Security Engineer III , Vulnerability Management

expedia· 11550 Expedia Online Travel Sv
Apply Now ↗
📍 India - GurgaonFull time

About this role

At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.


Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.

Introduction to the Team:

Risk Intelligence and Orchestration is redefining vulnerability management at Expedia Group through AI-driven risk intelligence, security orchestration, and automation. The team identifies and prioritizes exploitable attack paths (toxic combinations), and security findings across applications, cloud, infrastructure, and containerized environments, ensuring risks are remediated according to business impact, compliance obligations, and defined SLAs. We also partner closely with engineering and compliance teams to support critical security programs, including PCI DSS and SOC 2.
Our mission is to make security the easiest path for engineers. By leveraging modern AI technologies, agentic workflows, intelligent ownership attribution, and automated remediation orchestration, we transform fragmented security signals into actionable insights and scalable workflows. We are building toward a future of autonomous, risk-based remediation - reducing noise, eliminating critical attack paths, and enabling engineering teams to focus on delivering trusted experiences for travellers.

In this role, you will:

  • Own security risk decisions and exploitability prioritization across cloud, application, and infrastructure environments, translating vulnerability and threat signals into clear, actionable outcomes.

  • Evaluate critical and high-risk findings, applying SLA governance, escalation judgment, and  exploitability, blast radius, recurrence patterns, and business impact.

  • Analyze vulnerability, threat intelligence, and exposure data to determine real-world

  • Produce leadership-ready narratives and metrics (MTTR, recurrence, exception debt, aging vulnerabilities) that communicate risk posture, trends, and program effectiveness beyond dashboards outcome tracking aligned to organizational objectives.

  • Lead and support risk campaigns, including go/no-go decisions, prioritization logic, and stakeholders to influence risk outcomes and drive alignment.

  • Partner closely with threat intelligence, cloud security, product security, and engineering improvements back into tooling, workflows, and policy.Identify false positives, systemic detection gaps, and process inefficiencies, feeding improvement of decision frameworks.

  • Contribute to reporting automation, Organizational Security metrics, and continuous active incidents or emerging threat scenarios.

  • Participate in daily and ad-hoc risk assessments, providing authoritative guidance during  and process clarity.Support GRC, SOC2, PCI, and internal audit activities by providing evidence, explanations,

  • Participate in an on-call rotation to provide expert risk assessment, decision support, and guidance during active incidents, emerging threats, or time-sensitive security events

Experience and Qualifications: 

Minimum Qualifications:

  • Bachelor’s degree in Computer Science or a related technical field; or Equivalent related professional experience.

  • 5+ years of relevant professional experience

  • Strong ability to interpret vulnerability, exploit, and threat data across cloud, application, identity, and infrastructure layers.

  • Experience producing executive-level security narratives, risk summaries, and metric-based insights.

  • Working knowledge of cloud platforms, modern application architectures, and enterprise security tooling.


Preferred Qualifications:

  • Experience operating in high-scale or global environments with formal SLA, exception, and escalation frameworks.

  • Demonstrated ability to balance security risk, operational capacity, and business impact in decision-making.

  • Strong background in building or improving security detection, incident response workflows, and metrics, using data to continuously refine coverage, reduce false positives, and improve time to detect and respond.

  • Familiarity with AI-driven systems, tools, or workflows and practical experience applying AI/ML concepts to enhance or secure real world products and platforms.

Accommodation requests

Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.


About Expedia Group

Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.


Important notice

Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.


Equal Opportunity

Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, gender, sexual orientation, national origin, disability or age.

Frequently Asked Questions

Is the salary disclosed for the Security Engineer III , Vulnerability Management position at expedia?
The salary for this Security Engineer III , Vulnerability Management role at expedia is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Security Engineer III , Vulnerability Management position at expedia located?
This Security Engineer III , Vulnerability Management role at expedia is based in India - Gurgaon. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Security Engineer III , Vulnerability Management role at expedia full-time or part-time?
This is listed as a Full time position. It is posted as a Security Engineer III , Vulnerability Management role in the 11550 Expedia Online Travel Sv department at expedia.
Which team or department does the Security Engineer III , Vulnerability Management at expedia belong to?
This Security Engineer III , Vulnerability Management position is part of the 11550 Expedia Online Travel Sv department at expedia. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Security Engineer III , Vulnerability Management position at expedia?
Click the "Apply Now" button on this page. You will be redirected to expedia's official application portal hosted on workday where you can submit your application directly.
When was the Security Engineer III , Vulnerability Management job at expedia posted?
This Security Engineer III , Vulnerability Management position at expedia was posted on Sep 28, 2026. Apply as soon as possible — early applications are often reviewed first.
Security Engineer III , Vulnerability Management
expedia
Apply for this role ↗

You'll be redirected to expedia's official application page on Workday.