Security Engineering III

Expedia GroupSeattle, WA
$146,000 - $233,500

About The Position

Our Product Security organization is on a mission to transform how cybersecurity is built and delivered at Expedia Group. We are building the security infrastructure, platforms, and services that empower our engineering teams to ship products faster — with security embedded by default, not bolted on after the fact. We believe that great security accelerates product velocity, and we are looking for a deeply technical, hands-on individual contributor who will help us architect and realize that vision at scale. If you are passionate about reimagining what a modern product security organization looks like — and have the technical depth to make it real — this role is for you.

Requirements

  • Bachelor’s degree in Computer Science or a related technical field; or equivalent related professional experience.
  • 5+ years of relevant professional experience.
  • Experience in application security, product security, DevSecOps, or security engineering supporting modern CI/CD pipelines, cloud-native services, and secure software delivery practices across multiple services or domains.
  • Practical experience with software supply chain security, including areas such as SBOMs, signing or attestation, secure build pipelines, and using SAST, DAST, and SCA to protect against open-source and supply chain risks.
  • Practical experience operating and tuning vulnerability management and security tooling platforms (e.g., Qualys, SCA, Wiz, GHAS, Ox security, integrating them with CI/CD pipelines (e.g., GitHub Actions, Jenkins, Spinnaker), ticketing systems, and developer workflows, and using modern programming languages such as Java or Python to automate security outcomes.

Nice To Haves

  • Experience applying AI/ML and agentic AI techniques to vulnerability management, including autonomous triage workflows, intelligent prioritization, classification, enrichment, or AI-assisted security tooling that improves detection, prioritization, and remediation effectiveness.
  • Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real-world products, including a working understanding of AI/ML security implications such as the OWASP LLM Top 10 and basic penetration testing concepts.
  • Demonstrated success enabling developers on secure development practices and influencing secure engineering decisions within a team, product area, or domain through practical guidance, standards, and playbooks.
  • Strong communication skills with the ability to distill complex security topics for broad technical and non-security audiences, operate effectively in fast-paced environments, and navigate ambiguity with sound judgment.
  • Proven impact reducing vulnerability backlogs and improving remediation SLAs through automation, tool tuning, stronger signal-to-noise ratios, and data-driven operational improvement.

Responsibilities

  • Drive shift-left security practices by embedding security requirements and controls throughout the software development lifecycle, from design through deployment.
  • Integrate, maintain, and continuously improve security tooling and automation across CI/CD pipelines, including capabilities such as SAST, DAST, SCA, dependency scanning, and software supply chain protections.
  • Configure, tune, and triage security tools and vulnerability management platforms to reduce false positives, improve signal quality, and strengthen remediation workflows for developers.
  • Partner closely with product, engineering, platform, privacy, compliance, infrastructure, and security stakeholders to identify, assess, and remediate application security risks across the services and components you support.
  • Conduct threat modeling, security code reviews, and system design reviews, including low-level design, API design, and data modeling, for new and existing features and services.
  • Safely integrate and operate AI/ML-enabled solutions that improve security outcomes, applying familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products.

Benefits

  • medical, dental, and vision coverage
  • paid time off
  • an Employee Assistance Program
  • wellness and travel reimbursement
  • travel discounts
  • International Airlines Travel Agent Network (IATAN) membership
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service