Product Security Architect III

Expedia Expedia · Hospitality · San Jose, CA +1

This role focuses on integrating and securing AI/ML solutions within Expedia's products. The Product Security Architect III will define security architecture patterns, lead threat modeling, and provide technical leadership on application security controls. A key responsibility is guiding teams in safely integrating and operating AI/ML-enabled solutions, ensuring security and privacy by design. The role emphasizes applying AI/ML concepts to real-world products and ensuring responsible use of AI in production systems.

What you'd actually do

  1. Define and evolve security architecture patterns, standards, and reference designs that enable secure-by-design product development across multiple platforms and services.
  2. Partner with product, engineering, and infrastructure teams to design secure system architectures, including API design, low-level design (LLD), and data models that protect customer and partner data.
  3. Lead threat modeling, security design reviews, and risk assessments for complex product initiatives, translating security requirements into actionable engineering guidance.
  4. Provide technical leadership on application security controls (authentication, authorization, encryption, key management, secrets handling) and drive their consistent adoption across domains.
  5. Guide teams in safely integrating and operating AI/ML‑enabled and AI-driven solutions, tools, or workflows that improve security and product outcomes, including applying AI/ML concepts to real-world products.

Skills

Required

  • Product or application security
  • Designing secure architectures for services, APIs, and data models
  • Complex, distributed systems
  • Security architecture for a significant product area, service group, or domain
  • Driving security requirements from design through implementation
  • Secure software development practices
  • Identity and access management
  • Cryptography usage
  • Cloud-native security controls
  • Familiarity with AI-driven systems, tools, or workflows
  • Applying AI/ML concepts to real world products

Nice to have

  • Defining and implementing security architecture patterns at scale for multi-service or domain-wide product ecosystems in a cloud-native environment
  • Leading security architecture for complex, highly available, and high-throughput systems
  • Data-intensive and API-centric products
  • Operational excellence and resiliency
  • Driving secure-by-design practices across engineering teams
  • Formal threat modeling
  • Security design reviews
  • Integration of security automation into CI/CD pipelines, telemetry, and monitoring
  • Designing and governing security controls for AI/ML‑enabled and AI-driven products or platforms
  • Model security
  • Data protection
  • Responsible use of AI in production systems
  • Safely integrating and operating AI/ML‑enabled solutions that improve outcomes
  • Applying data-driven approaches (such as security metrics, risk scores, and telemetry) to prioritize security investments
  • Influence architecture decisions
  • Continuously improve product security posture across multiple domains

What the JD emphasized

  • security and privacy are built into Expedia Group products by design
  • secure-by-design product architecture
  • safely integrating and operating AI/ML‑enabled and AI-driven solutions
  • applying AI/ML concepts to real-world products
  • security fundamentals such as secure software development practices, identity and access management, cryptography usage, and cloud-native security controls, including familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products
  • governing security controls for AI/ML‑enabled and AI-driven products or platforms, including model security, data protection, responsible use of AI in production systems, and safely integrating and operating AI/ML‑enabled solutions that improve outcomes

Other signals

  • AI/ML-enabled and AI-driven solutions
  • applying AI/ML concepts to real-world products
  • model security
  • data protection
  • responsible use of AI in production systems