1

Director Cybersecurity Jobs (NOW HIRING)

Director CyberSecurity

San Jose, CA ยท On-site

$249 - $348.50/hr

Director, Security Engineering Our Technology Team partners with teams across Expedia Group to ... Demonstrated experience applying AI and machine learning techniques within cybersecurity contexts ...

New

Director CyberSecurity

San Jose, CA ยท On-site

$239.10 - $398.50/hr

Director, Security EngineeringOur Technology Team partners with teams across Expedia Group to ... Minimum Qualifications:15+ years of progressive, hands-on cybersecurity experience -- with ...

Director, Cybersecurity & GRC

Berkeley, CA ยท On-site

$199K - $293K/yr

Role Description As Form Energy matures and scales, the Director of Cybersecurity & GRC builds and leads our cybersecurity and IT governance, risk, and compliance programs. This is a CISO-track ...

Director CyberSecurity

San Jose, CA ยท On-site

$260 - $380/hr

Director, Security Engineering Our Technology Team partners with teams across Expedia Group to ... Demonstrated experience applying AI and machine learning techniques within cybersecurity contexts ...

Job Summary The Director, Cybersecurity Operations leads the development, implementation, and ongoing coordination of enterprise-wide cybersecurity operations, including Threat Engineering, Threat ...

Job Summary The Director, Cybersecurity Operations leads the development, implementation, and ongoing coordination of enterprise-wide cybersecurity operations, including Threat Engineering, Threat ...

Director, Cybersecurity Engineering

Rahway, NJ ยท Hybrid

$156K - $247K/yr

If you are passionate about cybersecurity and innovation, and thrive in a dynamic environment, we invite you to join our team and make a significant impact.This is a hybrid role (3 days in the office ...

Director, Cyber Security Engineer At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the ...

Director, Cybersecurity Engineering

Rahway, NJ ยท Hybrid

$156K - $247K/yr

If you are passionate about cybersecurity and innovation, and thrive in a dynamic environment, we invite you to join our team and make a significant impact. This is a hybrid role (3 days in the ...

next page

Showing results 1-20

Director Cybersecurity information

See salary details

$31.5K

$139.4K

$218.5K

How much do director cybersecurity jobs pay per year?

As of Jul 22, 2026, the average yearly pay for director cybersecurity in the United States is $139,409.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,000.00 and $160,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Director of Cybersecurity, and why are they important?

To thrive as a Director of Cybersecurity, you need deep expertise in information security management, risk assessment, and incident response, typically supported by a bachelor's or master's degree in a related field and significant industry experience. Familiarity with security frameworks (such as NIST or ISO/IEC 27001), regulatory compliance standards, and certifications like CISSP or CISM is often required. Strong leadership, strategic thinking, and effective communication skills help you guide teams and influence organizational security culture. These skills are crucial for protecting sensitive data, ensuring regulatory compliance, and developing resilient cybersecurity programs.

What does a Director of Cybersecurity do?

A Director of Cybersecurity is responsible for overseeing an organization's cybersecurity strategy, policies, and operations. They lead teams to protect sensitive data and systems from cyber threats, manage incident response, and ensure compliance with security regulations. This role often involves collaborating with other executives to align security initiatives with business objectives and staying updated on the latest security technologies and risks. The Director also plays a key role in training staff, conducting risk assessments, and developing disaster recovery plans.

How does a Director of Cybersecurity typically collaborate with other departments to ensure organizational security?

A Director of Cybersecurity works closely with various departments, including IT, legal, compliance, and executive leadership, to develop and implement security strategies that align with organizational goals. They often lead cross-functional teams during security incident response, ensure regular communication about risks, and provide guidance on secure practices. Building strong relationships across the organization is essential for fostering a security-aware culture and for integrating security considerations into business processes and projects.
More about Director Cybersecurity jobs
What cities are hiring for Director Cybersecurity jobs? Cities with the most Director Cybersecurity job openings:
What are the most commonly searched types of Cybersecurity jobs? The most popular types of Cybersecurity jobs are:
What states have the most Director Cybersecurity jobs? States with the most job openings for Director Cybersecurity jobs include:
Infographic showing various Director Cybersecurity job openings in the United States as of July 2026, with employment types broken down into 100% Full Time. Highlights an 67% In-person, and 33% Remote job distribution, with an average salary of $139,409 per year, or $67 per hour.

Director CyberSecurity

Traveltechessentialist

San Jose, CA โ€ข On-site

$249 - $348.50/hr

Other

Medical, Dental, Vision, PTO

Posted yesterday


Job description

Director, Security Engineering

Our Technology Team partners with teams across Expedia Group to create innovative products, services, and tools to deliver high-quality experiences for travelers, partners, and our employees. A singular technology platform powered by data and machine learning provides secure, differentiated, and personalized experiences that drive loyalty and traveler satisfaction.

Expedia Group's Product Security organization is building the security infrastructure, platforms, and services that power secure software delivery across one of the world's largest travel technology platforms. We are looking for a Director, Security Engineering who ships โ€” someone who turns architectural thinking into running systems, operating controls, and measurable outcomes at enterprise scale.

This is fundamentally a handsโ€‘on, executionโ€‘oriented role. You will design and build security platforms, embed controls into highโ€‘velocity engineering workflows, operationalize cloud and data security programs, and serve as the technical anchor for complex, crossโ€‘cutting security initiatives. You will work closely with engineering teams, platform architects, and technology leads โ€” influencing craft, output, and trust rather than org chart position.

If you are energized by building things that work at scale, by making security invisible to engineers who do the right thing, and by leaving systems measurably more secure than you found them โ€” this role was written for you.

WHO THRIVES IN THIS ROLE

You are a builder. You measure your impact in systems shipped, controls operationalized, and engineering teams unblocked โ€” not in decks presented or frameworks authored. You are most comfortable when you are deep in the work: designing a zeroโ€‘trust architecture in the morning, reviewing a CI/CD pipeline security integration in the afternoon, collaborating vertically and horizontally with product security and CTO stakeholders to drive our success while understanding competing priorities. You are passionate and curious about AI system the next day. You understand that security at scale is a product problem โ€” and you design accordingly, obsessing over adoption, ergonomics, and measurable outcomes. You influence through craft, consistency, and trust, and you thrive in environments where competing priorities are real, and judgment matters more than process.

In this role, you will: Security Platform & Infrastructure Delivery
  • Design, build, and operationalize reusable security platforms, shared services, and reference architectures that engineering teams consume at scale โ€” prioritizing developer ergonomics and adoption velocity.
  • Deliver security guardrails for infrastructureโ€‘asโ€‘code, containerized microservices, and service mesh architectures โ€” implemented as enforceable, automated policyโ€‘asโ€‘code controls, not documentation.
  • Build and maintain secrets management, certificate lifecycle, and workload identity frameworks for cloudโ€‘native infrastructure across multiโ€‘cloud environments.
  • Own the technical implementation of security tooling integrations โ€” Security Fabric to be include SAST, DAST, SCA, ASPM, CSPM, DSPM โ€” ensuring signal quality, pipeline integration, and engineering team usability.
  • Proven ability to develop and operationalize security policies, standards, and compliance frameworks (e.g., PCIโ€‘DSS, SOC 2, ISO 27001, GDPR)
AI & Agentic System Security โ€” Handsโ€‘On Implementation
  • Demonstrated experience applying AI and machine learning techniques within cybersecurity contexts, including threat detection, anomaly detection, or automated vulnerability management
  • Implement security architecture for LLMโ€‘based applications, RAG pipelines, and agentic AI systems โ€” applying controls for prompt injection, model abuse, data exfiltration, and agent trust boundaries in production environments.
  • Evaluate and operationalize AIโ€‘powered security tooling โ€” automated threat detection, vulnerability triage, AIโ€‘driven response โ€” from proof of concept through production operation.
  • Embed security early in Expedia Group's AI development lifecycle, influencing model selection, fineโ€‘tuning practices, and deployment architecture through direct partnership with AI platform teams.
Service Mesh & Zeroโ€‘Trust Infrastructure
  • Implement and operate service mesh security at scale โ€” mTLS enforcement, traffic policy, workload identity, and zeroโ€‘trust network segmentation across distributed microservices environments (Istio, Envoy, or equivalent).
  • Architect and build identityโ€‘centric, zeroโ€‘trust security models for distributed systems with complex eastโ€‘west traffic patterns and hundreds of services.
  • Drive practical implementation of zeroโ€‘trust principles across infrastructure โ€” not as a framework exercise, but as running, enforced controls.
AWS Cloud Security Operations at Scale
  • Architect and operate AWSโ€‘native security controls at enterprise scale: IAM and SCPs, GuardDuty, Security Hub, Inspector, Macie, Control Tower, Secrets Manager, KMS โ€” configured, tuned, and continuously improved, not just deployed.
  • Cloud Security Posture Management (CSPM) and Data Security Posture Management (DSPM) programs operationally โ€” driving down finding age, improving coverage, and closing posture gaps at velocity.
  • Instrument and maintain security observability across cloud environments: detection coverage, alerting pipelines, and automated response playbooks that operate reliably at scale.
  • Enable highโ€‘velocity release pipelines by embedding security controls natively into CI/CD without blocking engineering throughput โ€” shifting left without shifting blame.
SDLC Security Architecture โ€” Built Into Engineering Workflows
  • Implement SDLC security architecture endโ€‘toโ€‘end โ€” from threat modeling at design time through runtime protection โ€” embedded in the tools, pipelines, and workflows engineers already use.
  • Deliver reusable security frameworks, libraries, and platform services that let product engineers ship secure code without becoming security experts.
  • Build and maintain security standards for web application, API, mobile, and cloudโ€‘native services โ€” grounded in OWASP, NIST, and validated against Expedia Group's actual engineering stack.
  • Collaborate directly with engineering teams to balance security requirements against delivery priorities โ€” understanding the pressures, designing controls that fit naturally, and earning credibility through practical judgment.
Delivering Delight โ€” Cyber Experience That Engineers Actually Want
  • Design security interactions, tooling surfaces, and developer workflows that engineers find intuitive, fast, and useful โ€” minimizing friction while maximizing adoption of secure patterns.
  • Produce clear, actionable security guidance, architectural blueprints, and technical documentation calibrated to the engineering audience โ€” not compliance artifacts.
  • Navigate competing priorities with engineering teams by understanding delivery context, making risk tradeoffs explicit and transparent, and building durable trust through consistent, practical judgment.
  • Contribute to reshaping Product Security and cybersecurity strategy โ€” informing roadmap direction through execution experience, not just topโ€‘down design.
Minimum Qualifications
  • 15+ years of progressive, handsโ€‘on cybersecurity experience โ€” with demonstrated depth in building and operating security systems at enterprise scale, not just designing them.
  • Deep, practitionerโ€‘level AWS expertise: IAM, VPC, GuardDuty, Security Hub, Macie, Inspector, Control Tower, Secrets Manager, KMS โ€” operated at scale in highโ€‘velocity release environments with measurable outcomes.
  • Proven track record delivering SDLC security architecture across large engineering organizations โ€” including CI/CD integration, developer tooling, SAST/DAST/SCA deployment, and runtime security in production.
  • Handsโ€‘on implementation experience with service mesh architectures โ€” mTLS, workload identity, traffic policy, zeroโ€‘trust network enforcement โ€” using Istio, Envoy, Linkerd, or equivalent in production.
  • Demonstrated proficiency in AI security โ€” implementing controls for LLM applications, RAG systems, and agentic AI pipelines in enterprise production environments, not just evaluating them.
  • Operational experience running CSPM and DSPM programs at scale โ€” owning finding triage, remediation velocity, and posture improvement metrics.
  • Proven ability to collaborate with and influence engineering teams without formal authority โ€” translating security requirements into engineeringโ€‘compatible designs and building trust through delivery.
  • Ability to contribute to security strategy โ€” translating execution experience and technical depth into roadmap input, architectural direction, and stakeholder communication.
  • Exceptional technical communication skills โ€” producing authoritative architectural documentation, security guidance, and clear executiveโ€‘level summaries when needed.
  • Bachelor's degree in Computer Science, Information Security, or related technical field โ€” or equivalent professional experience.
Preferred Qualifications
  • Experience in a largeโ€‘scale, multiโ€‘cloud eโ€‘commerce or travel technology environment with global operations and high release frequency.
  • Handsโ€‘on experience building, deploying, or securing agentic AI systems and LLMโ€‘based applications in enterprise production โ€” including redโ€‘teaming and abuse scenario validation.
  • Experience building securityโ€‘asโ€‘aโ€‘platform services consumed by large engineering organizations โ€” including selfโ€‘service security tooling, pavedโ€‘road security libraries, or security SDK development.
  • Prior people leadership or tech lead experience โ€” not required, but relevant for candidates interested in optional team leadership scope.
  • Relevant certifications: CISSP, CCSP, CSSLP, AWS Security Specialty, or GCP Security Engineer.
  • Applied experience with PCIโ€‘DSS, SOC 2, GDPR, and ISO 27001 as a practitioner for building compliant systems โ€” not as a policy author.

Senior Individual Contributor | Directorโ€‘Level Scope

Note: This role is open to exceptional senior ICs and to candidates with people leadership experience who prefer to remain primarily handsโ€‘on. People management responsibilities may be available for the right candidate but are not required.

The total cash range for this position in San Jose is $249,000.00 to $348,500.00. Employees in this role have the potential to increase their pay up to $398,500.00, which is the top of the range, based on ongoing, demonstrated, and sustained performance in the role.

Starting pay for this role will vary based on multiple factors, including location, available budget, and an individualโ€™s knowledge, skills, and experience. Pay ranges may be modified in the future.

Benefits and perks

Expedia Group offers benefits and perks designed to support employees and their families, including medical, dental, and vision coverage, paid time off, an Employee Assistance Program, wellness and travel reimbursement, travel discounts, and International Airlines Travel Agent Network (IATAN) membership. Learn more about life at Expedia Group at https://careers.expediggroup.com/life.

Accommodation requests

Expedia Group is committed to providing an inclusive and accessible recruiting experience. If you need an accommodation or adjustment due to a disability during the application or recruiting process, please submit a request at https://expedia.service-now.com/askeg?id=job_accommodation.

About Expedia Group

Expedia Group includes three flagship consumer brands โ€“ Expedia, Hotels.com, and Vrbo โ€“ along with a leading B2B travel business and travel advertising offerings. Across our brands and business, we help travelers explore the world with confidence and ease.

Important notice

Employment opportunities and job offers at Expedia Group will always come from Expedia Group's Talent Acquisition and hiring teams. Never share sensitive personal information unless you are confident of the recipient. Expedia Group does not extend job offers via email or messaging tools to individuals with whom we have not made prior contact. Our email domain is @expediagroup.com. The official place to find and apply for roles is https://careers.expediagroup.com/jobs/.

Equal Opportunity

Expedia is committed to creating an inclusive work environment with a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other characteristic protected by law. This employer participates in Eโ€‘Verify. The employer will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's Iโ€‘9 to confirm work authorization.

#J-18808-Ljbffr