Security Engineer III

Expedia Expedia · Hospitality · Prague, Czech Republic

Security Engineer III at Expedia Group responsible for advanced cybersecurity investigations across various technologies and brands, analyzing security signals, threat intelligence, and vulnerability data to detect, investigate, and remediate security issues. The role requires expertise in application security, cloud security, data security, network security, and perimeter security, with a focus on driving long-term risk reduction through automation and scalable solutions. Familiarity with AI-driven systems is a plus.

What you'd actually do

  1. Perform advanced level of security investigation on the following areas: application security, cloud security, data security, network security, and perimeter security
  2. Analyze security signals, threat intelligence, and vulnerability data to detect, investigate, and remediate security issues, driving long-term risk reduction through automation and scalable solutions.
  3. Provide in-depth knowledge of cyber-attack analysis and cyber kill-chain framework
  4. Gather data and drill down to root cause analysis, ability to recommend effective courses of containment, remediation, and communicate to the various levels in the organization
  5. Suggest improvements to current Security Detection practices and procedures

Skills

Required

  • security engineering
  • security tooling, services, or platforms
  • programming or scripting language
  • secure coding practices
  • APIs
  • data models
  • modern software architectures
  • Python
  • PowerShell

Nice to have

  • leading shifts in a security operations center or CISRT
  • leading security initiatives or projects end to end
  • application security
  • infrastructure security
  • identity and access management
  • detection engineering
  • vulnerability management
  • measurable risk reduction
  • Cybersecurity certifications (SANS or CISSP)
  • data-driven approaches to prioritize security work
  • tune detections
  • improve operational excellence
  • defining metrics and feedback loops

What the JD emphasized

  • advanced cybersecurity investigations
  • advanced networking
  • advanced system administration
  • intermediate scripting
  • Several years of hands-on experience in security engineering
  • Proven experience owning the security posture of one or more services or platforms
  • Strong technical proficiency in at least one programming or scripting language
  • Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products.