Government Careers
  • Principal Analyst - Security Operations

  • Expedia Group
  • Seattle, Washington 98127 United States View Map

Summary

Principal Analyst – Security OperationsOur Cyber Security organization works across Expedia Group to protect the travelers, partners, employees, and platforms that power global travel. We build and operate resilient, intelligence-driven security capabilities spanning security operations, threat detection and response, security engineering, identity, data, and cloud security—reducing cyber risk while enabling trusted, secure innovation at scale.The Security Operations team partners with technology, product, and platform teams to detect, investigate, contain, and recover from threats while continuously improving the automation, telemetry, and operating models that keep Expedia Group secure. As part of this team, a Principal Security Operations leader will help set the technical direction for modern, AI-enabled defense capabilities, turn complex signals into decisive action, and strengthen a proactive, measurable security posture across the enterprise.In this role you will:Lead complex security operations analyses to detect, investigate, and respond to sophisticated threats across Expedia Group's environments, driving clear, measurable risk reduction.Design, optimize, and standardize security monitoring and incident response workflows, including runbooks, playbooks, and escalation paths, to improve speed, quality, and consistency of response.Partner with engineering, incident management, and product teams to translate security findings into actionable technical requirements and remediation plans, influencing roadmaps across multiple domains.Develop and maintain advanced analytics, detections, dashboards, and reporting that provide deep visibility into security posture, threat trends, and operational performance for senior stakeholders.Provide technical leadership and mentorship across global security operations, shaping best practices for log management, alert tuning, investigation techniques, and use of SOAR/SIEM and related tooling.Safely integrate and operate AI/ML-enabled solutions that improve detection, triage, and response outcomes, building familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world security operations scenarios.Minimum Qualifications:Bachelor's degree in computer science, Information Security, Engineering, or a related technical field, or equivalent practical experience in security operations.Extensive experience in security operations, including hands-on incident detection, investigation, and response across large-scale or complex environments.Proven ownership of security operations across multiple services or domains, including responsibility for end-to-end monitoring, alerting, and incident handling processes.Strong technical expertise in security tooling and infrastructure such as SIEM, EDR, log management, and security analytics platforms, and in interpreting complex telemetry for threat detection.Familiarity with AI-driven systems, tools, or workflows in a security context, and the ability to work effectively with data, detections, and automation to improve operational outcomes.Preferred Qualifications:Advanced experience operating global, large-scale security operations, including designing and refining detection strategies and incident response capabilities for highly distributed systems.Demonstrated leadership in shaping the architecture and integration of security operations tools (for example SIEM, SOAR, EDR, ticketing, and automation platforms) across multiple technical domains.Proven track record of driving operational excellence through continuous improvement of metrics, processes, automation, and data-driven decision making in security operations.Experience designing, implementing, and tuning AI/ML-supported detections, triage workflows, or automated response actions, ensuring safe and effective use of AI/ML-enabled solutions in production security environments.Ability to influence senior technical and business stakeholders using clear, data-backed insights from security operations, and to mentor others in advanced investigation, threat hunting, and incident management practices.

Job Description

Principal Analyst – Security OperationsOur Cyber Security organization works across Expedia Group to protect the travelers, partners, employees, and platforms that power global travel. We build and operate resilient, intelligence-driven security capabilities spanning security operations, threat detection and response, security engineering, identity, data, and cloud security—reducing cyber risk while enabling trusted, secure innovation at scale.The Security Operations team partners with technology, product, and platform teams to detect, investigate, contain, and recover from threats while continuously improving the automation, telemetry, and operating models that keep Expedia Group secure. As part of this team, a Principal Security Operations leader will help set the technical direction for modern, AI-enabled defense capabilities, turn complex signals into decisive action, and strengthen a proactive, measurable security posture across the enterprise.In this role you will:Lead complex security operations analyses to detect, investigate, and respond to sophisticated threats across Expedia Group's environments, driving clear, measurable risk reduction.Design, optimize, and standardize security monitoring and incident response workflows, including runbooks, playbooks, and escalation paths, to improve speed, quality, and consistency of response.Partner with engineering, incident management, and product teams to translate security findings into actionable technical requirements and remediation plans, influencing roadmaps across multiple domains.Develop and maintain advanced analytics, detections, dashboards, and reporting that provide deep visibility into security posture, threat trends, and operational performance for senior stakeholders.Provide technical leadership and mentorship across global security operations, shaping best practices for log management, alert tuning, investigation techniques, and use of SOAR/SIEM and related tooling.Safely integrate and operate AI/ML-enabled solutions that improve detection, triage, and response outcomes, building familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world security operations scenarios.Minimum Qualifications:Bachelor's degree in computer science, Information Security, Engineering, or a related technical field, or equivalent practical experience in security operations.Extensive experience in security operations, including hands-on incident detection, investigation, and response across large-scale or complex environments.Proven ownership of security operations across multiple services or domains, including responsibility for end-to-end monitoring, alerting, and incident handling processes.Strong technical expertise in security tooling and infrastructure such as SIEM, EDR, log management, and security analytics platforms, and in interpreting complex telemetry for threat detection.Familiarity with AI-driven systems, tools, or workflows in a security context, and the ability to work effectively with data, detections, and automation to improve operational outcomes.Preferred Qualifications:Advanced experience operating global, large-scale security operations, including designing and refining detection strategies and incident response capabilities for highly distributed systems.Demonstrated leadership in shaping the architecture and integration of security operations tools (for example SIEM, SOAR, EDR, ticketing, and automation platforms) across multiple technical domains.Proven track record of driving operational excellence through continuous improvement of metrics, processes, automation, and data-driven decision making in security operations.Experience designing, implementing, and tuning AI/ML-supported detections, triage workflows, or automated response actions, ensuring safe and effective use of AI/ML-enabled solutions in production security environments.Ability to influence senior technical and business stakeholders using clear, data-backed insights from security operations, and to mentor others in advanced investigation, threat hunting, and incident management practices.

Government Careers

Government Careers

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS