waypointjobs

American Express Global Business Travel

Director, Cyber Defense

augusta, ME

Check who can apply and the requirements below before continuing.

About this opportunity

American Express Global Business Travel lists this Director, Cyber Defense opportunity in augusta, Maine. Review the employer’s description below for duties, qualifications and application requirements.

Job description

United States

Full time

J-84873

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

We're looking for a Director, Cyber Defense to lead the teams that keep our travelers, colleagues, and data safe: Cyber Security Incident Response (CSIRT), Cyber Threat Intelligence (CTI), Detection Engineering, and Data Security Investigations (DSI). This is a hands‑on leadership role for someone who has run security operations at scale, knows what good incident command looks like under pressure, and can build detection and intelligence programs that get ahead of threats rather than just reacting to them.

You'll set the strategy for how we detect, investigate, and respond to security incidents and data-handling concerns across a global business. You'll also be a key partner to Legal, Privacy, HR, and executive leadership when incidents touch sensitive data or people. Amex GBT operates in a sector where trust is the product — this role protects that trust.

What You’ll Do

Team leadership and strategy

Lead and grow four connected teams — CSIRT, CTI, Detection Engineering, and DSI — as one cyber defense function with shared priorities and a common operating rhythm

Set the vision, roadmap, and budget for cyber defense capabilities, and report progress and risk to senior leadership

Hire, coach, and develop team leads and analysts; build a bench that can operate confidently during high‑pressure incidents

Define and track metrics that show real progress: dwell time, mean time to detect and respond, investigation closure rates, and intelligence coverage

Build strong working relationships with IT, Legal, Privacy, HR, Fraud, and business unit leaders

Incident response (CSIRT)

Own the incident response program end to end: playbooks, severity classification, escalation paths, and after‑action reviews

Act as incident commander (or oversee the commander on rotation) for major security incidents, coordinating technical response with clear communication to executives

Run regular tabletop exercises and simulations to test readiness across the company, not just within security

Maintain relationships with outside counsel, forensics firms, and law enforcement contacts for incidents that require it

Cyber threat intelligence (CTI)

Direct the collection, analysis, and distribution of threat intelligence relevant to our business, our sector, and our travelers

Turn intelligence into action: feed indicators and adversary tradecraft directly into detection content and hunting priorities

Represent us in relevant intelligence‑sharing communities and industry groups, and build vendor and peer relationships that strengthen our visibility

Deliver clear, decision‑useful threat briefings to technical teams and to executive leadership

Detection engineering

Set priorities for detection content development across SIEM, EDR, cloud, and identity systems, mapped to real adversary behavior (MITRE ATT&CK and similar frameworks)

Drive continuous tuning to cut down false positives while closing coverage gaps

Champion automation and orchestration so the team spends time on judgment calls, not repetitive triage

Partner with CTI and CSIRT so that every real incident and every new piece of intelligence turns into better detection

Data Security Investigations (DSI)

Lead investigations into potential inappropriate access, use, or disclosure of sensitive data — including privacy cases involving colleagues, contractors, or third parties

Build and maintain a defensible investigative process: evidence handling, chain of custody, documentation, and clear findings

Work closely with Legal, Privacy, and HR on cases that may carry disciplinary, regulatory, or legal exposure, and know when and how to loop them in

Advise on data loss prevention, access controls, and insider risk indicators based on investigation trends

Handle every case with the discretion and judgment these situations require, balancing thoroughness with fairness to everyone involved

What We’re Looking For

10+ years in cybersecurity, including 5+ years leading incident response, security operations, or a similar function

Direct experience running or overseeing sensitive investigations involving data privacy, insider risk, or employee conduct, ideally in partnership with Legal or HR

Working knowledge of threat intelligence practices and how intelligence should shape detection priorities

Experience with detection engineering concepts: SIEM/EDR content development, use case design, and frameworks like MITRE ATT&CK

A track record of leading through live incidents, including clear communication to non‑technical executives under pressure

Familiarity with privacy and data protection regulations relevant to a global business (for example, GDPR, CCPA, and similar frameworks)

Experience managing managers and building teams, not just individual contributors

A bachelor's degree in a related field, or equivalent experience

Preferred

Experience in travel, hospitality, financial services, or another sector handling large volumes of personal and payment data

Relevant certifications such as CISSP, GCIH, GCFA, GCTI, or equivalent

Experience with 24/7 or global follow‑the‑sun security operations models

Background working with outside counsel, forensics vendors, or law enforcement on significant incidents

Location

United States

The US national base salary range for this position is from

$130,200.00 - $241,800.00

The national range provided includes the base salary that Amex GBT expects to pay for the role. Actual base salary will be based on factors including the scope and complexity of the role and the successful candidate’s relevant experience, skills, knowledge, and work location.

In addition to base salary, the anticipated range of which is posted above, this role is eligible for a discretionary annual bonus, which rewards participants based on company and individual performance.

For information about our comprehensive US benefits programs and eligibility, please review our Benefits‑at‑a‑Glance document.

Benefits at a glance (

The #TeamGBT Experience

Work and life: Find your happy medium at Amex GBT.

Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.

Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.

Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.

We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.

And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement (

#J-18808-Ljbffr

Worksite address

augusta, ME, 04338, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

Nestlé USA

WhatJobs

Safety Health & Environmental Specialist

medford, WI

Salary not specified

Foods you love. Brands you trust. And a career that empowers you to grow.    At Nestlé USA, we’re all working towards the same goal – to delight …

Last received from source 2026-10-07View job

BMO Financial

WhatJobs

Associate Banker

steamboat springs, CO

See pay details in description

Application Deadline: 10/18/2026 Address: 555 Lincoln Ave. Job Family Group: Retail Banking Sales & Service Delivers exce…

Last received from source 2026-10-07View job

Nestlé USA

WhatJobs

Factory Manager

medford, WI

Salary not specified

Foods you love. Brands you trust. And a career that empowers you to grow.    At Nestlé USA, we’re all working towards the same goal – to delight …

Last received from source 2026-10-07View job

BMO Financial

WhatJobs

Bank Manager

hubertus, WI

See pay details in description

Application Deadline: 10/30/2026 Address: 1301 Highway 175 Job Family Group: Retail Banking Sales & Service Guides, direct…

Last received from source 2026-10-07View job

BMO Financial

WhatJobs

Centralized Mortgage Banker

tempe, AZ

See pay details in description

Application Deadline: 10/30/2026 Address: 1625 W. Fountainhead Parkway Job Family Group: Retail Banking Sales & Service Co…

Last received from source 2026-10-07View job

BMO Financial

WhatJobs

Bank Manager

coon rapids, MN

See pay details in description

Application Deadline: 10/13/2026 Address: th Avenue NW Job Family Group: Retail Banking Sales & Service Guides, directs, …

Last received from source 2026-10-07View job