Expedia Group logo

Security Engineer , Application Security

Expedia Group
NewPosted today

LOCATION

Gurgaon · Onsite

EXPERIENCE

2+ Years

TYPE

FullTime

SKILLS REQUIRED

Application SecuritySecure Coding PracticesThreat ModelingCI/CDAPI SecurityDAST

Job description

Overview

As a Security Engineer-II in Application Security, identify and help remediate application security vulnerabilities across software development and delivery workflows. Partner with engineering and product teams to embed secure-by-design practices throughout the software development lifecycle.

What you'll do

  • Identify, assess, and help remediate application security vulnerabilities across software development and delivery workflows.
  • Partner with engineering and product teams to embed secure-by-design practices throughout the software development lifecycle.
  • Perform security reviews, threat modeling, and risk analysis for applications, services, APIs, and data flows.
  • Integrate, maintain, and continuously improve security tooling and automation across CI/CD pipelines, including SAST, DAST, SCA, dependency scanning, and software supply chain protections.
  • Participate in security design reviews alongside senior engineers.
  • Identify risks in API design, data models, and system architecture, and recommend fixes based on application security principles.
  • Safely integrate and operate AI/ML-enabled solutions that improve application security outcomes.
  • Apply AI/ML concepts to real-world products and workflows.

What you'll need

  • Bachelor’s degree in computer science, information security, engineering, or a related technical field, or equivalent practical experience.
  • 2+ Experience in application security, software engineering, cybersecurity, or a related technical discipline.
  • Familiarity with how vulnerabilities are identified, assessed, and fixed in applications, such as priority based triaging or verifying a fix.
  • Working knowledge of common web and API vulnerabilities, such as OWASP Top 10, and how to prevent them.
  • Ability to read code, identify security issues, and explain them clearly to developers.

Nice to have

  • Hands-on experience identifying vulnerabilities in web applications or APIs through code review, testing tools such as Burp Suite, CTFs, bug bounty programs, or personal projects.
  • Experience writing scripts or small tools to automate an application security task, such as running a scanner in CI/CD, parsing and triaging scan results, or writing a custom SAST rule, such as Semgrep or CodeQL.
  • Exposure to threat modeling or secure design concepts, such as authentication, authorisation, input validation, and data protection.
  • Familiarity with triaging SAST, SCA, or secrets-scanning findings, including telling true positives from false positives.
  • Hands-on experience building AI-powered applications, such as LLM-based tools, agents, or automation workflows, through work, internships, personal projects, or open source.

Details

  • Location: Gurgaon, India.

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

Security Engineer , Application Security