Jobs and Careers
EX

Security Analyst II

Expedia Group
United Statesfull_timeVerifiedPosted 16 Dec 2024
💰 $179,000/yr($112,000/yr$179,000/yr)

About the role

Expedia Group brands power global travel for everyone, everywhere. We design cutting-edge tech to make travel smoother and more memorable, and we create groundbreaking solutions for our partners. Our diverse, vibrant, and welcoming community is essential in driving our success.

Why Join Us?

To shape the future of travel, people must come first. Guided by our Values and Leadership Agreements, we foster an open culture where everyone belongs, differences are celebrated and know that when one of us wins, we all win.

We provide a full benefits package, including exciting travel perks, generous time-off, parental leave, a global hybrid work setup (with some pretty cool offices), and career development resources, all to fuel our employees' passion for travel and ensure a rewarding career journey. We’re building a more open world. Join us.

Security Analyst II:

Are you an experienced security professional who is looking to join a team at the heart of Expedia's Technology Security and Privacy team?   

The Expedia Technology Security and Privacy team works across the company’s many groups and products to deliver security solutions to ensure Expedia customers can trust the Expedia brand. You will shape the future of Expedia by bringing a blend of strategy and security management competencies to ensure attack surface reduction. This role is unique and inherently cross-functional - you will collaborate across the multiple teams that develop and run our platform.   

The Security Analyst II, Attack Surface Management will work on a team of Security Analysts and Senior Security Engineers. You are an experienced security analyst, capable of supporting the security and privacy domain programs. You will be key to the delivery of measurable security outcomes. You will prepare analysis for Expedia development and infrastructure teams in support of Baseline Security.   

In this role, you will:  

  • Leverage analysis of security data to develop insights and create trusted vulnerability and risk reporting that meets user requirements.  

  • Recognize and stay apprised of emerging technology trends and best practices that could potentially benefit the organization  

  • Investigate a range of issues or incidents by gathering and analyzing information, documenting insights and findings on the underlying cause, circumstances, and contributing factors, and suggesting necessary actions for resolution  

  • Effectively identify issues with the quality and performance of products, services, solutions or processes and proposes improvements  

  • Possess knowledge of features and facilities for integration, and communication among applications, databases, and technology platforms to bring together different components and form a fully functional solution to a business problem  

  • Facilitate collaboration with different stakeholders with varied perspectives to develop effective solutions to issues  

  • Apply knowledge and expertise to complex asset management assignments and projects; assists with the development of business area’s asset management standards and procedures  

  • Provide data to quickly reveal the root cause of problems, and analyze problems all the way to successful resolutions

  • Use knowledge and experience to perform complex platform assessments and assignments in context of security; assists with policy and procedure development  

  • Evaluate trends and results of security investigations and outcomes to proactively tune security technology to force active prevention of security threats to the outermost layer of our infrastructure wherever possible  

  • Review outcomes of security investigations and compares expected prevention steps to actuals and modifies configuration of security controls to bring prevention further to the edge  

  • May design and implement custom software, scripts, policies, extensions, or APIs to support the identification and prevention of information security threats  

  • May conduct interoperability assessments on information security controls to limit friction caused to the end user, developer, analyst, and customer communities  

  • Ensure that information security controls are not in conflict and designs and implements solutions where tooling may overlap  

  • May assist in incident remediation activities by participating in incident response process and adjusting existing or implementing new information security controls to address discovered vulnerabilities or defensive gaps in the detective and preventative control stack live and in real time

  

Experience and qualifications: 

  • 3+ years of experience  

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Expedia Group

View company profile →