Kayak

Director of Cybersecurity

Concord Office · Posted 3h ago

$200-220Kdirectorpermanenthybrid

Job Description

KAYAK, part of Booking Holdings (NASDAQ: BKNG), is a leading travel search engine. With billions of queries across our platforms, we help people find their perfect flight, stay, rental car and vacation package. We're also transforming business travel with a new corporate travel solution, KAYAK for Business.

 

As an employee of KAYAK, you will be part of a travel company that operates a portfolio of global metasearch brands including momondo, Cheapflights and HotelsCombined, among others. From start-up to industry leader, innovation is in our DNA and every employee has an opportunity to make their mark. Our focus is on building the best travel search engine to make it easier for everyone to experience the world.


KAYAK's Security team exists to protect the company and its customers through comprehensive, agile, and collaborative security measures — with a human approach to policy, training, and awareness. We follow the NIST Cybersecurity Framework across six domains (Govern, Identify, Protect, Detect, Respond, and Recover).

We are looking for a Director of Cybersecurity to lead a global team of security engineers. This is a hands-on leadership role for an experienced security practitioner who will set direction for our technical security programs, support the growth of their team, and work closely with engineering and infrastructure partners to keep our systems and people secure — balancing strong protection with the business's need for agility and innovation.

This role is required to work from our Concord, MA office 3 days a week.

 

In this role, you will:

  • Partner with the CISO and other senior teammates to define and execute the organization’s cyber security strategy, roadmap, and operating model, ensuring security initiatives are measurable, operationally actionable, and aligned with business priorities.

  • Lead, mentor, and support a global team of security engineers across multiple disciplines, including incident response, vulnerability management, identity and access management and application security.

  • Own the day-to-day operations of the security program — including threat detection and response, vulnerability management, and endpoint security — and ensure the team has the support and clarity needed to execute effectively.

  • Partner with engineering, infrastructure, and product teams to embed security into how we build and operate systems.

  • Manage vendor relationships and contribute to budget planning for security tooling and services.

  • Support the hiring, onboarding, and career development of your team members, fostering a culture of learning, collaboration, and continuous improvement.

  • Explore and champion the use of AI and automation to improve how the team operates — this is an active area of investment for us.

  • Evaluate emerging threats and technologies, including the security implications of artificial intelligence and other new capabilities.

 

Please apply if you have:

  • 10 or more years of progressive experience in cybersecurity or a closely related field, including significant people-leadership experience.

  • Demonstrated success building or maturing security programs in a complex, technology-driven environment.

  • Strong experience across multiple security domains — such as security operations, incident response, vulnerability management, IAM, cloud security, application security, or security architecture.

  • Strong technical skills in endpoint and server operating systems (especially Linux), computer networking, firewalls, and Kubernetes.

  • General understanding of security and compliance frameworks (NIST CSF, CIS, SOC 2, PCI-DSS).

  • Excellent communication skills, with the ability to explain technical risk clearly to executives, engineers, and business partners.

  • Experience developing meaningful security metrics and reporting progress to senior leadership.

  • The capacity to thrive in a hybrid working model, including the ability to attend the Concord office at least 3 days a week.

  • A degree in a relevant field is welcome; equivalent experience, training, or transferable skills are equally valued.

  • Curiosity about emerging technologies, including how AI and automation can improve security operations.

 

Benefits and Perks

  • Work from (almost) anywhere for up to 20 days per year

  • Focus on mental health and well-being:

    • Company-paid therapy sessions through SpringHealth

    • Company-paid subscription to HeadSpace

    • Company-wide week off a year - the whole team fully recharges (and returns without a pile-up of work!)

    • No meeting Fridays

    • Paid parental leave

    • Generous paid vacation + time off for your birthday

    • Paid volunteer time

  • Focus on your career growth:

    • Development Dollars

    • Leadership development

    • Access to thousands of on-demand e-learnings

  • Travel Discounts

  • Employee Resource Groups

  • Competitive retirement and health plans

  • Free lunch 2 days per week

  • Fun quarterly events such as boat trips, arcades, ski trips, Thursday happy hours, and more


There are a variety of factors that go into determining a salary range, including but not limited to external market benchmark data, geographic location, and years of experience sought/required. The range for this Massachusetts based role is $200,000-220,000, not inclusive of annual bonus and recurring RSU grants.

 

We offer a competitive base salary and benefits including: health benefits; flexible spending account; retirement benefits; life insurance; paid time off (including PTO, paid sick leave, medical leave, bereavement leave, floating holidays and paid holidays); and parental leave benefits.

 

Inclusion

At KAYAK, we want everyone to have the space to grow, share ideas and do great work. That's why we're focused on hiring the best talent from all walks of life and experiences, supporting them well and making sure no one feels like they have to fit a mold to belong here.

 

Need any adjustments for the interview, application or on the job? No problem - just give us a heads-up. We've got you.