← Back to all jobs

Principal Cyber Security Engineer

Expedia Group · USA - California - San Jose · Posted 2026-08-29

Apply on the company site →

Job description

At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business. Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere. Principal Security Engineer Our Technology Team partners with teams across Expedia Group to create innovative products, services, and tools to deliver high-quality experiences for travelers, partners, and our employees. A singular technology platform powered by data and machine learning provides secure, differentiated, and personalized experiences that drive loyalty and traveler satisfaction. Expedia Group's Product Security organization is building the security infrastructure, platforms, and services that power secure software delivery across one of the world's largest travel technology platforms. We are looking for a Principal Security Engineer who ships — someone who turns architectural thinking into running systems, operating controls, and measurable outcomes at enterprise scale. This is fundamentally a hands-on, execution-oriented role. You will design and build security platforms, embed controls into high-velocity engineering workflows, operationalize cloud and data security programs, and serve as the technical anchor for complex, cross-cutting security initiatives. You will work closely with engineering teams, platform architects, and technology leads — influencing craft, output, and trust rather than org chart position. If you are energized by building things that work at scale, by making security invisible to engineers who do the right thing, and by leaving systems measurably more secure than you found them — this role was written for you. WHO THRIVES IN THIS ROLE You are a builder. You measure your impact in systems shipped, controls operationalized, and engineering teams unblocked — not in decks presented or frameworks authored. You are most comfortable when you are deep in the work: designing a zero-trust architecture in the morning, reviewing a CI/CD pipeline security integration in the afternoon, collaborating vertically and horizontally with product security and CTO stakeholders to drive our success while understanding competing priorities. you're are Passionate and curious about AI system the next day. You understand that security at scale is a product problem — and you design accordingly, obsessing over adoption, ergonomics, and measurable outcomes. You influence through craft, consistency, and trust, and you thrive in environments where competing priorities are real, and judgment matters more than process. In this role, you will: Security Platform & Infrastructure Delivery Design, build, and operationalize reusable security platforms, shared services, and reference architectures that engineering teams consume at scale — prioritizing developer ergonomics and adoption velocity. Deliver security guardrails for infrastructure-as-code, containerized microservices, and service mesh architectures — implemented as enforceable, automated policy-as-code controls, not documentation. Build and maintain secrets management, certificate lifecycle, and workload identity frameworks for cloud-native infrastructure across multi-cloud environments. Own the technical implementation of security tooling integrations — Security Fabric to be include SAST, DAST, SCA, ASPM, CSPM, DSPM — ensuring signal quality, pipeline integration, and engineering team usability. Proven ability to develop and operationalize security policies, standards, and compliance frameworks (e.g., PCI-DSS, SOC 2, ISO 27001, GDPR) AI & Agentic System Security — Hands-On Implementation Demonstrated experience applying AI and machine learning techniques within cybersecurity contexts, including threat detection, anomaly detection, or automated vulnerability management Implement security architecture for LLM-based applications, RAG pipelines, and agentic AI systems — applying controls for prompt injection, model abuse, data exfiltration, and agent trust boundaries in production environments. Evaluate and operationalize AI-powered security tooling — automated threat detection, vulnerability triage, AI-driven response — from proof of concept through production operation. Embed security early in Expedia Group's AI development lifecycle, influencing model selection, fine-tuning practices, and deployment architecture through direct partnership with AI platform teams. Service Mesh & Zero-Trust Infrastructure Implement and operate service mesh security at scale — mTLS enforcement, traffic policy, workload identity, and zero-trust network segmentation across distributed microservices environments (Istio, Envoy, or equivalent). Architect and build identity-centric, zero-trust security models for distributed systems with complex east-west traffic patterns and hundreds of services. Drive practical implementation of zero-trust principles across infrastructure — not as a framework exercise, but as running, enforced controls. AWS Cloud Security Operations at Scale Architect and operate AWS-native security controls at enterprise scale: IAM and SCPs, GuardDuty, Security Hub, Inspector, Macie, Control Tower, Secrets Manager, KMS — configured, tuned, and continuously improved, not just deployed. Cloud Security Posture Management (CSPM) and Data Security Posture Management (DSPM) programs operationally — driving down finding age, improving coverage, and closing posture gaps at velocity.Instrument and maintain security obs