Overview
As Principal Security Engineer, you will provide deep security expertise across applications, infrastructure, networks, cloud environments, and security platforms. You’ll translate security strategy and regulatory requirements into practical, scalable solutions and act as a trusted advisor to engineering, architecture, and product teams. You’ll review architectures, lead threat modeling, and drive secure design and implementation across the full stack. Your work will help ensure secure, compliant systems at scale in a complex, distributed environment. This role offers the chance to shape Travelport’s security posture while partnering with cross-functional teams to deliver impactful, trusted,
Responsibilities
- Serve as a senior security expert across application, network, cloud, and infrastructure security
- Partner with engineering and architecture to develop secure environments
- Translate security principles into practical implementations
- Participate in architecture and design reviews for new applications and platforms
- Identify security risks in proposed architectures and craft pragmatic solutions
- Apply security best practices to web apps, APIs, microservices, and cloud-native architectures
- Perform technical threat modeling and security design assessments
- Escalate complex security engineering and architecture issues
- Provide deep expertise in Identity and Access Management (IAM) technologies and platforms
- Review cloud environments for adherence to security standards and best practices
- Support PCI DSS and other security compliance programs
- Interpret PCI DSS requirements into practical controls and guidance
- Design and validate network segmentation and scope-reduction strategies for PCI environments
- Collaborate with governance, risk, and compliance teams to satisfy security controls
- Support security assessments, evidence gathering, remediation, and engagements with assessors
- Evaluate compensating controls and alternative approaches when standard patterns are impractical
- Mentor security engineers and lead cross-functional security initiatives
- Communicate complex security topics to technical and non-technical stakeholders
Key requirements
- 10+ years of progressive experience in cybersecurity and related disciplines
- Senior or principal-level experience solving cross-domain security problems
- Deep knowledge of networking and network security
- Experience designing network segmentation in PCI DSS environments
- Strong experience with IAM including OAuth 2.0, OIDC, SAML, federation, SSO
- Hands-on with Okta and/or Auth0
- Experience securing workforce IAM, CIAM, APIs, and service-to-service authentication
- Experience with Akamai WAF or similar edge security platforms
- Strong knowledge of PCI-DSS and supporting compliance activities
- Strong knowledge of AWS security (IAM, VPC, encryption, logging, monitoring)
- Experience applying security best practices to web apps, APIs, microservices, distributed systems, cloud-native architectures
- Understanding of CI/CD, DevSecOps, secure SDLC, IaC, and automated security testing
- Knowledge of common app and API vulnerabilities and mitigations
- Experience conducting security design reviews, risk assessments, and threat modeling
- Ability to troubleshoot complex security issues across apps, identity, networking, cloud, and security platforms
- Strong written and verbal communication skills to explain complex topics to diverse audiences
- strong communication
- collaboration
- mentorship
- IAM technologies and platforms
- OAuth 2.0, OIDC, SAML, federation, SSO
- Okta, Auth0
…
