Hiring.Camp

Security Engineer II - Threat Detection

Expedia

·

1 week ago

Location
India - Gurgaon
Type
Full-time
Department
Engineering
Experience
2+ years
Closing date
4 days ago
Source
Workday

Description

At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.


Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.

Introduction to the Team:

We are part of the Cyber defense organisation, focused on detecting, analyzing and responding to security threats across the enterprise. Our mission is to proactively identify adversary behavior, strengthen detection capabilities and improve overall security posture.

You will support the design, development and tuning of detection capabilities across SIEM and SOAR platforms. You will work closely with analysts, incident responders and threat hunters to translate threats into actionable detections.

In this role, you will:

  • Design, implement, and maintain security controls and services that protect applications, infrastructure, and data across multiple products and platforms, leveraging strong system design, API design, and data modeling skills.

  • Assist in building and tuning detection rules across SIEM platforms

  • Develop and maintain correlation rules based on known attack patterns

  • Demonstrates understanding of attacker TTPs and how to detect them

  • Contributes to reducing false positives and improving detection quality

  • Document detection logic, use cases and response workflows

  • Map detections to frameworks like MITRE ATT&CK and the Cyber Kill Chain

  • Analyze logs and telemetry to identify suspicious patterns and gaps in detection

  • Participate in detection engineering lifecycle from ideation, development, testing and tuning

  • Collaborate with SOC and Incident Response teams to improve alert fidelity and reduce false positives

  • Assist in threat modeling and contribute to defense in depth strategies

  • Support development of automated workflows and playbooks in SOAR tools

  • Stay updated on emerging threats, attacker techniques and detection strategies

  • Apply familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products to strengthen detection, response, and prevention capabilities across multiple security domains


Experience and Qualifications: 

Minimum Qualifications:

  • Bachelor’s degree in Computer Science, Information Security, related technical field, or equivalent practical experience.

  • 2–5 years of experience in security engineering, software engineering with a security focus, or infrastructure/security operations in cloud-based environments.

  • Experience designing, implementing, and operating security-related services or components (such as authentication/authorization, secrets management, encryption, or security monitoring) with clear ownership for the reliability, performance, and security of those services.

  • Understanding of security frameworks such as MITRE, Cyber Kill Chain

  • Familiarity with SIEM platforms (e.g. Splunk, Sentinel, QRadar), SOAR platforms and automation concept, Log analysis (authentication logs, network logs, endpoint telemetry)

  • Exposure to detection rule creation and tuning, correlation logic and alert engineering and basic scripting (Python, PowerShell or similar)

  • Understanding of network fundamentals (DNS, HTTP, TCP/IP), common attack techniques (phishing, credential theft, lateral movement), defense-in-depth principles

Preferred Qualifications:

  • Exposure to threat intelligence concepts

  • Practical experience integrating or securing AI/ML-enabled systems, such as protecting data pipelines, securing model endpoints, or using AI-driven tools to enhance threat detection and response, while safely integrating and operating AI/ML‑enabled solutions that improve outcomes.

  • Depth in at least one security specialization (such as cloud security, application security, identity and access management, endpoint security, or security automation) combined with the ability to work effectively across multiple technical domains.

  • Familiarity with AI-driven systems, tools, or workflows and applying AI/ML concepts to real world products to enhance security capabilities, such as automated risk analysis, intelligent anomaly detection, or adaptive access controls.

Accommodation requests

Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.


About Expedia Group

Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.


Important notice

Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.


Equal Opportunity

Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, gender, sexual orientation, national origin, disability or age.

Skills

PythonSIEMSOCSplunkTCP/IP

Similar Jobs

30

Security Engineer II

Advantage Solutions · Chicago, IL, US

2 weeks ago

Security Engineer II

Metropolis · Los Angeles, California, United States +4

3 weeks ago

Security Engineer II

Metropolis · New York, New York, United States +4

3 weeks ago

Security Engineer II

Tekion · Bengaluru, Karnataka, India

3 weeks ago

Security Engineer II

Liveperson · Sofia, Bulgaria

1 month ago

Security Engineer II

Remitly is · Seattle, Washington United States, United States of America

1 month ago

Security Engineer II

Remitly is · Seattle, Washington United States, United States of America

1 month ago

Security Engineer II

Expedia · Czech Republic - Prague, Czechia

1 month ago

Security Engineer II

AssetMark is · Atlanta, United States of America +2 · Hybrid

1 month ago

Security Engineer II

Delivery Hero · Barcelona, Spain

2 months ago

Security Engineer II

Garnerhealth · Remote · Remote

2 months ago

Security Engineer II

Relx · USA - Raleigh, NC (RDU), United States of America

2 months ago

Security Engineer II

RELX Jobs · USA - Raleigh, NC (RDU), United States of America

2 months ago

Security Engineer II

Akamai · United States, US · Remote

2 months ago

Security Engineer II

Paragon Technology Group · Scott AFB, IL

2 months ago

Security Engineer II

Thales · Singapore Suntec 2 Temasek Blv · Hybrid

2 months ago

Security Engineer II

Talkdesk · Bengaluru · Onsite

2 months ago

Security Engineer II

Sibros · Remote (Pune, Maharashtra, IN) +1 · Remote

2 months ago

Security Engineer II

Bamboo HR · Utah | Hybrid +1 · Hybrid

3 months ago

Security Engineer II

Greenlight · Bengaluru, Karnataka · Hybrid

3 months ago

Security Engineer II

Lennar · Irving TX (Greenway), United States of America · Hybrid

4 months ago

Security Engineer II

Nshs · NSO 4901 Searle Parkway Corporate Office Skokie, United States of America · Remote, Hybrid, Onsite

5 months ago

Security Engineer II

Humaninterest · United States, Remote +1 · Remote

5 months ago

Security Engineer II, Devices and Services Security

Amazon

Yesterday

Security Engineer II, LOAF - Lifecycle of A Finding

Amazon

Yesterday

Security Engineer II, Security Incident Response Team (SIRT)

Amazon

Yesterday

Security Engineer II - AMZ27587.1

Amazon

Yesterday

Security Engineer II - AMZ27256.1

Amazon

Yesterday

Security Engineer II, Differentiated Security Team (DST)

Amazon

Yesterday

Security Engineer II, Stores Security - HealthCare

Amazon

Yesterday