Verified today
Security Operations Analyst II, Security Compliance Center
About the role
Security Governance, Risk, Compliance and Privacy (GRCP) organization at Expedia Group builds a world‑class Security Compliance Center to manage PCI DSS, SOC 2, NIST and privacy compliance. The Analyst supports day‑to‑day compliance operations by gathering evidence, managing Jira tickets, documenting controls and coordinating with technical teams for audit readiness. Gurgaon, India, hybrid onsite model (On-site).
What you’ll do
- Support operational compliance activities across PCI DSS, SOC 2, NIST CSF and Privacy frameworks
- Gather and validate evidence, maintain organized repositories of audit artifacts
- Manage Jira tickets, workflows and follow‑ups for compliance tasks
- Prepare compliance documentation, SOPs and audit artifacts
- Coordinate with technical teams to obtain required information
- Assist internal readiness assessments and external audits
- Track and report status of compliance activities, risks and blockers
- Identify gaps in evidence or controls and escalate issues
What you’ll bring
- 3-5 years security compliance or IT audit experience
- Experience with PCI DSS, SOC 2, NIST CSF or similar frameworks
- Familiarity with cloud platforms such as AWS or Azure
- Proficiency with Jira or similar ticketing systems
- Strong organizational and documentation skills
- Effective communication with technical and non‑technical partners
- Understanding of authentication, encryption, logging and network fundamentals (preferred)
- Security or compliance certifications such as CISA, ISO 27001 (preferred)