About the Role
The Sr. Cybersecurity Engineer is a newly defined role that fuses two disciplines that the hospitality technology industry can no longer treat as separate domains: Artificial Intelligence and Cybersecurity. At their intersection lies the defining competitive and existential challenge of deploying AI to transform guest experience and operational efficiency while defending against the increasingly AI-weaponized threat landscape targeting hotels, resorts, clubs, restaurant venues and the platforms that power them.The chosen candidate will be a dual-domain expert who builds and governs both disciplines with equal depth and authority. The person in this seat will directly architect AI platforms and applications that will be offered to our hospitality clients as part of our technology product suite, while simultaneously owning the security infrastructure, threat defense posture, and incident response capability that protects those products and the properties that utilize them.This role requires up to 35% travel — property visits, vendor summits, industry conferences.
Role Overview
- AI Leadership & Product Creation: Own the end-to-end AI strategy: research, platform architecture, model development, productization, and deployment of AI capabilities into hospitality support and operations. The CAISO must be a practitioner who can sit at a workbench and build — not only a strategist who commissions others to do so.
- Cybersecurity Defense & Resilience: Architect and operate a cybersecurity program, purpose-built for the hospitality technology threat landscape. Candidate must have exposure to knowledge of major industry breaches and understand hardening against the attack vectors proven to succeed against hotel brands, loyalty programs, PMS environments, and third‑party platform ecosystems.
- Convergence of AI and Security Operations: Unify the two disciplines operationally: AI-powered security operations that detect and respond faster; security guardrails embedded into every AI platform the company builds; governance frameworks that treat AI risk and cyber risk as a single, integrated discipline.
- Hospitality Technology Domain Mastery: Bring irreplaceable, hard‑won expertise in the specific technology stack of the hospitality industry; PMS, POS, BMS, EMS, access control, VoIP, WiFi, and the dense vendor ecosystem around them, such that every AI and security decision is grounded in operational reality, not generalized enterprise IT theory.
Key Responsibilities
AI Strategy, Platform Development & Product Innovation
- Define and execute the company's comprehensive AI strategy across both internal operations and customer‑facing hospitality technology products.
- Have knowledge and ability to integrate the use of AI platforms including:
- Guest personalization and recommendation engines using ML/NLP.
- AI‑powered revenue management and dynamic pricing systems.
- Natural language virtual concierge and guest‑voice platforms.
- Predictive maintenance and IoT anomaly detection systems.
- AI‑driven energy management optimization within BMS/EMS environments.
- Generative AI content and marketing automation tools for hospitality operators.
- Establish AI product testing and governance: data sourcing, validation, deployment, monitoring.
- Integrate AI platforms with legacy hospitality systems (PMS, POS, CRM, channel managers) via secure API architectures — managing the security implications of cloud‑native, API‑heavy deployment models.
- Champion ethical AI practices: algorithmic bias auditing, explainability requirements, transparent data consent frameworks, and alignment with emerging AI regulation.
- Represent the company as an AI thought leader at industry events (HITEC), in client engagements, and in the press.
Cybersecurity Architecture, Operations & Incident Response
- Design, own, and continuously evolve a hospitality‑specific cybersecurity program aligned with NIST CSF 2.0, PCI‑DSS v4.0, GDPR, CCPA, HIPAA (wellness/F&B contexts), SOC 2 Type II, and FTC cybersecurity guidance.
- Develop standards for regular threat modeling across the full hospitality technology surface: PMS, POS, BMS, EMS, access control, VoIP, WiFi, IoT guest‑room devices, and third‑party integrations.
- Develop and rehearse incident response runbooks specifically calibrated to hospitality attack scenarios:
- Ransomware impacting reservations, payment processing, and digital room key systems simultaneously.
- Social engineering via helpdesk impersonation targeting IT admin credentials.
- Third‑party platform supply‑chain compromise cascading across multiple hotel brands.
- Loyalty program database breach and ransom demand.
- Lead post‑breach root‑cause analysis and produce reporting on cyber risk posture, incident timelines, and remediation status.
Hospitality Technology Platform Security
- Own the security architecture and hardening program for the full hospitality technology stack:
- Hospitality VoIP: SIP trunk security, SRTP/TLS enforcement, toll fraud detection, CDR anomaly monitoring.
- Guest & Enterprise WiFi: SSID segmentation, WPA3‑Enterprise / 802.1X, captive portal hardening, rogue AP detection, NAC integration.
- Enforce network segmentation between guest‑facing, operational, and corporate systems.
- Direct security assessment and onboarding of all hospitality technology vendors — OTA connectivity platforms, CRS providers, and AI tool vendors.
AI‑Security Convergence — The Unified Discipline
- Build and operate AI‑augmented security operations: AI‑assistant SOC workflows, automated phishing and anomaly detection, and predictive threat intelligence tuned to hospitality attack patterns.
- Embed security‑by‑design into every AI platform the company builds: secure training data pipelines, model access controls, inference endpoint protection, and prompt injection defense for LLM‑based products.
- Govern AI‑specific threat vectors unique to the hospitality sector:
- AI‑generated deepfake voice and video used to impersonate guests or executives in social engineering attacks.
- Develop unified reporting that presents AI risk and cyber risk as an integrated posture - eliminating the organizational blind spot created by treating them separately.
Network Infrastructure & Firewall Implementation
- Directly configure, manage, and validate enterprise‑grade firewall environments — policy creation, NAT/PAT, zone‑based segmentation, IDS/IPS tuning, and vendor integration on platforms including Palo Alto Networks (PAN-OS), Fortinet FortiGate or equivalent. This role requires direct implementation capability, not oversight only.
- Lead zero‑trust network architecture design for multi‑property hotel environments with high guest throughput and complex vendor connectivity requirements.
- Oversee secure WiFi architecture including RF site surveys, frequency planning, WPA3 deployment, RADIUS/802.1X integration, and RF interference mitigation in high‑density hospitality environments.
- Manage SIEM deployment (Splunk, Microsoft Sentinel, IBM QRadar, or equivalent) with custom correlation rules covering PMS, POS, physical access control, and IoT event sources.
- Own vulnerability management lifecycle: scanning, CVSS prioritization, patch SLA enforcement, and penetration testing programs with dedicated OT/IoT asset coverage.
- Deploy and manage VPN and zero‑trust network access (ZTNA) for property‑to‑corporate connectivity and remote management of distributed hospitality environments.
Product Development & Engineering Partnership
- Partner with engineering in design and code review of hospitality technology products — applying secure‑by‑design and DevSecOps principles from architecture through release.
- Apply direct development knowledge to review architecture proposals, audit application code, contribute to security libraries, and identify vulnerabilities before production deployment.
- Drive security integration into CI/CD pipelines: SAST, DAST, SCA tooling, container scanning, and secrets management.
- Contribute to and own the roadmap for AI‑powered hospitality product features — participating not only as a security reviewer, but as a co‑creator with direct technical contributions.
Compliance, Regulatory & Data Governance
- Maintain comprehensive compliance programs: PCI‑DSS v4.0, GDPR, CCPA, HIPAA, SOC 2 Type II, and emerging AI regulatory frameworks (EU AI Act, NIST AI RMF, ISO/IEC 42001).
- Serve as executive point of contact for regulatory audits, external penetration tests and cyber insurance underwriting.
- Monitor and shape company response to the evolving FTC cybersecurity guidance affecting the hospitality industry.
Executive Leadership, Culture & Talent
- Build and lead a converged AI & Security organization — defining team structure across AI engineering, cybersecurity operations, IT infrastructure, and data governance.
- Establish and chair a Technology Risk & AI Ethics committee with cross‑functional representation from Property Operations, Legal, Product, and Finance.
- Design hospitality‑specific security awareness programs: social engineering via helpdesk impersonation, front‑desk phishing, AI deepfake briefings for property managers, POS handling, and credential hygiene.
- Champion a security and AI governance culture that is enabling rather than obstructive — communicating requirements as business accelerators in a guest‑experience‑first industry.
- Represent the company at board level on both AI opportunity and cyber risk — translating deeply technical disciplines into business‑relevant executive narratives.
Required Qualifications
Education
- Master's Degree in Technical Science, Artificial Intelligence, Information Security, Data Science, or a closely related technical discipline from an accredited institution. (Required)
- Active continuing education in both AI disciplines and cybersecurity — certifications, graduate coursework, conference participation, or equivalent — maintained throughout career. (Required)
Experience Requirements
- 7+ Years — Direct hospitality technology and cybersecurity experience within the MSP hospitality sector:
- Hands‑on securing of PMS, POS, BMS, EMS, access control, VoIP, and WiFi platforms in live hospitality environments.
- Proven track record responding to or preventing cybersecurity incidents specific to the hospitality threat landscape: POS breaches, ransomware, social engineering via helpdesk impersonation, loyalty data exfiltration, third‑party platform compromise.
- 5+ Years — Direct AI discipline experience: creation, training, deployment, and lifecycle management. Hands‑on practitioner capability is mandatory.
- Direct implementation of AI platforms within hospitality operations in prior roles; this is a hard requirement. Candidates must cite specific implementations, the business problem addressed, the technical architecture, and measurable outcomes.
- Experience governing AI tool adoption: vendor evaluation, training data governance, bias auditing, model monitoring, and incident response for model failures.
Preferred Qualifications
- Hospitality WiFi & RF Disciplines: hands‑on RF site survey experience; 2.4 / 5 / 6 GHz band planning; co‑channel and adjacent‑channel interference mitigation in high‑density hotel environments; 802.11ax (Wi‑Fi 6/6E) deployment; DAS and in‑building cellular management.
- Development & Coding Proficiency: working knowledge in Python, JavaScript/Node.js, Go, C#, SQL, or Bash. The ability to write security automation, audit application code, or contribute directly to AI platform development is a meaningful differentiator as the company builds proprietary hospitality products.
- AI Ethics & Governance Credentials: experience with NIST AI Risk Management Framework (AI RMF), ISO/IEC 42001 auditing, or formal bias and fairness auditing in production AI systems.
- Startup or Product Build Experience: prior experience as a technical co‑funder or early engineering executive in a hospitality technology, travel‑tech, or cybersecurity product company.
Network Infrastructure & Firewall - Direct Implementation Requirement
We require the Sr. Cybersecurity Engineer to maintain direct, hands‑on implementation capability. This reflects both the company's size and our commitment to building a security practice rooted in operational reality.
- Design and directly implement enterprise firewall rules, zone policies, stateful inspection, NAT/PAT, and IDS/IPS signatures on platforms including Palo Alto Networks (PAN-OS), Fortinet FortiGate, Cisco ASA / Firepower Threat Defense, or equivalent.
- Integrate third‑party hospitality vendors — PMS providers, POS vendors, OTA connectivity platforms, channel managers, and AI service APIs — securely via firewall policies, API gateways, and DMZ architectures.
- Architect hospitality‑specific network segmentation: guest WiFi isolation, POS network quarantine, BMS/EMS separation, staff VLAN design, management network controls, and IoT device VLAN containment.
- Implement and operate 802.1X NAC for wired and wireless endpoints; manage certificate infrastructure for WPA3‑Enterprise deployments across multi‑property environments.
- Operate SIEM with custom hospitality correlation rules: PMS login anomalies, POS transaction spikes, badge reader tailgating patterns, after‑hours BMS access, SIP call pattern deviations.