Expedia

Application Security Engineer III

Expedia
Apply
2 hours ago

Responsibilities

  • Drive shift-left security practices and embed security requirements and controls throughout the software development lifecycle.
  • Integrate, maintain, and improve security tooling and automation across CI/CD pipelines, including SAST, DAST, SCA, dependency scanning, and software supply chain protections.
  • Configure, tune, and triage security tools and vulnerability management platforms to improve signal quality and remediation workflows.
  • Identify, assess, and remediate application security risks across supported services and components in partnership with cross-functional stakeholders.
  • Conduct threat modeling, security code reviews, and system design reviews covering low-level design, API design, and data modeling.
  • Safely integrate and operate AI/ML-enabled solutions that improve security outcomes.
  • Enable developers through secure development guidance, standards, and playbooks and influence secure engineering decisions.
  • Reduce vulnerability backlogs and improve remediation SLAs through automation, tool tuning, and operational improvements.

Requirements

  • Bachelor’s degree in Computer Science or a related technical field, or equivalent related professional experience.
  • 5+ years of relevant professional experience in application security, product security, DevSecOps, or security engineering.
  • Experience supporting modern CI/CD pipelines, cloud-native services, and secure software delivery across multiple services or domains.
  • Practical experience with software supply chain security, including SBOMs, signing or attestation, secure build pipelines, SAST, DAST, and SCA.
  • Experience operating and tuning vulnerability management and security tooling platforms and integrating them with CI/CD pipelines, ticketing systems, and developer workflows.
  • Experience with modern programming languages such as Java or Python for automating security outcomes.
  • Preferred experience applying AI/ML and agentic AI techniques to vulnerability management, including autonomous triage, prioritization, classification, enrichment, or AI-assisted security tooling.
  • Familiarity with AI-driven systems, AI/ML security implications such as the OWASP LLM Top 10, and basic penetration testing concepts.
  • Demonstrated success enabling developers on secure development practices and influencing secure engineering decisions.
  • Strong communication skills and the ability to explain complex security topics to technical and non-security audiences.
  • Proven impact reducing vulnerability backlogs and improving remediation SLAs.

Benefits

  • Medical, dental, and vision coverage.
  • Paid time off and an Employee Assistance Program.
  • Wellness and travel reimbursement.
  • Travel discounts and International Airlines Travel Agent Network (IATAN) membership.

Tech Stack

GitHub ActionsJavaJenkinsPythonSpinnaker

Categories

Expedia

About Expedia

10,000+ employees
Contact me