KAYAK, part of Booking Holdings (NASDAQ: BKNG), is a leading travel search engine. With billions of queries across our platforms, we help people find their perfect flight, stay, rental car and vacation package. We're also transforming business travel with a new corporate travel solution, KAYAK for Business.
As an employee of KAYAK, you will be part of a travel company that operates a portfolio of global metasearch brands including momondo, Cheapflights and HotelsCombined, among others. From start-up to industry leader, innovation is in our DNA and every employee has an opportunity to make their mark. Our focus is on building the best travel search engine to make it easier for everyone to experience the world.
KAYAK's Security team exists to protect the company and its customers through comprehensive, agile, and collaborative security measures — with a human approach to policy, training, and awareness. We follow the NIST Cybersecurity Framework across six domains (Govern, Identify, Protect, Detect, Respond, and Recover).
We are looking for a Director of Cybersecurity to lead a global team of security engineers. This is a hands-on leadership role for an experienced security practitioner who will set direction for our technical security programs, support the growth of their team, and work closely with engineering and infrastructure partners to keep our systems and people secure — balancing strong protection with the business's need for agility and innovation.
This role is required to work from our Concord, MA office 3 days a week.
In this role, you will:
Partner with the CISO and other senior teammates to define and execute the organization’s cyber security strategy, roadmap, and operating model, ensuring security initiatives are measurable, operationally actionable, and aligned with business priorities.
Lead, mentor, and support a global team of security engineers across multiple disciplines, including incident response, vulnerability management, identity and access management and application security.
Own the day-to-day operations of the security program — including threat detection and response, vulnerability management, and endpoint security — and ensure the team has the support and clarity needed to execute effectively.
Partner with engineering, infrastructure, and product teams to embed security into how we build and operate systems.
Manage vendor relationships and contribute to budget planning for security tooling and services.
Support the hiring, onboarding, and career development of your team members, fostering a culture of learning, collaboration, and continuous improvement.
Explore and champion the use of AI and automation to improve how the team operates — this is an active area of investment for us.
Evaluate emerging threats and technologies, including the security implications of artificial intelligence and other new capabilities.
Please apply if you have:
10 or more years of progressive experience in cybersecurity or a closely related field, including significant people-leadership experience.
Demonstrated success building or maturing security programs in a complex, technology-driven environment.
Strong experience across multiple security domains — such as security operations, incident response, vulnerability management, IAM, cloud security, application security, or security architecture.
Strong technical skills in endpoint and server operating systems (especially Linux), computer networking, firewalls, and Kubernetes.
General understanding of security and compliance frameworks (NIST CSF, CIS, SOC 2, PCI-DSS).
Excellent communication skills, with the ability to explain technical risk clearly to executives, engineers, and business partners.
Experience developing meaningful security metrics and reporting progress to senior leadership.
The capacity to thrive in a hybrid working model, including the ability to attend the Concord office at least 3 days a week.
A degree in a relevant field is welcome; equivalent experience, training, or transferable skills are equally valued.
Curiosity about emerging technologies, including how AI and automation can improve security operations.
Benefits and Perks
Work from (almost) anywhere for up to 20 days per year
Focus on mental health and well-being:
Company-paid therapy sessions through SpringHealth
Company-paid subscription to HeadSpace
Company-wide week off a year - the whole team fully recharges (and returns without a pile-up of work!)
No meeting Fridays
Paid parental leave
Generous paid vacation + time off for your birthday
Paid volunteer time
Focus on your career growth:
Development Dollars
Leadership development
Access to thousands of on-demand e-learnings
Travel Discounts
Employee Resource Groups
Competitive retirement and health plans
Free lunch 2 days per week
Fun quarterly events such as boat trips, arcades, ski trips, Thursday happy hours, and more
There are a variety of factors that go into determining a salary range, including but not limited to external market benchmark data, geographic location, and years of experience sought/required. The range for this Massachusetts based role is $180,000-220,000, not inclusive of annual bonus and recurring RSU grants.
We offer a competitive base salary and benefits including: health benefits; flexible spending account; retirement benefits; life insurance; paid time off (including PTO, paid sick leave, medical leave, bereavement leave, floating holidays and paid holidays); and parental leave benefits.
Inclusion
At KAYAK, we want everyone to have the space to grow, share ideas and do great work. That's why we're focused on hiring the best talent from all walks of life and experiences, supporting them well and making sure no one feels like they have to fit a mold to belong here.
Need any adjustments for the interview, application or on the job? No problem - just give us a heads-up. We've got you.
Skills Required
- 10 or more years of progressive experience in cybersecurity or a closely related field
- Significant people-leadership experience
- Experience building or maturing security programs in a complex, technology-driven environment
- Experience across security operations, incident response, vulnerability management, IAM, cloud security, application security, or security architecture
- Strong technical skills with endpoint and server operating systems, especially Linux
- Knowledge of computer networking and firewalls
- Experience with Kubernetes
- Understanding of NIST CSF, CIS, SOC 2, and PCI-DSS security and compliance frameworks
- Excellent communication skills for explaining technical risk to executives, engineers, and business partners
- Experience developing security metrics and reporting to senior leadership
- Ability to work in a hybrid model from the Concord office at least three days per week
- Relevant degree or equivalent experience, training, or transferable skills
- Curiosity about emerging technologies, including AI and automation for security operations
KAYAK Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about KAYAK and has not been reviewed or approved by KAYAK.
-
Leave & Time Off Breadth — Time off is positioned as generous, with team‑wide downtime, paid volunteer time, and location‑specific vacation allotments in certain offices. Public descriptions also highlight generous PTO and paid sick days.
-
Healthcare Strength — Health coverage is described as comprehensive, including medical, dental, vision, and mental‑health support such as Headspace and access to counseling in some programs. Employer-verified listings also reference wellness resources and related benefits.
-
Fair & Transparent Compensation — Compensation philosophy emphasizes Equal Pay and a commitment to closing the global pay gap. Some job postings disclose salary ranges and note equity or bonus eligibility, reinforcing transparency for certain roles and locations.
KAYAK Insights
What We Do
KAYAK, part of Booking Holdings (NASDAQ: BKNG), is the world's leading travel search engine. With billions of queries across our platforms, we help people find their perfect flight, stay, rental car, cruise, vacation package. We also support business travelers with KAYAK for Business, our free corporate travel solution and are transforming the in-travel experience with our app and new hotel and accommodation software. Want to join a talented team that’s eager to solve the world’s travel problems (and have a bit of fun)? As an employee of KAYAK, you’ll be part of a global network including OpenTable and a portfolio of travel metasearch brands like Swoodoo, checkfelix, momondo, Cheapflights, Mundi and Hotels Combined. So join us, and help others experience the world through dining and travel.
Why Work With Us
What's most unique about KAYAK is the way we empower our team to lead their best lives - in and out of the workplace. Our Work from Almost Anywhere policy is built for and by our team. It gives us the flexibility to choose where and how we work best.









