{"id":1580370,"url":"https://alion.io/job/expedia-group-security-engineer-vulnerability-management","title":"Security Engineer , Vulnerability management","company":{"id":1763687,"name":"Expedia Group","domain":"expediagroup.com","url":"https://alion.io/company/expediagroup-com","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":100,"open_postings":5,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":15,"computed_at":"2026-10-04T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"junior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Gurgaon, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":12500,"max_usd":35000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":309},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"GCP","optional":false},{"name":"Java","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"AI Agents","optional":true},{"name":"Kubernetes","optional":true}],"status":"live","first_seen_at":"2026-10-01T12:48:33Z","employer_posted_date":"2026-10-01","last_verified_at":"2026-10-05T00:14:31Z","board_verified":true,"closed_at":null,"days_open":3,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":3},"description":"At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.\nHere, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.\nIntroduction to the Team\n\nWe are seeking a Security Engineer II to help drive the evolution of our vulnerability management and risk intelligence capabilities through automation, cloud-native solutions, and data-driven decision making. This role focuses on reducing organizational risk by improving how vulnerabilities are identified, prioritized, triaged, and remediated across cloud, application, infrastructure, and identity environments.\nThe ideal candidate combines strong security fundamentals with systems thinking, cloud engineering knowledge, and an automation mindset. While coding and AI-assisted development tools are increasingly available, success in this role requires the ability to design scalable solutions, determine appropriate deployment architectures, validate automated outcomes, and operate security services in production environments.\nIn This Role, You Will\n\nOwn security risk decisions and exploitability prioritization across cloud, application, infrastructure, and identity environments, translating vulnerability and threat signals into clear, actionable outcomes.\nAnalyze vulnerability, threat intelligence, and exposure data to determine real-world exploitability, blast radius, recurrence patterns, and business impact.\nDesign and implement scalable security automation solutions that improve vulnerability identification, ownership attribution, prioritization, triage, and remediation workflows.\nEvaluate security challenges and determine the appropriate combination of automation, AI-assisted capabilities, engineering controls, and human review required to achieve effective risk reduction.\nDesign, deploy, and operate cloud-native security services and automation workflows while ensuring reliability, scalability, observability, and security.\nPartner with engineering teams to accelerate remediation through actionable insights, workflow improvements, and automation.\nReview and validate code, recommendations, and remediation actions generated by automation platforms and AI-assisted development tools prior to production use.\nProduce leadership-ready narratives and metrics such as MTTR, vulnerability aging, exception debt, recurrence rates, and remediation effectiveness to communicate risk posture and program impact.\nLead and support risk reduction campaigns, including prioritization decisions, execution tracking, and outcome measurement aligned to organizational security objectives.\nCollaborate with Product Security, Cloud Security, Threat Intelligence, Architecture, and Engineering teams to improve security outcomes through scalable solutions and automation.\nIdentify false positives, detection gaps, data quality issues, and process inefficiencies; drive improvements across tooling, workflows, data pipelines, and governance processes.\nContribute to the development and operationalization of AI-assisted security workflows and intelligent automation solutions that reduce manual effort and improve decision quality.\nSupport compliance, audit, and regulatory activities by providing evidence, technical explanations, and process documentation.\nParticipate in daily and ad hoc risk assessments, providing guidance during active incidents, emerging threats, and time-sensitive security events.\nParticipate in an on-call rotation to provide risk assessment, decision support, and technical guidance during security incidents and emerging threats.\nMinimum Qualifications\nBachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience.\n2+ years of experience in vulnerability management, security engineering, cloud security, security operations, risk assessment, or related security disciplines.\nDemonstrated understanding of cloud platforms such as AWS, Azure, or GCP and modern application architectures.\nExperience deploying, operating, troubleshooting, or supporting applications and services in cloud environments.\nUnderstanding of systems architecture, APIs, data flows, service integrations, and distributed systems concepts.\nAbility to evaluate security challenges and design scalable solutions that balance risk reduction, operational efficiency, and business impact.\nFamiliarity with scripting, automation, or programming languages (such as Python, PowerShell, Go, or Java) sufficient to automate workflows, integrate systems, and validate generated code.\nExperience working with APIs, automation workflows, and security tooling integrations.\nStrong analytical, troubleshooting, and problem-solving skills.\nStrong written and verbal communication skills with the ability to translate technical findings into actionable business outcomes.\nPreferred Qualifications\n\nExperience designing, deploying, or supporting cloud-native solutions using containers, Kubernetes, serverless platforms, or Infrastructure as Code.\nExperience building or operating security automation platforms, vulnerability management systems, workflow orchestration solutions, or security services.\nFamiliarity with AI-assisted development tools, intelligent automation platforms, and agentic AI concepts.\nExperience evaluating and validating AI-generated recommendations, remediation actions, or code changes before production deployment.\nUnderstanding of observability, monitoring, logging, resiliency, and operational excellence practices.\nExperience integrating, correlating, and enriching security data from multiple sources to improve prioritization, signal quality, ownership attribution, or remediation effectiveness.\nDemonstrated ability to identify opportunities where automation and AI can reduce operational effort and improve security outcomes.\nStrong curiosity, learning agility, and passion for solving complex security problems at scale.\nAccommodation requests\nExpedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request athttps://expedia.service-now.com/askeg?id=job_accommodation.\nAbout Expedia Group\nExpedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.\nImportant notice\nEmployment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.\nEqual Opportunity\nExpedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, gender, sexual orientation, national origin, disability or age.","description_format":"text","description_chars":7815,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Endpoint Security","Information Security","Vulnerability Management","Commerce"],"lifecycle":[{"event":"open","at":"2026-10-01T12:48:33Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.863,"p_room":1,"age_days":2,"expected_fill_days":15,"reasons":["conf:0","velocity","win:early","comp:junior,brand"],"computed_at":"2026-10-04T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/expedia-group-security-engineer-vulnerability-management","json_url":"https://alion.io/job/expedia-group-security-engineer-vulnerability-management.json","meta":{"generated_at":"2026-10-05T02:05:10Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2747,"day_limit":5000,"remaining_today":2253,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}