Director of Cyber Security

Posted 8 Days Ago
Be an Early Applicant
Hiring Remotely in Office, Machaze, Manica, MOZ
Remote or Hybrid
200K-220K Annually
Expert/Leader
Other • Travel
The Role
Lead KAYAK’s global security engineering team and execute its cybersecurity strategy and operating model. Oversee security operations, incident response, threat detection, vulnerability management, endpoint security, IAM, and application security. Partner with engineering, infrastructure, and product teams to embed security into systems, manage vendors and budgets, develop metrics, support hiring and career growth, and evaluate AI-driven security automation. This hybrid role requires working from the Concord, Massachusetts office three days per week.
Summary Generated by Built In

KAYAK, part of Booking Holdings (NASDAQ: BKNG), is a leading travel search engine. With billions of queries across our platforms, we help people find their perfect flight, stay, rental car and vacation package. We're also transforming business travel with a new corporate travel solution, KAYAK for Business.

 

As an employee of KAYAK, you will be part of a travel company that operates a portfolio of global metasearch brands including momondo, Cheapflights and HotelsCombined, among others. From start-up to industry leader, innovation is in our DNA and every employee has an opportunity to make their mark. Our focus is on building the best travel search engine to make it easier for everyone to experience the world.


KAYAK's Security team exists to protect the company and its customers through comprehensive, agile, and collaborative security measures — with a human approach to policy, training, and awareness. We follow the NIST Cybersecurity Framework across six domains (Govern, Identify, Protect, Detect, Respond, and Recover).

We are looking for a Director of Cybersecurity to lead a global team of security engineers. This is a hands-on leadership role for an experienced security practitioner who will set direction for our technical security programs, support the growth of their team, and work closely with engineering and infrastructure partners to keep our systems and people secure — balancing strong protection with the business's need for agility and innovation.

This role is required to work from our Concord, MA office 3 days a week.

 

In this role, you will:

  • Partner with the CISO and other senior teammates to define and execute the organization’s cyber security strategy, roadmap, and operating model, ensuring security initiatives are measurable, operationally actionable, and aligned with business priorities.

  • Lead, mentor, and support a global team of security engineers across multiple disciplines, including incident response, vulnerability management, identity and access management and application security.

  • Own the day-to-day operations of the security program — including threat detection and response, vulnerability management, and endpoint security — and ensure the team has the support and clarity needed to execute effectively.

  • Partner with engineering, infrastructure, and product teams to embed security into how we build and operate systems.

  • Manage vendor relationships and contribute to budget planning for security tooling and services.

  • Support the hiring, onboarding, and career development of your team members, fostering a culture of learning, collaboration, and continuous improvement.

  • Explore and champion the use of AI and automation to improve how the team operates — this is an active area of investment for us.

  • Evaluate emerging threats and technologies, including the security implications of artificial intelligence and other new capabilities.

 

Please apply if you have:

  • 10 or more years of progressive experience in cybersecurity or a closely related field, including significant people-leadership experience.

  • Demonstrated success building or maturing security programs in a complex, technology-driven environment.

  • Strong experience across multiple security domains — such as security operations, incident response, vulnerability management, IAM, cloud security, application security, or security architecture.

  • Strong technical skills in endpoint and server operating systems (especially Linux), computer networking, firewalls, and Kubernetes.

  • General understanding of security and compliance frameworks (NIST CSF, CIS, SOC 2, PCI-DSS).

  • Excellent communication skills, with the ability to explain technical risk clearly to executives, engineers, and business partners.

  • Experience developing meaningful security metrics and reporting progress to senior leadership.

  • The capacity to thrive in a hybrid working model, including the ability to attend the Concord office at least 3 days a week.

  • A degree in a relevant field is welcome; equivalent experience, training, or transferable skills are equally valued.

  • Curiosity about emerging technologies, including how AI and automation can improve security operations.

 

Benefits and Perks

  • Work from (almost) anywhere for up to 20 days per year

  • Focus on mental health and well-being:

    • Company-paid therapy sessions through SpringHealth

    • Company-paid subscription to HeadSpace

    • Company-wide week off a year - the whole team fully recharges (and returns without a pile-up of work!)

    • No meeting Fridays

    • Paid parental leave

    • Generous paid vacation + time off for your birthday

    • Paid volunteer time

  • Focus on your career growth:

    • Development Dollars

    • Leadership development

    • Access to thousands of on-demand e-learnings

  • Travel Discounts

  • Employee Resource Groups

  • Competitive retirement and health plans

  • Free lunch 2 days per week

  • Fun quarterly events such as boat trips, arcades, ski trips, Thursday happy hours, and more


There are a variety of factors that go into determining a salary range, including but not limited to external market benchmark data, geographic location, and years of experience sought/required. The range for this Massachusetts based role is $180,000-220,000, not inclusive of annual bonus and recurring RSU grants.

 

We offer a competitive base salary and benefits including: health benefits; flexible spending account; retirement benefits; life insurance; paid time off (including PTO, paid sick leave, medical leave, bereavement leave, floating holidays and paid holidays); and parental leave benefits.

 

Inclusion

At KAYAK, we want everyone to have the space to grow, share ideas and do great work. That's why we're focused on hiring the best talent from all walks of life and experiences, supporting them well and making sure no one feels like they have to fit a mold to belong here.

 

Need any adjustments for the interview, application or on the job? No problem - just give us a heads-up. We've got you.

Skills Required

  • 10 or more years of progressive experience in cybersecurity or a closely related field
  • Significant people-leadership experience
  • Experience building or maturing security programs in a complex, technology-driven environment
  • Experience across security operations, incident response, vulnerability management, IAM, cloud security, application security, or security architecture
  • Strong technical skills with endpoint and server operating systems, especially Linux
  • Knowledge of computer networking and firewalls
  • Experience with Kubernetes
  • Understanding of NIST CSF, CIS, SOC 2, and PCI-DSS security and compliance frameworks
  • Excellent communication skills for explaining technical risk to executives, engineers, and business partners
  • Experience developing security metrics and reporting to senior leadership
  • Ability to work in a hybrid model from the Concord office at least three days per week
  • Relevant degree or equivalent experience, training, or transferable skills
  • Curiosity about emerging technologies, including AI and automation for security operations

KAYAK Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about KAYAK and has not been reviewed or approved by KAYAK.

  • Leave & Time Off Breadth Time off is positioned as generous, with team‑wide downtime, paid volunteer time, and location‑specific vacation allotments in certain offices. Public descriptions also highlight generous PTO and paid sick days.
  • Healthcare Strength Health coverage is described as comprehensive, including medical, dental, vision, and mental‑health support such as Headspace and access to counseling in some programs. Employer-verified listings also reference wellness resources and related benefits.
  • Fair & Transparent Compensation Compensation philosophy emphasizes Equal Pay and a commitment to closing the global pay gap. Some job postings disclose salary ranges and note equity or bonus eligibility, reinforcing transparency for certain roles and locations.

KAYAK Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Stamford, CT
1,002 Employees
Year Founded: 2004

What We Do

KAYAK, part of Booking Holdings (NASDAQ: BKNG), is the world's leading travel search engine. With billions of queries across our platforms, we help people find their perfect flight, stay, rental car, cruise, vacation package. We also support business travelers with KAYAK for Business, our free corporate travel solution and are transforming the in-travel experience with our app and new hotel and accommodation software. Want to join a talented team that’s eager to solve the world’s travel problems (and have a bit of fun)? As an employee of KAYAK, you’ll be part of a global network including OpenTable and a portfolio of travel metasearch brands like Swoodoo, checkfelix, momondo, Cheapflights, Mundi and Hotels Combined. So join us, and help others experience the world through dining and travel.

Why Work With Us

What's most unique about KAYAK is the way we empower our team to lead their best lives - in and out of the workplace. Our Work from Almost Anywhere policy is built for and by our team. It gives us the flexibility to choose where and how we work best.

Similar Jobs

Mondelēz International Logo Mondelēz International

R&D Manager - Cote d'Or Chocolate

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
4 Locations
90000 Employees

Invenergy Logo Invenergy

Senior PI Administrator

Greentech • Real Estate • Social Impact • Energy • Industrial • Solar • Renewable Energy
Remote or Hybrid
18 Locations
2500 Employees
125K-155K Annually

Auror Logo Auror

Senior Engineering Lead (Risk Detection)

Artificial Intelligence • Big Data • Retail • Security • Social Impact • Software • Business Intelligence
Remote or Hybrid
Office, Machaze, Manica, MOZ
212 Employees
143K-190K Annually

Compa Logo Compa

Software Engineer

Artificial Intelligence • HR Tech • Software • Business Intelligence
Remote or Hybrid
4 Locations
75 Employees
125K-180K Annually

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
OmniCable Thumbnail
Other
Houston, Texas
815 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account