Senior Manager, Security Operations

Expedia Expedia · Hospitality · Prague, Czech Republic

This role leads a global Security Operations function, focusing on continuous monitoring, detection, investigation, and response to security incidents. It involves defining and evolving strategies, building and mentoring teams, partnering with other engineering and product teams, and owning security operations technologies. A key aspect is the safe integration and operation of AI/ML-enabled solutions to enhance detection, triage, and response outcomes, applying AI/ML concepts to real-world security products.

What you'd actually do

  1. Lead a global Security Operations function responsible for continuous monitoring, detection, investigation, and response to security incidents across complex, large-scale environments.
  2. Define and evolve the strategy, processes, and runbooks for security operations, including incident response, threat detection, and vulnerability response, ensuring consistent, high-quality execution.
  3. Build, develop, and mentor a high-performing security operations team, establishing clear goals, operational metrics, and feedback loops to drive operational excellence.
  4. Partner with engineering, infrastructure, and product teams to improve security posture, reduce risk, and embed security controls and automation into core platforms and services.
  5. Own and refine security operations technologies, including SIEM, SOAR, endpoint and network security tools, ensuring they are tuned, scalable, and aligned to threat landscape and business needs.

Skills

Required

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience
  • Extensive experience in security operations, including hands-on incident response, threat detection, and security monitoring in large-scale, complex environments
  • Proven experience managing and leading security operations teams with clear ownership over multi-service or domain-level security operations capabilities
  • Strong technical expertise in security operations tooling and practices, such as SIEM, SOAR, endpoint protection, network security monitoring, and log analysis
  • Demonstrated ability to define, implement, and continuously improve operational processes, metrics, and automation to enhance security posture and incident response effectiveness

Nice to have

  • Experience operating a 24x7 global security operations function at scale, including service reliability, on-call practices, and continuous improvement of detection and response
  • Track record of leading cross-functional incident response for high-severity security events, including executive communication, root cause analysis, and long-term remediation
  • Depth in designing and optimizing security operations architectures, including log pipelines, detection engineering frameworks, and automation workflows across multiple platforms
  • Proven ability to drive data-driven decision making within security operations, leveraging metrics, trends, and threat intelligence to prioritize investments and improve controls
  • Practical experience integrating AI/ML capabilities into security operations (for example, for anomaly detection, alert triage, or automated response), and safely operating AI/ML-enabled solutions that improve security outcomes

What the JD emphasized

  • extensive experience in security operations
  • proven experience managing and leading security operations teams
  • strong technical expertise in security operations tooling and practices
  • demonstrated ability to define, implement, and continuously improve operational processes, metrics, and automation
  • practical experience integrating AI/ML capabilities into security operations

Other signals

  • Safely integrate and operate AI/MLenabled solutions that improve detection, triage, and response outcomes
  • applying AI/ML concepts to real world products
  • Practical experience integrating AI/ML capabilities into security operations (for example, for anomaly detection, alert triage, or automated response)