Security Operations Analyst II – Security Compliance Center
At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.
Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.
Security Operations Analyst II – Security Compliance Center
The Expedia Group Security Governance, Risk, Compliance and Privacy (GRCP) organization is building a world‑class Security Compliance Center to support global PCI DSS, SOC 2, NIST, and Privacy compliance operations. We are seeking a highly organized and detail‑oriented Security Compliance Center Analyst to support evidence collection, control testing, documentation, and coordination activities across multiple security and privacy frameworks.
This role is ideal for someone who thrives in a fast‑paced environment, has strong operational discipline, and enjoys working across technical and business teams to help maintain a secure and compliant environment. As part of the India‑based Security Compliance Center, you will play a key role in how we execute day‑to‑day compliance operations and audit readiness tasks.
What you'll do:
· Support operational compliance activities across PCI DSS, SOC 2, NIST CSF, and Privacy frameworks, including gathering evidence and validating control execution.
· Manage and maintain Jira tickets, workflows, and follow‑ups related to compliance tasks, remediation items, and audit requests.
· Collect, review, and document control evidence to ensure accuracy, completeness, and alignment with audit requirements.
· Assist with preparing compliance documentation, including standard operating procedures, control descriptions, and audit artifacts.
· Coordinate with technical teams to obtain required information, clarify requests, and support timely closure of audit‑related actions.
· Participate in internal readiness assessments and support external audits by delivering samples, evidence, and system information.
· Maintain organized repositories of compliance evidence and audit artifacts to support repeatable processes and ongoing compliance.
· Identify gaps and issues in evidence, documentation, or control execution and escalate to the Compliance Center Manager when needed.
· Help track and report status of compliance operational activities, risks, and blockers.
· Contribute to process improvements for evidence collection, documentation quality, and audit efficiency.
· Support ongoing monitoring activities to validate the effectiveness of key IT and security controls.
· Perform additional tasks related to compliance operations as assigned.
Who you are:
· 3–5 years of experience in security compliance, IT audit, or related technical operational roles.
· Experience supporting compliance programs such as PCI DSS, SOC 2, NIST CSF, ISO 27001, or similar frameworks.
· Familiar with cloud technologies and modern IT environments; experience with AWS, and Azure is a plus.
· Strong organizational skills with the ability to manage multiple tasks, deadlines, and evidence requests simultaneously.
· Comfortable working in Jira or similar workflow/ticketing systems; experience managing queues and SLAs is a plus.
· Ability to document processes, controls, and procedures clearly and accurately.
· Strong communication skills and ability to coordinate with both technical and non‑technical partners.
· Able to identify inconsistencies or gaps in evidence and raise issues appropriately.
· Understanding of basic security concepts such as authentication, encryption, logging/monitoring, and network fundamentals is preferred (not required).
· Information security or compliance certification is a plus (e.g., CISA, Security+, ISO 27001 Associate, PCIP).
· Experience with any of the Big 4 is a plus.
· Capable of working with diverse teams and promoting a positive, enterprise‑wide security culture.
· Strong project management, multitasking, and organizational skills required.
Accommodation requests
Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.
About Expedia Group
Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.
Important notice
Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.
Equal Opportunity
Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, gender, sexual orientation, national origin, disability or age.