Security Engineer , Application Security
Expedia Group, Inc.Match Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Identify, assess, and help remediate application security vulnerabilities in software development workflows.
Partner with engineering and product teams to embed secure-by-design practices via security reviews, threat modeling, and risk analysis for applications, APIs, and data flows.
Integrate and improve security tooling and automation in CI/CD pipelines, including SAST, DAST, SCA, dependency scanning, and supply chain protections; apply AI/ML solutions to improve application security.
Minimum Requirements
Bachelor’s degree in computer science, information security, engineering, or related technical field, or equivalent experience.
2+ years of experience in application security, software engineering, cybersecurity, or related technical discipline.
Working knowledge of common web and API vulnerabilities (e.g., OWASP Top 10) and ability to read code and explain security issues to developers.
Familiarity with vulnerability identification, assessment, prioritization, and remediation processes in applications.
Ideal Candidate Profile
Experienced in hands-on identification of vulnerabilities in web applications or APIs using code reviews, testing tools, or bug bounty initiatives.
Skilled in automating application security tasks via scripting or custom rules in scanners (e.g., Semgrep, CodeQL) and familiar with CI/CD pipeline security integration.
Exposure to threat modeling, secure design principles, triaging vulnerability scan findings, and building AI-powered security tools or automation workflows.
