Expedia Group
Director CyberSecurity
USA - California - San Jose, USA · Director
Sponsorship not specified$249k-$349kDetected 12 hours ago
Distributed SystemsAWSGCPCloud PlatformsCI/CDMachine LearningLLMsRAGAgentic AICybersecuritySOC OperationsDetection EngineeringComplianceZero TrustLeadershipCommunicationCISSP
About the role
- Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy.
- This is fundamentally a hands-on, execution-oriented role.
- WHO THRIVES IN THIS ROLE You are a builder.
Responsibilities
- Design, build, and operationalize reusable security platforms, shared services, and reference architectures that engineering teams consume at scale - prioritizing developer ergonomics and adoption velocity.
- Deliver security guardrails for infrastructure-as-code, containerized microservices, and service mesh architectures - implemented as enforceable, automated policy-as-code controls, not documentation.
- Build and maintain secrets management, certificate lifecycle, and workload identity frameworks for cloud-native infrastructure across multi-cloud environments.
- Own the technical implementation of security tooling integrations - Security Fabric to be include SAST, DAST, SCA, ASPM, CSPM, DSPM - ensuring signal quality, pipeline integration, and engineering team usability.
- Proven ability to develop and operationalize security policies, standards, and compliance frameworks (e.g., PCI-DSS, SOC 2, ISO 27001, GDPR)
- Implement security architecture for LLM-based applications, RAG pipelines, and agentic AI systems - applying controls for prompt injection, model abuse, data exfiltration, and agent trust boundaries in production environments.
- Implement and operate service mesh security at scale - mTLS enforcement, traffic policy, workload identity, and zero-trust network segmentation across distributed microservices environments (Istio, Envoy, or equivalent).
- Architect and build identity-centric, zero-trust security models for distributed systems with complex east-west traffic patterns and hundreds of services.
- Drive practical implementation of zero-trust principles across infrastructure - not as a framework exercise, but as running, enforced controls.
- designing a zero-trust architecture in the morning, reviewing a CI/CD pipeline security integration in the afternoon, collaborating vertically and horizontally with product security and CTO stakeholders to drive our success while understanding competing priorities. you're are Passionate and curious about AI system the next day.
Requirements
- Deep, practitioner-level AWS expertise: IAM, VPC, GuardDuty, Security Hub, Macie, Inspector, Control Tower, Secrets Manager, KMS - operated at scale in high-velocity release environments with measurable outcomes.
- Proven track record delivering SDLC security architecture across large engineering organizations - including CI/CD integration, developer tooling, SAST/DAST/SCA deployment, and runtime security in production.
- Hands-on implementation experience with service mesh architectures - mTLS, workload identity, traffic policy, zero-trust network enforcement - using Istio, Envoy, Linkerd, or equivalent in production.
- Demonstrated proficiency in AI security - implementing controls for LLM applications, RAG systems, and agentic AI pipelines in enterprise production environments, not just evaluating them.
- Ability to contribute to security strategy - translating execution experience and technical depth into roadmap input, architectural direction, and stakeholder communication.
- Bachelor's degree in Computer Science, Information Security, or related technical field - or equivalent professional experience.
- You are a builder.
Nice to have
- Experience in a large-scale, multi-cloud e-commerce or travel technology environment with global operations and high release frequency.
- Prior people leadership or tech lead experience - not required, but relevant for candidates interested in optional team leadership scope.
- Relevant certifications: CISSP, CCSP, CSSLP, AWS Security Specialty, or GCP Security Engineer.
- Applied experience with PCI-DSS, SOC 2, GDPR, and ISO 27001 as a practitioner for building compliant systems - not as a policy author.
- Senior Individual Contributor | Director-Level Scope
- Note: This role is open to exceptional senior ICs and to candidates with people leadership experience who prefer to remain primarily hands-on.
- People management responsibilities may be available for the right candidate but are not required.
- The total cash range for this position in San Jose is $249,000.00 to $348,500.00.
Skills
- Join us and build for travelers everywhere.
- Director, Security Engineering
Compensation
- $249k-$349k
Benefits
- Benefits and perks
- Demonstrated experience applying AI and machine learning techniques within cybersecurity contexts, including threat detection, anomaly detection, or automated vulnerability management
Equal opportunity
- Accommodation requests
Apply directly at Expedia Group →Create a free account for alerts like thisView Expedia Group immigration profile
This listing is sourced directly from Expedia Group's careers page and normalized into a canonical job model.