Security Operations Analyst II – Third Party Risk Management Operations Center

Expedia Expedia · Hospitality · Gurgaon, India

This role focuses on managing third-party risk and security compliance for Expedia Group. Responsibilities include conducting security assessments, reviewing vendor documentation (SOC 2, ISO 27001), analyzing risks against frameworks, managing tickets, coordinating with internal and external stakeholders, and documenting findings. The role requires experience in TPRM, GRC, or IT audit, familiarity with security frameworks, and understanding of core security concepts.

What you'd actually do

  1. Support end‑to‑end third party security assessments for new and existing vendors, including scoping, initiating assessments, collecting documentation, and tracking to closure.
  2. Review and analyze vendor security evidence (e.g., SOC 2 reports, ISO 27001 certificates, penetration test reports, security policies, questionnaires such as CAIQ/VSAQ/SIG) to identify control coverage, gaps, and issues.
  3. Perform structured security and risk evaluations against Expedia Group TPRM standards and industry frameworks (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS, privacy requirements) and document clear, defensible conclusions.
  4. Create and manage TPRM tickets and workflows (e.g., in Jira or a third party risk platform), ensuring assessments, findings, and remediation items are logged, updated, and closed within defined SLAs.
  5. Coordinate with internal stakeholders (Security, Privacy, Legal, Procurement, Engineering, Product, Business Owners) to obtain required information, clarify use cases, and agree on risk treatment decisions.

Skills

Required

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field; or equivalent practical experience in security operations or incident response.
  • 3–5 years of experience in third party risk management, security GRC, IT audit, vendor risk, or related technology risk/compliance roles
  • Experience supporting vendor due diligence or security assessments, including reviewing security documentation such as SOC 2, ISO 27001, penetration test reports, or security policies/standards.
  • Familiarity with common security and risk frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, and/or privacy requirements (e.g., GDPR, CCPA) and how they apply to third party environments.
  • Understanding of core information security concepts (e.g., access control, encryption, logging/monitoring, network security, vulnerability management, incident response) and ability to relate them to vendor controls.
  • Comfortable working in workflow and ticketing systems (e.g., Jira, ServiceNow) and ideally exposure to third party risk platforms (e.g., Archer, OneTrust, ServiceNow VRM, or similar).

Nice to have

  • Experience handling complex, multi-stage security incidents in large-scale, distributed, or cloud-based environments, including root cause analysis and post-incident reviews.
  • Information security, audit, or risk certifications are a plus (e.g., CISA, CRISC, Security+, ISO 27001 Associate, CTPRP/CTPRP‑like third party risk certifications).
  • Proven track record of improving SOC effectiveness through detection engineering, runbook optimization, automation, or tuning of security tools to enhance signal quality and response speed.
  • Experience using data-driven approaches to identify security trends, measure operati

What the JD emphasized

  • third party risk management
  • security GRC
  • IT audit
  • vendor risk
  • technology risk/compliance