Expedia

Senior Security Maven (Remote)

New Orleans, Louisiana, United States

Not SpecifiedCompensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Data and Technology, Financial Services, Healthcare, Automotive, Agrifinance, InsuranceIndustries

Senior Security Maven

Employment Type: Full-time Location Type: Remote Salary: Not Specified


Company Description

Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create digital marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to realise their financial goals and help them to save time and money.

We operate across a range of markets, from financial services to healthcare, automotive, agrifinance, insurance, and many more industry segments. We invest in people and new advanced technologies to unlock the power of data and to innovate. A FTSE 100 Index company listed on the London Stock Exchange (EXPN), we have a team of 23,300 people across 32 countries. Our corporate headquarters are in Dublin, Ireland. Learn more at experianplc.com.


Job Description

The Senior Security Maven reports to Experian Health, Product Security. You will work in a team of technologists that focus on the security aspects of our application portfolio. The Product Security team (aka Security Mavens) are responsible for the security of Experian's Health's products, including security by design, vulnerability remediation, and driving special security related programs.

Key Responsibilities:

  • Lead client incident readiness and escalation response and take an ownership in managing the security response for incidents.
  • Lead client incident retrospectives and RCAs by collaborating with engineering, operations, and security teams to identify systemic breakdowns during client or internal incidents.
  • Improve adoption of secure development practices and embed secure-by-design thinking in the SDLC.
  • Accelerate threat modeling, secure code reviews, and initiative-taking security testing tailored to the team's architecture.
  • Escalate organizational misalignments and champion resolutions.
  • Safeguard client data and promote and oversee adherence to data protection standards.
  • Provide risk-based, practical security guidance that aligns with enterprise policies and balances delivery needs.
  • Coordinate technical investigations, interface with client-facing teams, and help summarize messaging that is transparent and accurate.
  • Be a Trusted Security Advisor and serve as the primary security contact for assigned application portfolios and product teams.
  • Partner with application owners to ensure sensitive client data is stored, transmitted, and processed in accordance with regulatory and contractual obligations.
  • Ensure resulting insights from all incidents lead to improvements in controls, data flows, and team processes.
  • Operationalize corporate security Projects and translate central security programs—such as vulnerability management, bug bounty operations, access management, and compliance requirements—into clear implementation plans.
  • Improve communication and agreement by anticipating the downstream impact of security programs and brief department leaders, product teams, and client partners.
  • Mentor and multiply impacts by serving as a senior representative and role model for the Security Mavens program.
  • Mentor junior Mavens and help establish a culture of continuous improvement, knowledge-sharing, and security ownership.

Qualifications

  • Experience directly supporting senior level partners.
  • Certifications such as CISSP, CSSLP, CIPP/US, CISM, CISA, or GCSA (or equivalent experience).
  • 7+ years of experience supporting third-party client audits, privacy assessments, or compliance efforts (HIPAA, SOC2, FedRAMP, HITRUST).
  • 7+ years of experience with frameworks like OWASP, MITRE, and DevSecOps toolchains.

Benefits/Perks

  • Great compensation package and bonus plan.
  • Core benefits including medical, dental, vision, and matching 401K.
  • Flexible work environment, ability to work remote.
  • Flexible time off including volunteer time off, vacation, sick and 12-paid holidays.
  • Explore all our exciting benefits.

Skills

security by design
vulnerability remediation
incident response
secure development practices
threat modeling
secure code reviews
security testing
architecture

Expedia

Travel booking platform for flights, hotels, rentals

About Expedia

Expedia Group operates in the travel industry, offering a wide range of services for travelers and travel-related businesses. It connects users with options for flights, hotels, car rentals, vacation packages, and activities through its various brands, including Expedia, Hotels.com, and Vrbo. Travelers can easily find and book trips that match their preferences and budgets. The company earns revenue primarily through commissions on bookings and advertising from travel service providers looking to promote their offerings. Additionally, Expedia Group supports its partners by providing access to valuable data and technology, helping them improve their operations and grow their businesses. The goal of Expedia Group is to create a seamless travel experience for users while maximizing the potential of its partners.

Bellevue, WashingtonHeadquarters
1996Year Founded
$3,277.3MTotal Funding
IPOCompany Stage
Consumer Goods, EntertainmentIndustries
10,001+Employees

Benefits

Competitive Paid Time Off
Travel Discounts
Healthcare Flexible Spending Accounts
Employee Assistance Program
Wellness & Travel Reimbursement
Workplace Accomodations
Medical, Dental, & Vision Insurance
Matching Gifts
New Parental Benefits

Risks

Riyadh Air's entry could increase competition, affecting Expedia's market share.
CFO transition may lead to strategic shifts impacting financial management and investor confidence.
Expedia's partnerships may strain resources, affecting service quality if not managed well.

Differentiation

Expedia offers a comprehensive suite of travel services under one platform.
The company leverages a diverse portfolio of brands like Hotels.com and Vrbo.
Expedia provides partners with valuable data and technology to optimize their offerings.

Upsides

Expedia can capitalize on the rise of 'workcations' with longer stay packages.
The trend of 'bleisure' travel offers opportunities for specialized leisure-business packages.
Increased demand for personalized travel experiences can enhance user engagement for Expedia.

Land your dream remote job 3x faster with AI