American Express Global Business Travel Logo

American Express Global Business Travel

Director, Cyber Defense

Posted 4 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
130K-242K Annually
Expert/Leader
Remote
Hiring Remotely in United States
130K-242K Annually
Expert/Leader
Leads global cyber defense across incident response, threat intelligence, detection engineering, and data security investigations. Sets strategy, budgets, metrics, and operating priorities; manages managers and develops security teams. Directs major incident response, tabletop exercises, threat intelligence programs, SIEM and EDR detection capabilities, automation, and sensitive data investigations. Partners with Legal, Privacy, HR, executives, law enforcement, and external counsel while ensuring compliance with global privacy regulations.
The summary above was generated by AI

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

We're looking for a Director, Cyber Defense to lead the teams that keep our travelers, colleagues, and data safe: Cyber Security Incident Response (CSIRT), Cyber Threat Intelligence (CTI), Detection Engineering, and Data Security Investigations (DSI). This is a hands-on leadership role for someone who has run security operations at scale, knows what good incident command looks like under pressure, and can build detection and intelligence programs that get ahead of threats rather than just reacting to them.

You'll set the strategy for how we detect, investigate, and respond to security incidents and data-handling concerns across a global business. You'll also be a key partner to Legal, Privacy, HR, and executive leadership when incidents touch sensitive data or people. Amex GBT operates in a sector where trust is the product — this role protects that trust.

What You'll Do

Team leadership and strategy

  • Lead and grow four connected teams — CSIRT, CTI, Detection Engineering, and DSI — as one cyber defense function with shared priorities and a common operating rhythm
  • Set the vision, roadmap, and budget for cyber defense capabilities, and report progress and risk to senior leadership
  • Hire, coach, and develop team leads and analysts; build a bench that can operate confidently during high-pressure incidents
  • Define and track metrics that show real progress: dwell time, mean time to detect and respond, investigation closure rates, and intelligence coverage
  • Build strong working relationships with IT, Legal, Privacy, HR, Fraud, and business unit leaders

Incident response (CSIRT)

  • Own the incident response program end to end: playbooks, severity classification, escalation paths, and after-action reviews
  • Act as incident commander (or oversee the commander on rotation) for major security incidents, coordinating technical response with clear communication to executives
  • Run regular tabletop exercises and simulations to test readiness across the company, not just within security
  • Maintain relationships with outside counsel, forensics firms, and law enforcement contacts for incidents that require it

Cyber threat intelligence (CTI)

  • Direct the collection, analysis, and distribution of threat intelligence relevant to our business, our sector, and our travelers
  • Turn intelligence into action: feed indicators and adversary tradecraft directly into detection content and hunting priorities
  • Represent us in relevant intelligence-sharing communities and industry groups, and build vendor and peer relationships that strengthen our visibility
  • Deliver clear, decision-useful threat briefings to technical teams and to executive leadership

Detection engineering

  • Set priorities for detection content development across SIEM, EDR, cloud, and identity systems, mapped to real adversary behavior (MITRE ATT&CK and similar frameworks)
  • Drive continuous tuning to cut down false positives while closing coverage gaps
  • Champion automation and orchestration so the team spends time on judgment calls, not repetitive triage
  • Partner with CTI and CSIRT so that every real incident and every new piece of intelligence turns into better detection

Data Security Investigations (DSI)

  • Lead investigations into potential inappropriate access, use, or disclosure of sensitive data — including privacy cases involving colleagues, contractors, or third parties
  • Build and maintain a defensible investigative process: evidence handling, chain of custody, documentation, and clear findings
  • Work closely with Legal, Privacy, and HR on cases that may carry disciplinary, regulatory, or legal exposure, and know when and how to loop them in
  • Advise on data loss prevention, access controls, and insider risk indicators based on investigation trends
  • Handle every case with the discretion and judgment these situations require, balancing thoroughness with fairness to everyone involved

What We're Looking For

  • 10+ years in cybersecurity, including 5+ years leading incident response, security operations, or a similar function
  • Direct experience running or overseeing sensitive investigations involving data privacy, insider risk, or employee conduct, ideally in partnership with Legal or HR
  • Working knowledge of threat intelligence practices and how intelligence should shape detection priorities
  • Experience with detection engineering concepts: SIEM/EDR content development, use case design, and frameworks like MITRE ATT&CK
  • A track record of leading through live incidents, including clear communication to non-technical executives under pressure
  • Familiarity with privacy and data protection regulations relevant to a global business (for example, GDPR, CCPA, and similar frameworks)
  • Experience managing managers and building teams, not just individual contributors
  • A bachelor's degree in a related field, or equivalent experience

Preferred

  • Experience in travel, hospitality, financial services, or another sector handling large volumes of personal and payment data
  • Relevant certifications such as CISSP, GCIH, GCFA, GCTI, or equivalent
  • Experience with 24/7 or global follow-the-sun security operations models
  • Background working with outside counsel, forensics vendors, or law enforcement on significant incidents

     

Location

United States

     

The US national base salary range for this position is from 

$130,200.00 - $241,800.00

The national range provided includes the base salary that Amex GBT expects to pay for the role.  Actual base salary will be based on factors including the scope and complexity of the role and the successful candidate’s relevant experience, skills, knowledge, and work location.

In addition to base salary, the anticipated range of which is posted above, this role is eligible for a discretionary annual bonus, which rewards participants based on company and individual performance.

For information about our comprehensive US benefits programs and eligibility, please review our Benefits-at-a-Glance document.

Benefits at a glance

The #TeamGBT Experience

Work and life: Find your happy medium at Amex GBT.

  • Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.

  • Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.

  • Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.

  • We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.

  • And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Click Here for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement.

What if I don’t meet every requirement? If you’re passionate about our mission and believe you’d be a phenomenal addition to our team, don’t worry about “checking every box;" please apply anyway. You may be exactly the person we’re looking for!

Similar Jobs

An Hour Ago
In-Office or Remote
275K-350K Annually
Mid level
275K-350K Annually
Mid level
Information Technology • Software • Financial Services • Big Data Analytics
Quantitative Research Engineers at Citadel's GQS develop software solutions, enhance trading systems, and collaborate with researchers to apply quantitative techniques.
Top Skills: C++Linux
2 Hours Ago
Remote or Hybrid
Boston, MA, USA
83K-154K Annually
Mid level
83K-154K Annually
Mid level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Configure and enhance SAP PaPM solutions for finance allocations and month-end close processes. Responsibilities include mapping business requirements, configuring SAP settings, conducting unit and integration testing, troubleshooting defects, documenting specifications, supporting production users, and assisting with implementation, cutover, training, and optimization activities.
Top Skills: AgileSap BwSap Hana SqlSap PapmSap ReportingSap S/4Hana
2 Hours Ago
Easy Apply
Remote
United States
Easy Apply
230K-300K Annually
Senior level
230K-300K Annually
Senior level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Develop and close enterprise business across Texas and surrounding states by prospecting Fortune 1000 companies, building executive relationships, winning RFPs, expanding accounts, exceeding revenue quotas, and delivering consultative value around Motive’s fleet technology platform. The role partners with account teams and technical resources, demonstrates integrations, analyzes customer needs, resolves problems, and provides market feedback.
Top Skills: AICustomer AnalyticsHardware And Software IntegrationsSaaS

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account