Director, Security Engineering Our Technology Team partners with teams across Expedia Group to ... Demonstrated experience applying AI and machine learning techniques within cybersecurity contexts ...
Director, Security Engineering Our Technology Team partners with teams across Expedia Group to ... Demonstrated experience applying AI and machine learning techniques within cybersecurity contexts ...
Director, Cybersecurity & GRC
Berkeley, CA · On-site
$180 - $280/hr
Role Description As Form Energy matures and scales, the Director of Cybersecurity & GRC builds and leads our cybersecurity and IT governance, risk, and compliance programs. This is a CISO-track ...
Director, Cybersecurity & GRC
Berkeley, CA · On-site
$180 - $280/hr
Role Description As Form Energy matures and scales, the Director of Cybersecurity & GRC builds and leads our cybersecurity and IT governance, risk, and compliance programs. This is a CISO-track ...
Role Description As Form Energy matures and scales, the Director of Cybersecurity & GRC builds and leads our cybersecurity and IT governance, risk, and compliance programs. This is a CISO-track ...
Role Description As Form Energy matures and scales, the Director of Cybersecurity & GRC builds and leads our cybersecurity and IT governance, risk, and compliance programs. This is a CISO-track ...
We're looking for a proactive, curious, and impact-driven Director to lead day-to-day client programs and support growth within our Cybersecurity and Cloud/AI Infrastructure accounts. You'll play a ...
We're looking for a proactive, curious, and impact-driven Director to lead day-to-day client programs and support growth within our Cybersecurity and Cloud/AI Infrastructure accounts. You'll play a ...
Form Energy is seeking a Director of Cybersecurity & GRC to lead our cybersecurity and IT governance, risk, and compliance programs. This CISO-track leader will guide a team including a GRC Manager ...
Form Energy is seeking a Director of Cybersecurity & GRC to lead our cybersecurity and IT governance, risk, and compliance programs. This CISO-track leader will guide a team including a GRC Manager ...
Cybersecurity Director
San Francisco, CA · On-site
About the Role The Cybersecurity Director is responsible for providing strategic leadership across Business Wire's cybersecurity function, providing strategy, overseeing security architecture and ...
New
Quick apply
Cybersecurity Director
San Francisco, CA · On-site
About the Role The Cybersecurity Director is responsible for providing strategic leadership across Business Wire's cybersecurity function, providing strategy, overseeing security architecture and ...
New
Cybersecurity Director (Sunnyvale)
Sunnyvale, CA · On-site
$200K - $260K/yr
Onsite / Sunnyvale, CA HQ (This is not a remote role) About The Role Knightscope is seeking a Cybersecurity Director to lead the strategic direction, governance, and long-term maturity of our ...
Cybersecurity Director (Sunnyvale)
Sunnyvale, CA · On-site
$200K - $260K/yr
Onsite / Sunnyvale, CA HQ (This is not a remote role) About The Role Knightscope is seeking a Cybersecurity Director to lead the strategic direction, governance, and long-term maturity of our ...
Provide clear expectations, guidance, and oversight to product teams for secure design, development, and maintenance, without assuming direct development ownership. * Ensure cybersecurity ...
Provide clear expectations, guidance, and oversight to product teams for secure design, development, and maintenance, without assuming direct development ownership. * Ensure cybersecurity ...
The Cyber Security Engineer will implement and manage security systems and tools as directed by Firm policies, procedures, and management. Specific duties include, but are not limited to, the ...
The Cyber Security Engineer will implement and manage security systems and tools as directed by Firm policies, procedures, and management. Specific duties include, but are not limited to, the ...
The Cyber Security Engineer will implement and manage security systems and tools as directed by Firm policies, procedures, and management. Specific duties include, but are not limited to, the ...
The Cyber Security Engineer will implement and manage security systems and tools as directed by Firm policies, procedures, and management. Specific duties include, but are not limited to, the ...
The Cyber Security Engineer will implement and manage security systems and tools as directed by Firm policies, procedures, and management. Specific duties include, but are not limited to, the ...
The Cyber Security Engineer will implement and manage security systems and tools as directed by Firm policies, procedures, and management. Specific duties include, but are not limited to, the ...
The Cyber Security Engineer will implement and manage security systems and tools as directed by Firm policies, procedures, and management. Specific duties include, but are not limited to, the ...
The Cyber Security Engineer will implement and manage security systems and tools as directed by Firm policies, procedures, and management. Specific duties include, but are not limited to, the ...
Provide clear expectations, guidance, and oversight to product teams for secure design, development, and maintenance, without assuming direct development ownership. * Ensure cybersecurity ...
Provide clear expectations, guidance, and oversight to product teams for secure design, development, and maintenance, without assuming direct development ownership. * Ensure cybersecurity ...
Provide clear expectations, guidance, and oversight to product teams for secure design, development, and maintenance, without assuming direct development ownership. * Ensure cybersecurity ...
Provide clear expectations, guidance, and oversight to product teams for secure design, development, and maintenance, without assuming direct development ownership. * Ensure cybersecurity ...
Knightscope, located at Sunnyvale HQ, seeks a Cybersecurity Director to lead strategic direction, governance, and long-term maturity of our cybersecurity program. You will secure autonomous robotics ...
Knightscope, located at Sunnyvale HQ, seeks a Cybersecurity Director to lead strategic direction, governance, and long-term maturity of our cybersecurity program. You will secure autonomous robotics ...
Hardware Cyber Security Engineer (Test Lead)
Fremont, CA · On-site
$160K/yr
Overview Element is seeking a Hardware Cyber Security Engineer (Test Lead) to join our lab in ... To carry out any other reasonable duty as directed by the line manager Skills / Qualifications
Hardware Cyber Security Engineer (Test Lead)
Fremont, CA · On-site
$160K/yr
Overview Element is seeking a Hardware Cyber Security Engineer (Test Lead) to join our lab in ... To carry out any other reasonable duty as directed by the line manager Skills / Qualifications
Ability to travel, as required * 3+ years direct applicable experience (e.g., cybersecurity, infrastructure, or systems architecture). Senior level candidates considered with 5+ years direct ...
Ability to travel, as required * 3+ years direct applicable experience (e.g., cybersecurity, infrastructure, or systems architecture). Senior level candidates considered with 5+ years direct ...
Ability to travel, as required * 3+ years direct applicable experience (e.g., cybersecurity, infrastructure, or systems architecture). Senior level candidates considered with 5+ years direct ...
Ability to travel, as required * 3+ years direct applicable experience (e.g., cybersecurity, infrastructure, or systems architecture). Senior level candidates considered with 5+ years direct ...
Ability to travel, as required * 3+ years direct applicable experience (e.g., cybersecurity, infrastructure, or systems architecture). Senior level candidates considered with 5+ years direct ...
Ability to travel, as required * 3+ years direct applicable experience (e.g., cybersecurity, infrastructure, or systems architecture). Senior level candidates considered with 5+ years direct ...
Ability to travel, as required * 3+ years direct applicable experience (e.g., cybersecurity, infrastructure, or systems architecture). Senior level candidates considered with 5+ years direct ...
Ability to travel, as required * 3+ years direct applicable experience (e.g., cybersecurity, infrastructure, or systems architecture). Senior level candidates considered with 5+ years direct ...
Director Cyber Security information
See San Ramon, CA salary details
$63.7K - $76.8K
1% of jobs
$76.8K - $89.9K
4% of jobs
$89.9K - $103K
5% of jobs
$103K - $116.1K
9% of jobs
$123.3K is the 25th percentile. Wages below this are outliers.
$116.1K - $129.2K
11% of jobs
$129.2K - $142.3K
10% of jobs
The median wage is $147.4K / yr.
$142.3K - $155.4K
28% of jobs
$163K is the 75th percentile. Wages above this are outliers.
$155.4K - $168.5K
14% of jobs
$168.5K - $181.6K
11% of jobs
$181.6K - $194.8K
4% of jobs
$194.8K - $207.9K
4% of jobs
$63.7K
$148.6K
$207.9K
How much do director cyber security jobs pay per year?
What is a director cyber security?
A Director of Cyber Security is a senior leadership role responsible for overseeing an organization's cybersecurity strategy, policies, and operations. They lead teams to identify and mitigate security risks, ensure compliance with regulations, and implement protective measures against cyber threats. This role involves collaboration with executive leadership to align cybersecurity initiatives with business objectives. The director also monitors emerging threats, manages incident responses, and ensures continuous improvements in security posture. Effective communication, technical expertise, and strategic planning are key skills for success in this role.
What are common challenges faced by directors of cyber security, and how do they address them?
Directors of Cyber Security often face challenges such as keeping pace with evolving threats, balancing budget constraints with security priorities, and fostering a culture of security awareness across all departments. They address these by proactively monitoring the threat landscape, prioritizing risk management initiatives, and implementing clear security policies and ongoing training. Collaboration with IT, legal, and executive leadership is essential to align security strategies with organizational goals and ensure company-wide support. Managing these complexities requires both a technical mindset and strong leadership to drive continuous improvement. This dynamic environment makes the role both challenging and rewarding for professionals who enjoy problem-solving and leadership.
What skills and qualifications are needed to be a director cyber security?
To thrive as a Director Cyber Security, you need deep expertise in information security practices, risk management, and policy development, typically supported by a relevant bachelor's or master's degree and substantial leadership experience. Familiarity with tools such as SIEM platforms, vulnerability management solutions, and certifications like CISSP, CISM, or CISA is common. Strong strategic vision, communication skills, and the ability to influence and mentor cross-functional teams help you excel in this leadership role. These competencies are essential for designing effective security programs, building resilient organizations, and ensuring compliance with industry regulations.

Expedia Group rating
6.9
Based on 25 frontline employees who took The Breakroom Quiz
8th of 11 rated travel agencies
Job description
At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company powered by passionate people, trusted partnerships, and leading technology, we connect travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business.
Here, you'll do meaningful work that helps millions of people discover, book, and experience travel with more ease, confidence, and joy. Our five Behaviors-Traveler First, Think Big, Operate with Excellence, Ownership Mindset, and Succeed Together-help foster a supportive environment where people can grow their careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere.
Our Technology Team partners with teams across Expedia Group to create innovative products, services, and tools to deliver high-quality experiences for travelers, partners, and our employees. A singular technology platform powered by data and machine learning provides secure, differentiated, and personalized experiences that drive loyalty and traveler satisfaction.
Expedia Group's Product Security organization is building the security infrastructure, platforms, and services that power secure software delivery across one of the world's largest travel technology platforms. We are looking for a Director, Security Engineering who ships - someone who turns architectural thinking into running systems, operating controls, and measurable outcomes at enterprise scale.
This is fundamentally a hands-on, execution-oriented role. You will design and build security platforms, embed controls into high-velocity engineering workflows, operationalize cloud and data security programs, and serve as the technical anchor for complex, cross-cutting security initiatives. You will work closely with engineering teams, platform architects, and technology leads -influencingcraft, output, and trust rather than org chart position.
If you are energized by building things that work at scale, by making security invisible to engineers who do the right thing, and by leaving systems measurably more secure than you found them - this role was written for you.
WHO THRIVES IN THIS ROLE
You are a builder. You measure your impactinsystems shipped, controls operationalized, and engineering teams unblocked - not in decks presented or frameworks authored. You are most comfortable when you are deep in the work: designing a zero-trust architecture in the morning, reviewing a CI/CD pipeline security integration in the afternoon, collaborating vertically and horizontally with product security and CTO stakeholders to drive our success while understanding competing priorities. you're are Passionate and curious about AI system the next day. You understand that security at scale is a product problem - and you design accordingly, obsessing over adoption, ergonomics, and measurable outcomes. You influence through craft, consistency, and trust, and you thrive in environments where competing priorities arereal,and judgment matters more than process.
In this role, you will:
Security Platform & Infrastructure Delivery
Design, build, and operationalize reusable security platforms, shared services, and reference architectures that engineering teams consume at scale - prioritizing developer ergonomics and adoption velocity.
Deliver security guardrails for infrastructure-as-code, containerized microservices, and service mesh architectures - implemented as enforceable, automated policy-as-code controls, not documentation.
Build and maintain secrets management, certificate lifecycle, and workload identity frameworks for cloud-native infrastructure across multi-cloud environments.
Own the technical implementation of security tooling integrations - Security Fabric to be include SAST, DAST, SCA, ASPM, CSPM, DSPM - ensuring signal quality, pipeline integration, and engineering team usability.
Proven ability to develop and operationalize security policies, standards, and compliance frameworks (e.g., PCI-DSS, SOC 2, ISO 27001, GDPR)
AI & Agentic System Security - Hands-On Implementation
Demonstrated experience applying AI and machine learning techniques within cybersecurity contexts, including threat detection, anomaly detection, or automated vulnerability management
Implement security architecture for LLM-based applications, RAG pipelines, and agentic AI systems - applying controls for prompt injection, model abuse, data exfiltration, and agent trust boundaries in production environments.
Evaluate and operationalize AI-powered security tooling - automated threat detection, vulnerability triage, AI-driven response - from proof of concept through production operation.
Embed security early in Expedia Group's AI development lifecycle, influencing model selection, fine-tuning practices, and deployment architecture through direct partnership with AI platform teams.
Service Mesh & Zero-Trust Infrastructure
Implement and operate service mesh security at scale - mTLS enforcement, traffic policy, workload identity, and zero-trust network segmentation across distributed microservices environments (Istio, Envoy, or equivalent).
Architect and build identity-centric, zero-trust security models for distributed systems with complex east-west traffic patterns and hundreds of services.
Drive practical implementation of zero-trust principles across infrastructure - not as a framework exercise, but as running, enforced controls.
AWS Cloud Security Operations at Scale
Architect and operate AWS-native security controls at enterprise scale: IAM and SCPs, GuardDuty, Security Hub, Inspector, Macie, Control Tower, Secrets Manager, KMS - configured, tuned, and continuously improved, not just deployed.
Cloud Security Posture Management (CSPM) and Data Security Posture Management (DSPM) programs operationally - driving down finding age, improving coverage, and closing posture gaps at velocity.
Instrument and maintain security observability across cloud environments: detection coverage, alerting pipelines, and automated response playbooks that operate reliably at scale.
Enable high-velocity release pipelines by embedding security controls natively into CI/CD without blocking engineering throughput - shifting left without shifting blame.
SDLC Security Architecture - Built Into Engineering Workflows
Implement SDLC security architecture end-to-end - from threat modeling at design time through runtime protection - embedded in the tools, pipelines, and workflows engineers already use.
Deliver reusable security frameworks, libraries, and platform services that let product engineers ship secure code without becoming security experts.
Build and maintain security standards for web application, API, mobile, and cloud-native services - grounded in OWASP, NIST, and validated against Expedia Group's actual engineering stack.
Collaborate directly with engineering teams to balance security requirements against delivery priorities - understanding the pressures, designing controls that fit naturally, and earning credibility through practical judgment.
Delivering Delight - Cyber Experience That Engineers Actually Want
Design security interactions, tooling surfaces, and developer workflows that engineers find intuitive, fast, and useful - minimizing friction while maximizing adoption of secure patterns.
Produce clear, actionable security guidance, architectural blueprints, and technical documentation calibrated to the engineering audience - not compliance artifacts.
Navigate competing priorities with engineering teams by understanding delivery context, making risk tradeoffs explicit and transparent, and building durable trust through consistent, practical judgment.
Contribute to reshaping Product Security and cybersecurity strategy - informing roadmap direction through execution experience, not just top-down design.
Minimum Qualifications:
15+ years of progressive, hands-on cybersecurity experience - with demonstrated depth in building and operating security systems at enterprise scale, not just designing them.
Deep, practitioner-level AWS expertise: IAM, VPC, GuardDuty, Security Hub, Macie, Inspector, Control Tower, Secrets Manager, KMS - operated at scale in high-velocity release environments with measurable outcomes.
Proven track record delivering SDLC security architecture across large engineering organizations - including CI/CD integration, developer tooling, SAST/DAST/SCA deployment, and runtime security in production.
Hands-on implementation experience with service mesh architectures - mTLS, workload identity, traffic policy, zero-trust network enforcement - using Istio, Envoy, Linkerd, or equivalent in production.
Demonstrated proficiency in AI security - implementing controls for LLM applications, RAG systems, and agentic AI pipelines in enterprise production environments, not just evaluating them.
Operational experience running CSPM and DSPM programs at scale - owning finding triage, remediation velocity, and posture improvement metrics.
Proven ability to collaborate with and influence engineering teams without formal authority - translating security requirements into engineering-compatible designs and building trust through delivery.
Ability to contribute to security strategy - translating execution experience and technical depth into roadmap input, architectural direction, and stakeholder communication.
Exceptional technical communication skills - producing authoritative architectural documentation, security guidance, and clear executive-level summaries when needed.
Bachelor's degree in Computer Science, Information Security, or related technical field - or equivalent professional experience.
Preferred Qualifications:
Experience in a large-scale, multi-cloud e-commerce or travel technology environment with global operations and high release frequency.
Hands-on experience building, deploying, or securing agentic AI systems and LLM-based applications in enterprise production - including red-teaming and abuse scenario validation.
Experience building security-as-a-platform services consumed by large engineering organizations - including self-service security tooling, paved-road security libraries, or security SDK development.
Prior people leadership or tech lead experience - not required, but relevant for candidates interested in optional team leadership scope.
Relevant certifications: CISSP, CCSP, CSSLP, AWS Security Specialty, or GCP Security Engineer.
Applied experience with PCI-DSS, SOC 2, GDPR, and ISO 27001 as apractitioner forbuilding compliant systems - not as a policy author.
Senior Individual Contributor | Director-Level Scope
Note: This role is open to exceptional senior ICs and to candidates with people leadership experience who prefer to remain primarily hands-on. People management responsibilities may be available for the right candidate but are not required.
Starting pay for this role will vary based on multiple factors, including location, available budget, and an individual's knowledge, skills, and experience. Pay ranges may be modified in the future.
Benefits and perks
Expedia Group offers benefits and perks designed to support employees and their families, including medical, dental, and vision coverage, paid time off, an Employee Assistance Program, wellness and travel reimbursement, travel discounts, and International Airlines Travel Agent Network (IATAN) membership. Learn more about life at Expedia Group at https://careers.expediagroup.com/life.
Accommodation requests
Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.
About Expedia Group
Expedia Group includes three flagship consumer brands - Expedia, Hotels.com, and Vrbo - along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.
Important notice
Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made p...
What Expedia Group employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom