 3,000,000
SENIOR SOFTWARE DEVELOPER
SENIOR SOFTWARE DEVELOPER

Expedia Group • Gurgaon

On-site
INR 4,000,000 - 7,000,000
Software Development Engineer III (Java)
Software Development Engineer III (Java)

Traveltechessentialist • Gurugram District

On-site
INR 2,500,000 - 4,200,000
Software Development Engineer III (Java)
Software Development Engineer III (Java)

Expedia, Inc. • Gurugram District

Hybrid
INR 3,000,000 - 4,000,000