Summary
Principal Analyst – Security OperationsOur Cyber Security organization works across Expedia Group to protect the travelers, partners, employees, and platforms that power global travel. We build and operate resilient, intelligence-driven security capabilities spanning security operations, threat detection and response, security engineering, identity, data, and cloud security—reducing cyber risk while enabling trusted, secure innovation at scale.The Security Operations team partners with technology, product, and platform teams to detect, investigate, contain, and recover from threats while continuously improving the automation, telemetry, and operating models that keep Expedia Group secure. As part of this team, a Principal Security Operations leader will help set the technical direction for modern, AI-enabled defense capabilities, turn complex signals into decisive action, and strengthen a proactive, measurable security posture across the enterprise.In this role you will:Lead complex security operations analyses to detect, investigate, and respond to sophisticated threats across Expedia Group's environments, driving clear, measurable risk reduction.Design, optimize, and standardize security monitoring and incident response workflows, including runbooks, playbooks, and escalation paths, to improve speed, quality, and consistency of response.Partner with engineering, incident management, and product teams to translate security findings into actionable technical requirements and remediation plans, influencing roadmaps across multiple domains.Develop and maintain advanced analytics, detections, dashboards, and reporting that provide deep visibility into security posture, threat trends, and operational performance for senior stakeholders.Provide technical leadership and mentorship across global security operations, shaping best practices for log management, alert tuning, investigation techniques, and use of SOAR/SIEM and related tooling.Safely integrate and operate AI/ML-enabled solutions that improve detection, triage, and response outcomes, building familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world security operations scenarios.Minimum Qualifications:Bachelor's degree in computer science, Information Security, Engineering, or a related technical field, or equivalent practical experience in security operations.Extensive experience in security operations, including hands-on incident detection, investigation, and response across large-scale or complex environments.Proven ownership of security operations across multiple services or domains, including responsibility for end-to-end monitoring, alerting, and incident handling processes.Strong technical expertise in security tooling and infrastructure such as SIEM, EDR, log management, and security analytics platforms, and in interpreting complex telemetry for threat detection.Familiarity with AI-driven systems, tools, or workflows in a security context, and the ability to work effectively with data, detections, and automation to improve operational outcomes.Preferred Qualifications:Advanced experience operating global, large-scale security operations, including designing and refining detection strategies and incident response capabilities for highly distributed systems.Demonstrated leadership in shaping the architecture and integration of security operations tools (for example SIEM, SOAR, EDR, ticketing, and automation platforms) across multiple technical domains.Proven track record of driving operational excellence through continuous improvement of metrics, processes, automation, and data-driven decision making in security operations.Experience designing, implementing, and tuning AI/ML-supported detections, triage workflows, or automated response actions, ensuring safe and effective use of AI/ML-enabled solutions in production security environments.Ability to influence senior technical and business stakeholders using clear, data-backed insights from security operations, and to mentor others in advanced investigation, threat hunting, and incident management practices.
Job Description
Principal Analyst – Security OperationsOur Cyber Security organization works across Expedia Group to protect the travelers, partners, employees, and platforms that power global travel. We build and operate resilient, intelligence-driven security capabilities spanning security operations, threat detection and response, security engineering, identity, data, and cloud security—reducing cyber risk while enabling trusted, secure innovation at scale.The Security Operations team partners with technology, product, and platform teams to detect, investigate, contain, and recover from threats while continuously improving the automation, telemetry, and operating models that keep Expedia Group secure. As part of this team, a Principal Security Operations leader will help set the technical direction for modern, AI-enabled defense capabilities, turn complex signals into decisive action, and strengthen a proactive, measurable security posture across the enterprise.In this role you will:Lead complex security operations analyses to detect, investigate, and respond to sophisticated threats across Expedia Group's environments, driving clear, measurable risk reduction.Design, optimize, and standardize security monitoring and incident response workflows, including runbooks, playbooks, and escalation paths, to improve speed, quality, and consistency of response.Partner with engineering, incident management, and product teams to translate security findings into actionable technical requirements and remediation plans, influencing roadmaps across multiple domains.Develop and maintain advanced analytics, detections, dashboards, and reporting that provide deep visibility into security posture, threat trends, and operational performance for senior stakeholders.Provide technical leadership and mentorship across global security operations, shaping best practices for log management, alert tuning, investigation techniques, and use of SOAR/SIEM and related tooling.Safely integrate and operate AI/ML-enabled solutions that improve detection, triage, and response outcomes, building familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world security operations scenarios.Minimum Qualifications:Bachelor's degree in computer science, Information Security, Engineering, or a related technical field, or equivalent practical experience in security operations.Extensive experience in security operations, including hands-on incident detection, investigation, and response across large-scale or complex environments.Proven ownership of security operations across multiple services or domains, including responsibility for end-to-end monitoring, alerting, and incident handling processes.Strong technical expertise in security tooling and infrastructure such as SIEM, EDR, log management, and security analytics platforms, and in interpreting complex telemetry for threat detection.Familiarity with AI-driven systems, tools, or workflows in a security context, and the ability to work effectively with data, detections, and automation to improve operational outcomes.Preferred Qualifications:Advanced experience operating global, large-scale security operations, including designing and refining detection strategies and incident response capabilities for highly distributed systems.Demonstrated leadership in shaping the architecture and integration of security operations tools (for example SIEM, SOAR, EDR, ticketing, and automation platforms) across multiple technical domains.Proven track record of driving operational excellence through continuous improvement of metrics, processes, automation, and data-driven decision making in security operations.Experience designing, implementing, and tuning AI/ML-supported detections, triage workflows, or automated response actions, ensuring safe and effective use of AI/ML-enabled solutions in production security environments.Ability to influence senior technical and business stakeholders using clear, data-backed insights from security operations, and to mentor others in advanced investigation, threat hunting, and incident management practices.
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Combat Engineer - Find Success in US Army (98312)
- Bremerton, Washington
- U.S. Army
- Aug 26, 2026
-
Traffic Control Technician II (UNION)
- Evansville, Indiana
- RoadSafe Traffic
- Aug 26, 2026
-
Special Forces Candidate - Find Success in US Army (94901)
- San Rafael, California
- U.S. Army
- Aug 26, 2026
-
Field Artillery Recruit 13U - Entry Level (95320)
- Escalon, California
- U.S. Army
- Aug 26, 2026
-
All Source Intelligence Analyst
- Tampa, Florida
- Maxar Technologies
- Aug 26, 2026
-
Field Artillery Recruit 13U - Find Your Full Time or Part Time Army Career (91423)
- Sherman Oaks, California
- U.S. Army
- Aug 26, 2026