KAYAK operates a metasearch platform that ingests and correlates pricing data from hundreds of third-party travel sites - flights, hotels, rental cars, packages - at a scale of billions of annual queries. That volume turns the infrastructure itself into a threat surface: high-throughput data pipelines, real-time API integrations, and user trust baked into every search result. The attack model spans credential stuffing against user accounts, scraping and data exfiltration from proprietary pricing feeds, and supply-chain risk across the seven travel search brands under the KAYAK umbrella.
Engineering runs across 15 international offices with a hybrid-flexible model, supporting a team of over 800. The company's move into AI-powered tools and conversational search - fronted by products like KAYAK.ai - introduces additional security considerations around prompt injection, model output integrity, and the safe handling of natural-language queries that may surface sensitive booking or payment data.
Culturally, the org signals ownership and fast decision-making. For security practitioners, that means working inside a high-traffic, consumer-facing platform where the blast radius of a misconfiguration or a compromised dependency is measured in millions of users worldwide. The role isn't perimeter defense - it's securing data flows at the intersection of travel, payments, and machine learning.






