×
Register Here to Apply for Jobs or Post Jobs. X

Director, Cyber Defense

Job in Washington, District of Columbia, 20022, USA
Listing for: American Express
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 130000 - 242000 USD Yearly USD 130000.00 242000.00 YEAR
Job Description & How to Apply Below

Amex GBT is a place where colleagues find inspiration in travel as a force for good and - through their work - can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued. We're looking for a Director, Cyber Defense to lead the teams that keep our travelers, colleagues, and data safe:
Cyber Security Incident Response (CSIRT), Cyber Threat Intelligence (CTI), Detection Engineering, and Data Security Investigations (DSI). This is a hands-on leadership role for someone who has run security operations at scale, knows what good incident command looks like under pressure, and can build detection and intelligence programs that get ahead of threats rather than just reacting to them.

You’ll set the strategy for how we detect, investigate, and respond to security incidents and data-handling concerns across a global business. You’ll also be a key partner to Legal, Privacy, HR, and executive leadership when incidents touch sensitive data or people. Amex GBT operates in a sector where trust is the product - this role protects that trust.

What You’ll Do
  • Team leadership and strategy
  • Lead and grow four connected teams - CSIRT, CTI, Detection Engineering, and DSI - as one cyber defense function with shared priorities and a common operating rhythm
  • Set the vision, roadmap, and budget for cyber defense capabilities, and report progress and risk to senior leadership
  • Hire, coach, and develop team leads and analysts; build a bench that can operate confidently during high‑pressure incidents
  • Define and track metrics that show real progress: dwell time, mean time to detect and respond, investigation closure rates, and intelligence coverage
  • Build strong working relationships with IT, Legal, Privacy, HR, Fraud, and business unit leaders
  • Incident response (CSIRT)
  • Own the incident response program end to end: playbooks, severity classification, escalation paths, and after‑action reviews
  • Act as incident commander (or oversee the commander on rotation) for major security incidents, coordinating technical response with clear communication to executives
  • Run regular tabletop exercises and simulations to test readiness across the company, not just within security
  • Maintain relationships with outside counsel, forensics firms, and law enforcement contacts for incidents that require it
  • Cyber threat intelligence (CTI)
  • Direct the collection, analysis, and distribution of threat intelligence relevant to our business, our sector, and our travelers
  • Turn intelligence into action: feed indicators and adversary tradecraft directly into detection content and hunting priorities
  • Represent us in relevant intelligence‑sharing communities and industry groups, and build vendor and peer relationships that strengthen our visibility
  • Deliver clear, decision‑useful threat briefings to technical teams and to executive leadership
  • Detection engineering
  • Set priorities for detection content development across SIEM, EDR, cloud, and identity systems, mapped to real adversary behavior (MITRE ATT&CK and similar frameworks)
  • Drive continuous tuning to cut down false positives while closing coverage gaps
  • Champion automation and orchestration so the team spends time on judgment calls, not repetitive triage
  • Partner with CTI and CSIRT so that every real incident and every new piece of intelligence turns into better detection
  • Data Security Investigations (DSI)
  • Lead investigations into potential inappropriate access, use, or disclosure of sensitive data - including privacy cases involving colleagues, contractors, or third parties
  • Build and maintain a defensible investigative process: evidence handling, chain of custody, documentation, and clear findings
  • Work closely with Legal,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary