Principal Analyst - Security Operations

WashingtonFull-timeup to $370kPosted Aug 6, 2026

At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.


Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.

Principal Analyst – Security Operations
Our Cyber Security organization works across Expedia Group to protect the travelers, partners, employees, and platforms that power global travel. We build and operate resilient, intelligence-driven security capabilities spanning security operations, threat detection and response, security engineering, identity, data, and cloud security—reducing cyber risk while enabling trusted, secure innovation at scale.

The Security Operations team partners with technology, product, and platform teams to detect, investigate, contain, and recover from threats while continuously improving the automation, telemetry, and operating models that keep Expedia Group secure. As part of this team, a Principal Security Operations leader will help set the technical direction for modern, AI-enabled defense capabilities, turn complex signals into decisive action, and strengthen a proactive, measurable security posture across the enterprise.

In this role you will:

  • Lead complex security operations analyses to detect, investigate, and respond to sophisticated threats across Expedia Group’s environments, driving clear, measurable risk reduction.
  • Design, optimize, and standardize security monitoring and incident response workflows, including runbooks, playbooks, and escalation paths, to improve speed, quality, and consistency of response.
  • Partner with engineering, incident management, and product teams to translate security findings into actionable technical requirements and remediation plans, influencing roadmaps across multiple domains.
  • Develop and maintain advanced analytics, detections, dashboards, and reporting that provide deep visibility into security posture, threat trends, and operational performance for senior stakeholders.
  • Provide technical leadership and mentorship across global security operations, shaping best practices for log management, alert tuning, investigation techniques, and use of SOAR/SIEM and related tooling.
  • Safely integrate and operate AI/ML‑enabled solutions that improve detection, triage, and response outcomes, building familiarity with AI‑driven systems, tools, or workflows and applying AI/ML concepts to real world security operations scenarios.

Minimum Qualifications:

  • Bachelor’s degree in computer science, Information Security, Engineering, or a related technical field, or equivalent practical experience in security operations.
  • Extensive experience in security operations, including hands‑on incident detection, investigation, and response across large‑scale or complex environments.
  • Proven ownership of security operations across multiple services or domains, including responsibility for end‑to‑end monitoring, alerting, and incident handling processes.
  • Strong technical expertise in security tooling and infrastructure such as SIEM, EDR, log management, and security analytics platforms, and in interpreting complex telemetry for threat detection.
  • Familiarity with AI‑driven systems, tools, or workflows in a security context, and the ability to work effectively with data, detections, and automation to improve operational outcomes.

Preferred Qualifications:

  • Advanced experience operating global, large‑scale security operations, including designing and refining detection strategies and incident response capabilities for highly distributed systems.
  • Demonstrated leadership in shaping the architecture and integration of security operations tools (for example SIEM, SOAR, EDR, ticketing, and automation platforms) across multiple technical domains.
  • Proven track record of driving operational excellence through continuous improvement of metrics, processes, automation, and data‑driven decision making in security operations.
  • Experience designing, implementing, and tuning AI/ML‑supported detections, triage workflows, or automated response actions, ensuring safe and effective use of AI/ML‑enabled solutions in production security environments.
  • Ability to influence senior technical and business stakeholders using clear, data‑backed insights from security operations, and to mentor others in advanced investigation, threat hunting, and incident management practices.


 

The total cash range for this position in Seattle is $231,000.00 to $323,500.00. Employees in this role have the potential to increase their pay up to $369,500.00, which is the top of the range, based on ongoing, demonstrated, and sustained performance in the role.


Starting pay for this role will vary based on multiple factors, including location, available budget, and an individual’s knowledge, skills, and experience. Pay ranges may be modified in the future.


Benefits and perks

Expedia Group offers benefits and perks designed to support employees and their families, including medical, dental, and vision coverage, paid time off, an Employee Assistance Program, wellness and travel reimbursement, travel discounts, and International Airlines Travel Agent Network (IATAN) membership. Learn more about life at Expedia Group at https://careers.expediagroup.com/life.


Accommodation requests

Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.


About Expedia Group

Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.


Important notice

Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.


Equal Opportunity

Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other characteristic protected by law. This employer participates in E-Verify. The employer will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's I-9 to confirm work authorization.

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free