At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.
Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.
Introduction to the Team:
The Expedia Group Security Governance, Risk, Compliance and Privacy organization is evolving its technical GRC capability to better align roles to engineering, automation, and scalable compliance outcomes.
We are seeking a highly motivated, collaborative, and technically strong Senior Security Operations Manager – GRCP Automation to serve as a senior individual contributor focused on GRC engineering, AI and automation enablement, and scalable compliance operations. This role will help design, build, and mature automated approaches for control evaluation, evidence collection, compliance workflows, and policy-to-technology traceability across security and privacy programs.
This is a manager-level individual contributor role, intended for a practitioner who leads through technical depth, influence, and execution rather than direct people management. The role is ideal for someone who can partner across engineering, architecture, product, legal, and audit teams to reduce manual compliance effort, improve control reliability, and embed compliance-by-design into systems and processes.
In this role, you will:
Lead the design and maturation of compliance automation capabilities across security and privacy domains, with emphasis on reducing manual evidence gathering, improving control observability, and scaling assurance activities across multiple frameworks.
Drive technical implementation and optimization of GRC platforms, workflows, integrations, and data models to support compliance operations and measurable control outcomes.
Partner with engineering, security architecture, product, and business teams to translate regulatory and policy requirements into technical control objectives, automated validations, and durable operating processes.
Build and enhance automated approaches for continuous control monitoring, readiness assessments, evidence collection, issue tracking, and remediation reporting across applicable compliance programs.
Identify opportunities to use AI and automation responsibly to improve compliance workflows, risk analysis, control mapping, and operational efficiency while maintaining strong governance and defensible outcomes.
Develop metrics, dashboards, and reporting that provide leadership with clear visibility into compliance posture, control health, automation coverage, and remediation progress.
Serve as a senior technical advisor on compliance-by-design, secure-by-design, and privacy-by-design patterns for systems, applications, data flows, and emerging capabilities.
Evaluate control effectiveness, identify design or implementation gaps, and work with technical owners to define pragmatic remediation strategies or compensating controls.
Partner with internal and external auditors on control walkthroughs, technical evidence strategies, and automated methods for demonstrating compliance at scale.
Promote standardization across GRC processes, tooling, and data to improve consistency, reduce duplication, and create a more scalable operating model for Digital Compliance.
Stay current on evolving regulatory expectations, security and privacy frameworks, and technology trends that impact compliance automation, AI governance, and technical assurance.
Experience and Qualifications:
Minimum Qualifications:
Bachelor’s degree in a relevant field such as law, information security, computer science, information systems, or a related discipline, or equivalent practical experience.
8+ years of experience in security, privacy, risk, compliance, governance engineering, or a related technical program role, including meaningful experience designing or operating scalable compliance or control processes.
Proven experience as a senior individual contributor in a technical GRC, security engineering, compliance engineering, or control automation capacity.
Strong knowledge of security and compliance frameworks such as NIST, ISO 27xxx, PCI DSS, SOC 2, and privacy requirements, with the ability to map obligations to technical controls and operational evidence.
Demonstrated experience with GRC platforms and supporting technologies, including platform configuration, workflow design, integrations, and reporting.
Strong technical fluency across areas such as cloud environments, application security, identity and access management, logging and monitoring, data protection, and control implementation patterns.
Experience using automation and scripting to streamline security and compliance processes; familiarity with technologies such as SQL, Python, PowerShell, or similar tooling is strongly preferred.
Ability to analyze complex systems, reverse engineer workflows where needed, and translate technical realities into compliance narratives, control designs, and actionable remediation plans.
Excellent communication, stakeholder management, and influencing skills, with the ability to work effectively across technical and non-technical teams and drive outcomes without direct authority.
Experience building metrics and using data to inform decisions, track progress, and demonstrate program maturity is strongly preferred.
Relevant certifications such as CISSP, CISM, CISA, CRISC, GRCP, PCIP, or comparable credentials are preferred.
Preferred Qualifications:
Experience designing continuous controls monitoring or engineering-led compliance evidence strategies in cloud-native environments.
Experience partnering closely with engineering organizations to build scalable, automated compliance capabilities rather than relying primarily on manual assessment methods.
Safely integrates and operates AI/ML‑enabled solutions that improve outcomes, such as enhanced monitoring, automated controls testing, or intelligent risk detection in digital environments.
Advanced experience applying AI/ML concepts to assess, manage, and mitigate compliance risks within complex technical ecosystems, including governance of AI-driven products and workflows
Accommodation requests
Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.
About Expedia Group
Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.
Important notice
Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.
Equal Opportunity
Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, gender, sexual orientation, national origin, disability or age.