Director, Cyber Defense & Incident Response

American Express Global Business Travel

Boston (MA)

On-site

USD 130,000 - 242,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Flexible benefits
Travel perks
Learning & development

Job summary

American Express Global Business Travel seeks a Director of Cyber Defense to lead CSIRT, CTI, Detection Engineering, and DSI. You will set strategy, see incidents through end-to-end, and partner with Legal, Privacy, and HR on sensitive cases.

The role requires 10+ years in cybersecurity and a track record of leading through major incidents. You will report to senior leadership, build a strong team, and drive metrics like dwell time and MTTD to strengthen threat visibility across a global

Qualifications

  • 10+ years in cybersecurity, including 5+ years leading incident response, security operations, or a similar function.
  • Direct experience running or overseeing sensitive investigations involving data privacy, insider risk, or employee conduct, ideally in partnership with Legal or HR
  • Working knowledge of threat intelligence practices and how intelligence should shape detection priorities
  • Experience with detection engineering concepts: SIEM/EDR content development, use case design, and frameworks like MITRE ATT&CK
  • A track record of leading through live incidents, including clear communication to non-technical executives under pressure
  • Familiarity with privacy and data protection regulations relevant to a global business (e.g., GDPR, CCPA)
  • Experience managing managers and building teams, not just individual contributors
  • A bachelor's degree in a related field, or equivalent experience

Responsibilities

  • Lead and grow four cyber defense teams — CSIRT, CTI, Detection Engineering, and DSI — as one cyber defense function with shared priorities and a common operating rhythm
  • Set the vision, roadmap, and budget for cyber defense capabilities, and report progress and risk to senior leadership
  • Hire, coach, and develop team leads and analysts; build a bench that can operate confidently during high-pressure incidents
  • Define and track metrics that show real progress: dwell time, mean time to detect and respond, investigation closure rates, and intelligence coverage
  • Build strong working relationships with IT, Legal, Privacy, HR, Fraud, and business unit leaders
  • Own the incident response program end to end: playbooks, severity classification, escalation paths, and after-action reviews
  • Act as incident commander (or oversee the commander on rotation) for major security incidents, coordinating technical response with clear communication to executives
  • Run regular tabletop exercises and simulations to test readiness across the company, not just within security
  • Maintain relationships with outside counsel, forensics firms, and law enforcement contacts for incidents that require it
  • Direct the collection, analysis, and distribution of threat intelligence relevant to our business, our sector, and our travelers
  • Turn intelligence into action: feed indicators and adversary tradecraft directly into detection content and hunting priorities
  • Represent us in relevant intelligence-sharing communities and industry groups, and build vendor and peer relationships that strengthen our visibility
  • Deliver clear, decision-useful threat briefings to technical teams and to executive leadership
  • Set priorities for detection content development across SIEM, EDR, cloud, and identity systems, mapped to real adversary behavior
  • Drive continuous tuning to cut down false positives while closing coverage gaps
  • Champion automation and orchestration so the team spends time on judgment calls, not repetitive triage
  • Partner with CTI and CSIRT so that every real incident and every new piece of intelligence turns into better detection
  • Lead investigations into potential inappropriate access, use, or disclosure of sensitive data — including privacy cases involving colleagues, contractors, or third parties
  • Build and maintain a defensible investigative process: evidence handling, chain of custody, documentation, and clear findings
  • Work closely with Legal, Privacy, and HR on cases that may carry disciplinary, regulatory, or legal exposure
  • Advise on data loss prevention, access controls, and insider risk indicators based on investigation trends

Skills

Cybersecurity
Incident response leadership
Security operations
Threat intelligence
Team leadership
Budget planning
Stakeholder communication

Education

Bachelor's degree

Tools

SIEM/EDR
MITRE ATT&CK

Job description

American Express Global Business Travel seeks a Director of Cyber Defense to lead CSIRT, CTI, Detection Engineering, and DSI. You will set strategy, see incidents through end-to-end, and partner with Legal, Privacy, and HR on sensitive cases.

The role requires 10+ years in cybersecurity and a track record of leading through major incidents. You will report to senior leadership, build a strong team, and drive metrics like dwell time and MTTD to strengthen threat visibility across a global

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Cyber Defense & Threat Intelligence
Director of Cyber Defense & Threat Intelligence

American Express Global Business Travel • Denver (CO)

On-site
USD 130,000 - 242,000
Chief Cyber Defense & Incident Response
Chief Cyber Defense & Incident Response

American Express Global Business Travel • Des Moines (IA)

On-site
USD 130,000 - 242,000
Director, Cyber Defense & Incident Response
Director, Cyber Defense & Incident Response

American Express Global Business Travel • Harrisburg

On-site
USD 130,000 - 242,000
Flexible benefits
Travel perks
Learning platform access
+1
Director, Global Cyber Defense & Incident Response
Director, Global Cyber Defense & Incident Response

American Express • United States

Remote
USD 130,000 - 242,000
Discretionary bonus
Travel perks
Learning platform access
+1
Global Director, Cyber Defense & Incident Response
Global Director, Cyber Defense & Incident Response

American Express Global Business Travel • Northern (KY)

Hybrid
USD 130,000 - 242,000
Global Cyber Defense Director & Incident Response
Global Cyber Defense Director & Incident Response

American Express Global Business Travel • Columbia (SC)

On-site
USD 130,000 - 242,000
Travel perks
Flexible benefits
Learning platform access
+1
Director of Cyber Defense & Incident Response
Director of Cyber Defense & Incident Response

American Express Global Business Travel • New York (NY)

On-site
USD 130,000 - 242,000
Health and retirement benefits
Travel perks
Learning & development platform access
+1
Director of Cybersecurity & Agentic AI
Director of Cybersecurity & Agentic AI

American Express • Atlanta (GA)

On-site
USD 180,000 - 240,000
Senior Cyber Threat Engineer — Lead & Innovate
Senior Cyber Threat Engineer — Lead & Innovate

American Express • Saint Paul (MN)

On-site
USD 27,552 - 41,328
Professional development
Leadership opportunities
Cyber Security Engineer — Cloud & Threat Defense
Cyber Security Engineer — Cloud & Threat Defense

American Express Global Business Travel • United States

On-site
USD 104,000 - 194,000
Health insurance
Retirement plan
Parental leave
+2