At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.
Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.
Security Engineer-II, Application Security
In this role you will :
- Identify, assess, and help remediate application security vulnerabilities across software development and delivery workflows.
- Partner with engineering and product teams to embed secure-by-design practices throughout the software development lifecycle.
- Perform security reviews, threat modeling, and risk analysis for applications, services, APIs, and data flows.
- Integrate, maintain, and continuously improve security tooling and automation across CI/CD pipelines, including capabilities such as SAST, DAST, SCA, dependency scanning, and software supply chain protections.
- Participate in security design reviews alongside senior engineers, helping identify risks in API design, data models and system architecture, and recommend fixes based on application security principles.
- Safely integrate and operate AI/ML-enabled solutions that improve application security outcomes, while applying AI/ML concepts to real-world products and workflows.
Minimum Qualifications:
- Bachelor’s degree in computer science, information security, engineering, or a related technical field, or equivalent practical experience.
- 2+ Experience in application security, software engineering, cybersecurity, or a related technical discipline.
- Familiarity with how vulnerabilities are identified, assessed and fixed in applications, such as priority based triaging or verifying a fix.
- Working knowledge of common web and API vulnerabilities (e.g., OWASP Top 10) and how to prevent them.
- Ability to read code, identify security issues, and explain them clearly to developers.
Preferred Qualifications:
- Hands-on experience identifying vulnerabilities in web applications or APIs, through code review, testing tools such as Burp Suite, CTFs, bug bounty programs or personal projects
- Experience writing scripts or small tools to automate an application security task, such as running a scanner in CI/CD, parsing and triaging scan results, or writing a custom SAST rule (e.g., Semgrep or CodeQL)
- Exposure to threat modeling or secure design concepts, such as authentication, authorisation, input validation and data protection.
- Familiarity with triaging SAST, SCA or secrets-scanning findings, including telling true positives from false positives.
- Hands-on experience building AI-powered applications, such as LLM-based tools, agents or automation workflows, through work, internships, personal projects or open source.
Accommodation requests
Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.
About Expedia Group
Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.
Important notice
Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.
Equal Opportunity
Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, gender, sexual orientation, national origin, disability or age.Skills Required
- Bachelor's degree in computer science, information security, engineering, or a related technical field, or equivalent practical experience
- 2+ years of experience in application security, software engineering, cybersecurity, or a related technical discipline
- Familiarity with identifying, assessing, prioritizing, and verifying remediation of application vulnerabilities
- Working knowledge of common web and API vulnerabilities, including the OWASP Top 10, and prevention techniques
- Ability to read code, identify security issues, and explain findings clearly to developers
- Hands-on experience identifying vulnerabilities in web applications or APIs through code review, testing tools, CTFs, bug bounty programs, or personal projects
- Experience writing scripts or tools to automate application security tasks, including CI/CD scanning, scan-result triage, or custom SAST rules
- Exposure to threat modeling and secure design concepts, including authentication, authorization, input validation, and data protection
- Familiarity with triaging SAST, SCA, or secrets-scanning findings and distinguishing true positives from false positives
- Hands-on experience building AI-powered applications, LLM-based tools, agents, or automation workflows
Expedia Group Compensation & Benefits Highlights
-
Wellbeing & Lifestyle Benefits — Travel-aligned perks such as employee travel discounts and an annual travel/wellness reimbursement stand out as distinctive elements of the package. Wellness resources and mental health tools further enhance day-to-day lifestyle value.
-
Healthcare Strength — Medical, dental, and vision coverage are described as comprehensive, with strong support including EAP and mental health offerings. U.S. coverage is frequently highlighted as a particular strength.
-
Parental & Family Support — Paid parental leave is characterized as generous for all parents, with additional time for the birthing parent. Family-building and caregiving resources extend to fertility, adoption, surrogacy, gender-affirming care, and specialized caregiver support.
Expedia Group Insights
What We Do
Expedia Group, Inc. is the global travel marketplace with one purpose: to help travelers explore the world, one journey at a time. Expedia Group™ connects travelers, partners, and advertisers through its trusted brands, leading technology, and rich first-party data, delivering predictive, personalized experiences that shape the future of travel. Expedia Group’s ecosystem includes three flagship consumer brands – Expedia®, Hotels.com®, and Vrbo® – the largest B2B travel business, and a premier advertising network. Guided by an experienced and passionate global team, Expedia Group helps millions of travelers in more than 70 countries explore the world with confidence and ease.
Why Work With Us
Life at Expedia Group starts with the people and is shaped by how we work together. You’ll join a global community of curious teammates from different backgrounds, locations, and disciplines. Day to day, that means sharing ideas, taking ownership, and solving problems together.
Gallery
Expedia Group Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.

