Security Analyst III

Expedia Expedia · Hospitality · Seattle, WA

Expedia Group is seeking a Security Analyst III to perform advanced cybersecurity investigations across various technologies and brands. The role involves analyzing security signals, threat intelligence, and vulnerability data to detect, investigate, and remediate security issues, with a focus on automation and scalable solutions. The analyst will also provide in-depth knowledge of cyber-attack analysis and contribute to improving security detection practices. Familiarity with AI-driven systems is a plus.

What you'd actually do

  1. Perform advanced level of security investigation on the following areas: application security, cloud security, data security, network security, and perimeter security
  2. Analyze security signals, threat intelligence, and vulnerability data to detect, investigate, and remediate security issues, driving long-term risk reduction through automation and scalable solutions.
  3. Provide in-depth knowledge of cyber-attack analysis and cyber kill-chain framework
  4. Gather data and drill down to root cause analysis, ability to recommend effective courses of containment, remediation, and communicate to the various levels in the organization
  5. Suggest improvements to current Security Detection practices and procedures

Skills

Required

  • Bachelor’s degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience in security engineering.
  • Several years of hands-on experience in security engineering, including building or operating security tooling, services, or platforms within complex, distributed systems.
  • Proven experience owning the security posture of one or more services or platforms, including responsibility for implementing controls, monitoring, and remediation within that scope.
  • Strong technical proficiency in at least one programming or scripting language, with experience applying secure coding practices, working with APIs, and understanding data models in modern software architectures.
  • Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products.

Nice to have

  • Experience leading shifts in a security operations center or CISRT
  • Demonstrated success leading security initiatives or projects end to end, such as rolling out new security controls, detection capabilities, or automation across multiple teams or services.
  • Depth in one or more security domains such as application security, infrastructure security, identity and access management, detection engineering, or vulnerability management, with a track record of measurable risk reduction.
  • Cybersecurity certifications such as SANS or CISSP
  • Experience applying data-driven approaches to prioritize security work, tune detections, and improve operational excellence, including defining metrics and feedback loops for continuous improvement.

What the JD emphasized

  • advanced cybersecurity investigations
  • advanced cybersecurity
  • advanced networking
  • advanced system administration
  • intermediate scripting
  • security engineering
  • building or operating security tooling, services, or platforms
  • owning the security posture
  • implementing controls, monitoring, and remediation
  • applying secure coding practices
  • working with APIs
  • understanding data models
  • AI-driven systems, tools, or workflows
  • applying AI/ML concepts
  • security operations center or CISRT
  • leading security initiatives or projects
  • detection engineering