Expedia Group · 9 hours ago
Director, Cyber Risk Management
Expedia Group is a technology company that partners with product teams to create innovative services for travelers. The Director of Cyber Risk Management will lead the development and implementation of a proactive cyber risk management program, ensuring the security of the company’s digital landscape and aligning with strategic goals.
Responsibilities
Develop and implement a multi-year, proactive cyber risk management program, establishing clear governance, risk appetite, and ownership
Oversee the end-to-end risk lifecycle, from identification and assessment using NIST-aligned methodologies to response, monitoring, and authorization
Advise executive leadership and the board on our cyber risk posture, presenting clear insights and metrics to support strategic decision-making
Drive operational excellence by formalizing exception handling, automating workflows, and integrating risk management into agile and DevOps processes
Lead the achievement and maintenance of alignment with NIST CSF maturity goals and other key compliance frameworks
Build, lead, and mentor a high-performing risk management team, fostering a culture of collaboration, accountability, and continuous improvement
Champion change management strategies to support workforce transformation, including upskilling and AI fluency initiatives
Collaborate with engineering, product, security, privacy, and compliance teams to deliver integrated risk and governance strategies
Model and reinforce Expedia Group’s values, promoting an environment where people feel valued, motivated, and inspired to excel
Qualification
Required
Bachelor's degree in a related technical field; or Equivalent related professional experience
10+ years of experience in cyber risk management
5+ years of experience in managing teams
Experience building and deploying scalable risk programs in an enterprise environment
Demonstrated success in cross-functional leadership, proficient executive communication, and influencing across multiple levels
Proven ability to assess and manage risks in cloud-native architectures (AWS, Azure, GCP), agile development, and data-driven platforms
Deep understanding of risk management methodologies (NIST CSF, ISO 31000, COSO ERM) and regulatory frameworks (SOX, PCI, SOC 2, GDPR, CCPA)
Preferred
Experience within high-growth technology or SaaS environments
Industry certifications such as CRISC, CISA, CISSP, or ISO 31000
Experience with automation, risk register normalization, and continuous monitoring of key controls
Experience collaborating across GRCP functions and with privacy, legal, and IT to deliver integrated risk and governance strategies
Experience in advocating for inclusive talent practices that attract and retain diverse, high-potential individuals prepared to lead in a dynamic environment
Benefits
Medical/dental/vision
Paid time off
Employee Assistance Program
Wellness & travel reimbursement
Travel discounts
International Airlines Travel Agent (IATAN) membership
Company
Expedia Group
At Expedia Group (NASDAQ: EXPE), we believe travel is a force for good – it opens minds, builds connections, and bridges divides.
H1B Sponsorship
Expedia Group has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (519)
2024 (410)
2023 (382)
2022 (629)
2021 (483)
2020 (366)
Funding
Current Stage
Public CompanyTotal Funding
$4.25BKey Investors
TCV
2025-02-21Post Ipo Debt· $985M
2020-04-23Post Ipo Equity· $1.2B
2020-04-23Post Ipo Debt· $2B
Recent News
PhAndroid.com
2026-01-07
2026-01-07
Company data provided by crunchbase