Senior Product Security Architect

Expedia Expedia · Hospitality · Austin, TX

This role focuses on integrating AI, particularly Generative AI and agentic architectures, into product security practices and tooling within a large enterprise. The primary goal is to enhance security posture, automate verification processes, and provide architectural guidance for secure product development, especially concerning AI-enabled solutions.

What you'd actually do

  1. Provide thought leadership around enabling and applying AI across the Product Security org.
  2. Be a change agent influencing and scaling the adoption of AI-enabled security tooling and best practices across the product security organization.
  3. Drive continuous verification of product security controls and requirements through AI-enabled automation and integration with existing product security tooling.
  4. Serve as a trusted product security architecture advisor to product, engineering, and platform teams, helping them design secure, highly available, and privacy-aware products and services.
  5. Lead and facilitate threat modeling and security assessments for new and evolving products, services, and platforms, translating findings into clear, actionable recommendations.

Skills

Required

  • Bachelor’s degree in Computer Science or a related technical field; or equivalent related professional experience.
  • 10+ years of product security and development experience
  • Extensive experience performing application threat modeling
  • Extensive experience conducting architecture reviews to find and evaluate application and infrastructure security risks
  • Significant experience in the last several years applying Generative AI in software development and for end users, ideally in the context of a medium or large enterprise.
  • Deep understanding of modern product development practices and CI/CD and how AI can change and improve these practices to increase both quality and velocity.
  • Familiarity with ‘agentic’ architectures including SDKs, context engineering, MCPs, authorization.

Nice to have

  • Expertise in public cloud platforms (AWS is preferred), containerization and orchestration (Kubernetes, Docker), and related technologies.
  • Excellent communication and collaboration skills, with the ability to work effectively with both technical and non-technical stakeholders.
  • Track record of setting and evolving security architecture standards, patterns, and guardrails for complex, multi-tenant or multi-domain platforms, and driving their adoption across diverse engineering teams.
  • Experience operating product security at scale in cloud-native environments (such as large microservices architectures), including secure service-to-service communication, token-based auth, and secret and certificate management.
  • Deep experience conducting and scaling threat modeling, security design reviews, and architecture risk assessments, and using insights to shape platform capabilities, reusable controls, and security automation.
  • Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products, including leveraging AI/ML‑enabled code analysis, anomaly detection, or security automation; safely integrates and operates AI/ML‑enabled solutions that improve security posture, detection, and response.
  • Demonstrated experience taking products from concept to scaled adoption by partnering with pro

What the JD emphasized

  • Significant experience in the last several years applying Generative AI in software development and for end users, ideally in the context of a medium or large enterprise.
  • Familiarity with ‘agentic’ architectures including SDKs, context engineering, MCPs, authorization.
  • applying AI/ML concepts to real world products
  • safely integrates and operates AI/ML‑enabled solutions

Other signals

  • AI-enabled security tooling
  • AI-enabled automation
  • Generative AI in software development
  • agentic architectures