Senior Manager, Threat Detection Engineering
We are building out Expedia's Security and Threat Research team, a proactive and dynamic team construct integrating Cyber Threat Intelligence, Adversary Simulation, Advanced Threat Hunting, and Threat Detection Engineering. This position will contribute to ESTR's research of emerging technologies, develop business use cases by stakeholder, research attack vectors and develop kill chain models, as well as identify security gaps and needs. Specifically, this position will lead a team responsible for developing tailored cyber threat detection analytics, pulled from industry standard frameworks, customized for optimal performance within Expedia’s tech stack.
What you'll do:
Build and manage threat detection engineering program and initiatives
Ensure program success through operational metrics, key performance indicators, and service-level objectives
Work cross functionally across threat intelligence teams to support department initiatives, to include but not limited to threat hunting, adversary simulation, threat actor profiling
Provide support to EG Security teams for high-priority events and department initiatives
Work closely with the Security Engineering and Architecture teams to drive tooling and logging optimization
Who you are:
Proven experience building and managing security engineering programs and teams within security/engineering organization
Comfortable in overseeing a metrics-driven operation with a focus on process optimization and automation
Experience providing technical leadership and guidance, and thinking strategically and analytically to solve problems
Able to work with many cross functional partners and managing programs that require stakeholder support and buy-in
Effective communicator; able to translate technical information to non-technical audience
Extensive experience in creating and tuning threat detection analytics (Yara, Sigma, RegEx, etc.)
Solid understanding of security fundamentals and threat lifecycle, including MITRE ATT&CK framework
Research experience in understanding and analysis of adversary capabilities, infrastructure and techniques
Extensive experience in responding to threats in an organization (SOC, IR, CTI, or similar functions)
Endpoint security logging (Windows, Linux, macOS, and security tools, such as Antivirus/EDR)
Network Security tools and concepts (firewalls, Active Directory, IDS/IPS, proxies, packet analysis, etc.)
Query languages (SQL, MySQL) and development/scripting languages (Python, Perl, Go, etc.)
#LI-AM4
At Expedia Group, we believe in bringing people together and creating an inclusive workplace where everyone belongs and can do their best work. We care about our employees’ safety and wellbeing, so we’re requiring new hires in the U.S. to be fully vaccinated against COVID-19 and present acceptable proof of vaccination before their start date as a condition of employment. Expedia Group will consider requests for a reasonable accommodation as required under applicable law.
About Expedia Group
Expedia Group (NASDAQ: EXPE) powers travel for everyone, everywhere through our global platform. Driven by the core belief that travel is a force for good, we help people experience the world in new ways and build lasting connections. We provide industry-leading technology solutions to fuel partner growth and success, while facilitating memorable experiences for travelers. Expedia Group's family of brands includes: Brand Expedia®, Hotels.com®, Expedia® Partner Solutions, Vrbo®, trivago®, Orbitz®, Travelocity®, Hotwire®, Wotif®, ebookers®, CheapTickets®, Expedia Group™ Media Solutions, Expedia Local Expert®, CarRentals.com™, and Expedia Cruises™.
© 2021 Expedia, Inc. All rights reserved. Trademarks and logos are the property of their respective owners. CST: 2029030-50
Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. This employer participates in E-Verify. The employer will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's I-9 to confirm work authorization.If you need assistance during the recruiting process due to a disability, please reach out to our Recruiting Accommodations Team through the Accommodation Request form. This form is used only by individuals with disabilities who require assistance or adjustments in applying and interviewing for a job. This form is not for inquiring about a position or the status of an application.