Senior Product Security Architect
About the role
The Senior Product Security Architect plays a pivotal role in ensuring that Expedia Group's products and services are secure and privacy-aware. Reporting to the Head of Product Security, you will advise product, engineering, and platform teams on security matters, lead threat modeling and security assessments, and contribute to the broader security strategy.
Responsibilities
- Serve as a trusted product security architecture advisor to product, engineering, and platform teams.
- Lead and facilitate threat modeling and security assessments for new and evolving products, services, and platforms.
- Partner closely with product and engineering leaders to embed security requirements into product roadmaps, design reviews, and delivery processes.
- Provide thought leadership around enabling and applying AI across the Product Security org.
- Be a change agent influencing and scaling the adoption of AI-enabled security tooling and best practices across the product security organization.
- Drive continuous verification of product security controls and requirements through AI-enabled automation and integration with existing product security tooling.
- Communicate complex product security and architecture trade-offs in a clear, outcome-focused way to both technical and non-technical stakeholders.
- Mentor and coach product managers, engineers, and architects to raise the bar on product security literacy and design thinking across the organization.
- Contribute to the broader Expedia Group security strategy by identifying emerging product security risks and technology trends and proposing pragmatic, long-term architecture approaches.
- Create a culture of continuous learning, data-driven decisions, and improvements.
- Collaborate across IT and Information Security teams to ensure end-to-end coverage across the product lifecycle.
Requirements
- Bachelor’s degree in Computer Science or a related technical field; or equivalent related professional experience.
- 10+ years of product security and development experience.
- Extensive experience performing application threat modeling.
- Significant experience in the last several years applying Generative AI in software development and for end users, ideally in the context of a medium or large enterprise.
- Expertise in public cloud platforms (AWS is preferred), containerization and orchestration (Kubernetes, Docker), and related technologies.
- Excellent communication and collaboration skills, with the ability to work effectively with both technical and non-technical stakeholders.
- Experience operating product security at scale in cloud-native environments (such as large microservices architectures).
- Deep experience conducting and scaling threat modeling, security design reviews, and architecture risk assessments, and using insights to shape platform capabilities, reusable controls, and security automation.
- Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real-world products, including leveraging AI/ML-enabled code analysis, anomaly detection, or security automation; safely integrating and operating AI/ML-enabled solutions that improve security posture, detection, and response.
- Demonstrated experience taking products from concept to scaled adoption by partnering with product and engineering leadership to embed security requirements into product vision, architecture, and roadmaps, and to measure and report on security outcomes.
Preferred Qualifications
- Expertise in public cloud platforms (AWS is preferred), containerization and orchestration (Kubernetes, Docker), and related technologies.
- Track record of setting and evolving security architecture standards, patterns, and guardrails for complex, multi-tenant or multi-domain platforms, and driving their adoption across diverse engineering teams.
- Experience operating product security at scale in cloud-native environments (such as large microservices architectures).
- Deep experience conducting and scaling threat modeling, security design reviews, and architecture risk assessments, and using insights to shape platform capabilities, reusable controls, and security automation.
- Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real-world products, including leveraging AI/ML-enabled code analysis, anomaly detection, or security automation; safely integrating and operating AI/ML-enabled solutions that improve security posture, detection, and response.
- Demonstrated experience taking products from concept to scaled adoption by partnering with product and engineering leadership to embed security requirements into product vision, architecture, and roadmaps, and to measure and report on security outcomes.
Pay
The total cash range for this position varies by location, but typically ranges from $184,500.00 to $295,000.00, with potential for further increases based on performance.
Benefits and Perks
Expedia Group offers a comprehensive benefits package including medical, dental, and vision coverage, paid time off, an Employee Assistance Program, wellness and travel reimbursement, travel discounts, and International Airlines Travel Agent Network (IATAN) membership. Learn more about life at Expedia Group at https://careers.expediagroup.com/life.
About Expedia Group
Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.
Equal Opportunity
Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other characteristic protected by law.