Jobs and Careers
EX

Security Compliance Analyst III

Expedia Group
Washington, United Statesfull_timeVerifiedPosted 22 Oct 2024
💰 $174,500/yr($101,500/yr$174,500/yr)

About the role

Expedia Group brands power global travel for everyone, everywhere. We design cutting-edge tech to make travel smoother and more memorable, and we create groundbreaking solutions for our partners. Our diverse, vibrant, and welcoming community is essential in driving our success.

Why Join Us?

To shape the future of travel, people must come first. Guided by our Values and Leadership Agreements, we foster an open culture where everyone belongs, differences are celebrated and know that when one of us wins, we all win.

We provide a full benefits package, including exciting travel perks, generous time-off, parental leave, a global hybrid work setup (with some pretty cool offices), and career development resources, all to fuel our employees' passion for travel and ensure a rewarding career journey. We’re building a more open world. Join us.

Security Compliance Analyst III

Expedia Product & Technology builds innovative products, services, and tools to deliver high-quality experiences for travelers, partners, and our employees. A singular technology platform powered by data and machine learning provides secure, differentiated, and personalized experiences for the traveler and our partners that drive loyalty and customer satisfaction. 

The Security Compliance Analyst III role sits on the Policy Management team in the Expedia Technology Security & Privacy (ETSP) organization. Security risk management is the systematic process of identifying, analyzing, mitigating, and reporting the threats and vulnerabilities that pose a risk to our organization's information systems and assets. Security policies and standards are the set of rules, guidelines, and procedures that facilitate the implementation and enforcement of the risk management strategy. They are crucial for ensuring that the organization's security objectives are consistent with our business goals, regulatory obligations, and best practices. Together, the ETSP Policy and Risk Management teams aim to enable our organization to balance the demand for security and privacy with the demand for innovation and performance.
 

Expedia Group Technology, Security and Privacy (ETSP) organization is seeking a highly motivated, collaborative, and technically proficient Security Compliance Analyst. In this role, you will serve as the primary security policy Subject Matter Expert (SME), driving revisions of security standards, identifying gaps, and updating standards and controls to align with current industry benchmarks while balancing compliance requirements, business needs, and risk.  You will develop and implement security policies and standards that align with industry best practices and regulatory requirements and collaborate with Security Architecture and Infrastructure teams to capture and define security requirements for new projects and initiatives.

  
In this role you will:

  • Write, edit, maintain, and support security policies and standards.

  • Evaluate security requirements and controls for design, effectiveness, and gaps.

  • Represent security policy to business stakeholders.

  • Support compliance initiatives and projects as needed, such as GDPR compliance, ISO 27001 certification, PCI DSS compliance authorization, and SOC 2 audits.

  • Collaborate with legal and compliance teams to ensure policies meet legal requirements and industry regulations.

  • Partner with compliance teams on audits and assessments and stay informed about regulatory updates.

  • Assist with security policy exception requests, reviews, and monitoring.

  • Understand the business organizational structure and culture to best attain objectives and results

Experience and Qualifications:

  • You have 5 + years’ experience in information security, risk, compliance, governance, or privacy required.

  • You have a bachelor's degree in in Computer Science or Information Security or related technical field; or equivalent related professional experience

  • Preferred: You have knowledge and experience with NIST CSF, ISO 27001, ISO 27018, PCI, SSAE 18, or SOC 2.

  • Preferred: You have Cyber Security Certifcation.

  • Preferred: You are experienced leading small teams in a collaborative environment.

  • You have extensive experience in writing or managing security policies.

  • You have excellent writing and communication skills.

  • You have experience with technology, data security, and data privacy concepts.

  • You have a proven ability to explain and defend positions to internal and external stakeholders.

  • Yo

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Expedia Group

View company profile →