Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Amex GBT is seeking a Director, Cyber Defense to lead the CSIRT, CTI, Detection Engineering, and Data Security Investigations teams. This executive role sets strategy for detection, investigation, and response to security incidents and data-handling concerns across our global business.
You will partner with Legal, Privacy, HR, and executive leadership and act as a key incident commander during major security events, ensuring trust and safeguarding travelers and colleagues.
United States
Full time
J-84873
Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.
We’re looking for a Director, Cyber Defense to lead the teams that keep our travelers, colleagues, and data safe: Cyber Security Incident Response (CSIRT), Cyber Threat Intelligence (CTI), Detection Engineering, and Data Security Investigations (DSI). This is a hands‑on leadership role for someone who has run security operations at scale, knows what good incident command looks like under pressure, and can build detection and intelligence programs that get ahead of threats rather than just reacting to them.
You’ll set the strategy for how we detect, investigate, and respond to security incidents and data‑handling concerns across a global business. You’ll also be a key partner to Legal, Privacy, HR, and executive leadership when incidents touch sensitive data or people. Amex GBT operates in a sector where trust is the product — this role protects that trust.
Lead and grow four connected teams — CSIRT, CTI, Detection Engineering, and DSI — as one cyber defense function with shared priorities and a common operating rhythm
Set the vision, roadmap, and budget for cyber defense capabilities, and report progress and risk to senior leadership
Hire, coach, and develop team leads and analysts; build a bench that can operate confidently during high‑pressure incidents
Define and track metrics that show real progress: dwell time, mean time to detect and respond, investigation closure rates, and intelligence coverage
Build strong working relationships with IT, Legal, Privacy, HR, Fraud, and business unit leaders
Own the incident response program end to end: playbooks, severity classification, escalation paths, and after‑action reviews
Act as incident commander (or oversee the commander on rotation) for major security incidents, coordinating technical response with clear communication to executives
Run regular tabletop exercises and simulations to test readiness across the company, not just within security
Maintain relationships with outside counsel, forensics firms, and law enforcement contacts for incidents that require it
Direct the collection, analysis, and distribution of threat intelligence relevant to our business, our sector, and our travelers
Turn intelligence into action: feed indicators and adversary tradecraft directly into detection content and hunting priorities
Represent us in relevant intelligence‑sharing communities and industry groups, and build vendor and peer relationships that strengthen our visibility
Deliver clear, decision‑useful threat briefings to technical teams and to executive leadership
Set priorities for detection content development across SIEM, EDR, cloud, and identity systems, mapped to real adversary behavior (MITRE ATT&CK and similar frameworks)
Drive continuous tuning to cut down false positives while closing coverage gaps
Champion automation and orchestration so the team spends time on judgment calls, not repetitive triage
Partner with CTI and CSIRT so that every real incident and every new piece of intelligence turns into better detection
Lead investigations into potential inappropriate access, use, or disclosure of sensitive data — including privacy cases involving colleagues, contractors, or third parties
Build and maintain a defensible investigative process: evidence handling, chain of custody, documentation, and clear findings
Work closely with Legal, Privacy, and HR on cases that may carry disciplinary, regulatory, or legal exposure, and know when and how to loop them in
Advise on data loss prevention, access controls, and insider risk indicators based on investigation trends
Handle every case with the discretion and judgment these situations require, balancing thoroughness with fairness to everyone involved
10+ years in cybersecurity, including 5+ years leading incident response, security operations, or a similar function
Direct experience running or overseeing sensitive investigations involving data privacy, insider risk, or employee conduct, ideally in partnership with Legal or HR
Working knowledge of threat intelligence practices and how intelligence should shape detection priorities
Experience with detection engineering concepts: SIEM/EDR content development, use case design, and frameworks like MITRE ATT&CK
A track record of leading through live incidents, including clear communication to non‑technical executives under pressure
Familiarity with privacy and data protection regulations relevant to a global business (for example, GDPR, CCPA, and similar frameworks)
Experience managing managers and building teams, not just individual contributors
A bachelor's degree in a related field, or equivalent experience
Experience in travel, hospitality, financial services, or another sector handling large volumes of personal and payment data
Relevant certifications such as CISSP, GCIH, GCFA, GCTI, or equivalent
Experience with 24/7 or global follow‑the‑sun security operations models
Background working with outside counsel, forensics vendors, or law enforcement on significant incidents
United States
The US national base salary range for this position is from
$130,200.00 - $241,800.00
The national range provided includes the base salary that Amex GBT expects to pay for the role. Actual base salary will be based on factors including the scope and complexity of the role and the successful candidate’s relevant experience, skills, knowledge, and work location.
In addition to base salary, the anticipated range of which is posted above, this role is eligible for a discretionary annual bonus, which rewards participants based on company and individual performance.
For information about our comprehensive US benefits programs and eligibility, please review our Benefits-at-a-Glance document.
Benefits at a glance (https://experience100.ehr.com/LinkClick.aspx?fileticket=CjACTXO3wMk%3d&portalid=66)
Work and life: Find your happy medium at Amex GBT.
Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.
Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.
Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.
We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.
And much more!
All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.
Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement (https://www.amexglobalbusinesstravel.com/gbt-recruitment-privacy-statement/).
What if I don’t meet every requirement? If you’re passionate about our mission and believe you’d be a phenomenal addition to our team, don’t worry about “checking every box;\