Director, Cyber Defense

American Express Global Business Travel
$130,200 - $241,800Onsite

About The Position

Amex GBT is seeking a Director, Cyber Defense to lead critical teams responsible for safeguarding travelers, colleagues, and data. This role involves leading Cyber Security Incident Response (CSIRT), Cyber Threat Intelligence (CTI), Detection Engineering, and Data Security Investigations (DSI). The ideal candidate will have experience managing security operations at scale, excelling in incident command under pressure, and building proactive detection and intelligence programs. This position will define the strategy for detecting, investigating, and responding to security incidents and data-handling concerns globally, acting as a key partner to Legal, Privacy, HR, and executive leadership. The role is crucial in protecting the trust that is fundamental to Amex GBT's business.

Requirements

  • 10+ years in cybersecurity, including 5+ years leading incident response, security operations, or a similar function.
  • Direct experience running or overseeing sensitive investigations involving data privacy, insider risk, or employee conduct, ideally in partnership with Legal or HR.
  • Working knowledge of threat intelligence practices and how intelligence should shape detection priorities.
  • Experience with detection engineering concepts: SIEM/EDR content development, use case design, and frameworks like MITRE ATT&CK.
  • A track record of leading through live incidents, including clear communication to non-technical executives under pressure.
  • Familiarity with privacy and data protection regulations relevant to a global business (for example, GDPR, CCPA, and similar frameworks).
  • Experience managing managers and building teams, not just individual contributors.
  • A bachelor's degree in a related field, or equivalent experience.

Nice To Haves

  • Experience in travel, hospitality, financial services, or another sector handling large volumes of personal and payment data.
  • Relevant certifications such as CISSP, GCIH, GCFA, GCTI, or equivalent.
  • Experience with 24/7 or global follow-the-sun security operations models.
  • Background working with outside counsel, forensics vendors, or law enforcement on significant incidents.

Responsibilities

  • Lead and grow four connected teams — CSIRT, CTI, Detection Engineering, and DSI — as one cyber defense function with shared priorities and a common operating rhythm.
  • Set the vision, roadmap, and budget for cyber defense capabilities, and report progress and risk to senior leadership.
  • Hire, coach, and develop team leads and analysts; build a bench that can operate confidently during high-pressure incidents.
  • Define and track metrics that show real progress: dwell time, mean time to detect and respond, investigation closure rates, and intelligence coverage.
  • Build strong working relationships with IT, Legal, Privacy, HR, Fraud, and business unit leaders.
  • Own the incident response program end to end: playbooks, severity classification, escalation paths, and after-action reviews.
  • Act as incident commander (or oversee the commander on rotation) for major security incidents, coordinating technical response with clear communication to executives.
  • Run regular tabletop exercises and simulations to test readiness across the company, not just within security.
  • Maintain relationships with outside counsel, forensics firms, and law enforcement contacts for incidents that require it.
  • Direct the collection, analysis, and distribution of threat intelligence relevant to our business, our sector, and our travelers.
  • Turn intelligence into action: feed indicators and adversary tradecraft directly into detection content and hunting priorities.
  • Represent us in relevant intelligence-sharing communities and industry groups, and build vendor and peer relationships that strengthen our visibility.
  • Deliver clear, decision-useful threat briefings to technical teams and to executive leadership.
  • Set priorities for detection content development across SIEM, EDR, cloud, and identity systems, mapped to real adversary behavior (MITRE ATT&CK and similar frameworks).
  • Drive continuous tuning to cut down false positives while closing coverage gaps.
  • Champion automation and orchestration so the team spends time on judgment calls, not repetitive triage.
  • Partner with CTI and CSIRT so that every real incident and every new piece of intelligence turns into better detection.
  • Lead investigations into potential inappropriate access, use, or disclosure of sensitive data — including privacy cases involving colleagues, contractors, or third parties.
  • Build and maintain a defensible investigative process: evidence handling, chain of custody, documentation, and clear findings.
  • Work closely with Legal, Privacy, and HR on cases that may carry disciplinary, regulatory, or legal exposure, and know when and how to loop them in.
  • Advise on data loss prevention, access controls, and insider risk indicators based on investigation trends.
  • Handle every case with the discretion and judgment these situations require, balancing thoroughness with fairness to everyone involved.

Benefits

  • health and welfare insurance plans
  • retirement programs
  • parental leave
  • adoption assistance
  • wellbeing resources
  • travel perks
  • access to over 20,000 courses on our learning platform
  • leadership courses
  • new job openings available to internal candidates first
  • global INclusion Groups
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service