American Express Global Business Travel Logo

American Express Global Business Travel

Director, Cyber Defense

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
130K-242K Annually
Expert/Leader
Remote
Hiring Remotely in United States
130K-242K Annually
Expert/Leader
Leads global cyber defense across incident response, threat intelligence, detection engineering, and data security investigations. Sets strategy, budgets, metrics, and operating priorities; manages managers and develops security teams. Directs major incident response, tabletop exercises, threat intelligence programs, SIEM and EDR detection capabilities, automation, and sensitive data investigations. Partners with Legal, Privacy, HR, executives, law enforcement, and external counsel while ensuring compliance with global privacy regulations.
The summary above was generated by AI

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

We're looking for a Director, Cyber Defense to lead the teams that keep our travelers, colleagues, and data safe: Cyber Security Incident Response (CSIRT), Cyber Threat Intelligence (CTI), Detection Engineering, and Data Security Investigations (DSI). This is a hands-on leadership role for someone who has run security operations at scale, knows what good incident command looks like under pressure, and can build detection and intelligence programs that get ahead of threats rather than just reacting to them.

You'll set the strategy for how we detect, investigate, and respond to security incidents and data-handling concerns across a global business. You'll also be a key partner to Legal, Privacy, HR, and executive leadership when incidents touch sensitive data or people. Amex GBT operates in a sector where trust is the product — this role protects that trust.

What You'll Do

Team leadership and strategy

  • Lead and grow four connected teams — CSIRT, CTI, Detection Engineering, and DSI — as one cyber defense function with shared priorities and a common operating rhythm
  • Set the vision, roadmap, and budget for cyber defense capabilities, and report progress and risk to senior leadership
  • Hire, coach, and develop team leads and analysts; build a bench that can operate confidently during high-pressure incidents
  • Define and track metrics that show real progress: dwell time, mean time to detect and respond, investigation closure rates, and intelligence coverage
  • Build strong working relationships with IT, Legal, Privacy, HR, Fraud, and business unit leaders

Incident response (CSIRT)

  • Own the incident response program end to end: playbooks, severity classification, escalation paths, and after-action reviews
  • Act as incident commander (or oversee the commander on rotation) for major security incidents, coordinating technical response with clear communication to executives
  • Run regular tabletop exercises and simulations to test readiness across the company, not just within security
  • Maintain relationships with outside counsel, forensics firms, and law enforcement contacts for incidents that require it

Cyber threat intelligence (CTI)

  • Direct the collection, analysis, and distribution of threat intelligence relevant to our business, our sector, and our travelers
  • Turn intelligence into action: feed indicators and adversary tradecraft directly into detection content and hunting priorities
  • Represent us in relevant intelligence-sharing communities and industry groups, and build vendor and peer relationships that strengthen our visibility
  • Deliver clear, decision-useful threat briefings to technical teams and to executive leadership

Detection engineering

  • Set priorities for detection content development across SIEM, EDR, cloud, and identity systems, mapped to real adversary behavior (MITRE ATT&CK and similar frameworks)
  • Drive continuous tuning to cut down false positives while closing coverage gaps
  • Champion automation and orchestration so the team spends time on judgment calls, not repetitive triage
  • Partner with CTI and CSIRT so that every real incident and every new piece of intelligence turns into better detection

Data Security Investigations (DSI)

  • Lead investigations into potential inappropriate access, use, or disclosure of sensitive data — including privacy cases involving colleagues, contractors, or third parties
  • Build and maintain a defensible investigative process: evidence handling, chain of custody, documentation, and clear findings
  • Work closely with Legal, Privacy, and HR on cases that may carry disciplinary, regulatory, or legal exposure, and know when and how to loop them in
  • Advise on data loss prevention, access controls, and insider risk indicators based on investigation trends
  • Handle every case with the discretion and judgment these situations require, balancing thoroughness with fairness to everyone involved

What We're Looking For

  • 10+ years in cybersecurity, including 5+ years leading incident response, security operations, or a similar function
  • Direct experience running or overseeing sensitive investigations involving data privacy, insider risk, or employee conduct, ideally in partnership with Legal or HR
  • Working knowledge of threat intelligence practices and how intelligence should shape detection priorities
  • Experience with detection engineering concepts: SIEM/EDR content development, use case design, and frameworks like MITRE ATT&CK
  • A track record of leading through live incidents, including clear communication to non-technical executives under pressure
  • Familiarity with privacy and data protection regulations relevant to a global business (for example, GDPR, CCPA, and similar frameworks)
  • Experience managing managers and building teams, not just individual contributors
  • A bachelor's degree in a related field, or equivalent experience

Preferred

  • Experience in travel, hospitality, financial services, or another sector handling large volumes of personal and payment data
  • Relevant certifications such as CISSP, GCIH, GCFA, GCTI, or equivalent
  • Experience with 24/7 or global follow-the-sun security operations models
  • Background working with outside counsel, forensics vendors, or law enforcement on significant incidents

     

Location

United States

     

The US national base salary range for this position is from 

$130,200.00 - $241,800.00

The national range provided includes the base salary that Amex GBT expects to pay for the role.  Actual base salary will be based on factors including the scope and complexity of the role and the successful candidate’s relevant experience, skills, knowledge, and work location.

In addition to base salary, the anticipated range of which is posted above, this role is eligible for a discretionary annual bonus, which rewards participants based on company and individual performance.

For information about our comprehensive US benefits programs and eligibility, please review our Benefits-at-a-Glance document.

Benefits at a glance

The #TeamGBT Experience

Work and life: Find your happy medium at Amex GBT.

  • Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.

  • Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.

  • Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.

  • We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.

  • And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Click Here for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement.

What if I don’t meet every requirement? If you’re passionate about our mission and believe you’d be a phenomenal addition to our team, don’t worry about “checking every box;" please apply anyway. You may be exactly the person we’re looking for!

Similar Jobs

52 Minutes Ago
Remote or Hybrid
Mid level
Mid level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Provides technology consulting and implementation services for clients. Responsibilities include resolving complex IT issues, assessing Microsoft and cloud environments, documenting technology roadmaps and security reviews, leading maintenance discussions, identifying risks and modernization opportunities, developing recommendations, and managing project scope, budgets, timelines, and client communications. The role requires client interaction, occasional travel, and expertise across Microsoft Azure, Active Directory, networking, servers, security, and virtualized environments.
Top Skills: Active DirectoryAntivirusAzure Active DirectoryCloud ApplicationsEndpoint DevicesFirewallsLocal NetworksMicrosoft 365AzureServersSharepointSwitchesVirtualization
52 Minutes Ago
Remote or Hybrid
Mid level
Mid level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Develops and implements consultative and technical IT solutions for clients. Responsibilities include level-three escalation support, Microsoft and cloud environment assessments, security reviews, technology roadmaps, risk and modernization recommendations, project scoping and budgeting, and client communication. The role requires coordinating technical resolutions, managing multiple projects, and traveling approximately 15% to client locations in Pennsylvania.
Top Skills: Active DirectoryAntivirusAzure Active DirectoryCloud ApplicationsEndpoint DevicesFirewallsLocal NetworksMicrosoft 365AzureServersSharepointSwitchesVirtualized Environments
53 Minutes Ago
Remote or Hybrid
66K-89K Annually
Mid level
66K-89K Annually
Mid level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Provides regulatory compliance consulting to financial services clients, including risk assessments, remediation, monitoring, regulatory research, change management, education, reporting, compliance system development, gap analysis, board presentations, and federal consumer compliance testing. Requires banking compliance experience, audit documentation expertise, lending knowledge, strong communication and analytical skills, and approximately 20% U.S. travel.

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account