Expedia

Principal Cybersecurity Engineer

Expedia
Apply
2 hours ago
San Jose, CA, USAStaff+
H1B sponsor

Responsibilities

  • Design, build, and operate reusable security platforms, shared services, reference architectures, and automated policy-as-code controls for infrastructure, containers, and service meshes.
  • Build and maintain secrets management, certificate lifecycle, workload identity, zero-trust, and service mesh security capabilities across multi-cloud environments.
  • Integrate SAST, DAST, SCA, ASPM, CSPM, and DSPM tooling into engineering pipelines and workflows.
  • Implement security architecture and operational controls for LLM applications, RAG pipelines, and agentic AI systems, including protections against prompt injection, model abuse, data exfiltration, and agent trust-boundary violations.
  • Architect and operate AWS-native security controls including IAM, SCPs, GuardDuty, Security Hub, Inspector, Macie, Control Tower, Secrets Manager, and KMS.
  • Run cloud security posture, data security posture, detection, alerting, and automated response programs at enterprise scale.
  • Embed threat modeling, runtime protection, security frameworks, libraries, and controls into SDLC, CI/CD, web application, API, mobile, and cloud-native engineering workflows.
  • Develop security guidance, architectural blueprints, documentation, and strategy input while partnering with engineering and AI platform teams.

Requirements

  • 15+ years of progressive, hands-on cybersecurity experience building and operating enterprise-scale security systems.
  • Deep practitioner-level AWS expertise, including IAM, VPC, GuardDuty, Security Hub, Macie, Inspector, Control Tower, Secrets Manager, and KMS.
  • Proven experience delivering SDLC security architecture, CI/CD integrations, developer tooling, SAST/DAST/SCA deployments, and runtime security in production.
  • Hands-on production experience with service mesh architectures, mTLS, workload identity, traffic policy, and zero-trust enforcement using Istio, Envoy, Linkerd, or equivalent.
  • Demonstrated experience implementing security controls for LLM applications, RAG systems, and agentic AI pipelines in enterprise production environments.
  • Operational experience running CSPM and DSPM programs, including finding triage, remediation velocity, and posture improvement metrics.
  • Ability to influence engineering teams without formal authority, contribute to security strategy, and communicate through authoritative technical documentation and executive-level summaries.
  • Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience.
  • Preferred qualifications include large-scale multi-cloud e-commerce or travel technology experience, agentic AI security and red-teaming, security-as-a-platform development, prior people leadership or tech lead experience, and CISSP, CCSP, CSSLP, AWS Security Specialty, or GCP Security Engineer certification.
  • Experience applying PCI-DSS, SOC 2, GDPR, and ISO 27001 as a practitioner is preferred.

Benefits

  • Medical, dental, and vision coverage.
  • Paid time off and an Employee Assistance Program.
  • Wellness and travel reimbursement.
  • Travel discounts and International Airlines Travel Agent Network membership.

Tech Stack

AmbassadorAssemblyAWSIstio

Categories

Expedia

About Expedia

10,000+ employees
Contact me