Jobs and Careers
EX

Senior Manager, Security Governance and Trust

Expedia Group
Washington, United Statesfull_timeVerifiedPosted 20 May 2024
💰 $233,500/yr($146,000/yr$233,500/yr)

About the role

If you need assistance during the recruiting process due to a disability, please reach out to our Recruiting Accommodations Team through the Accommodation Request form. This form is used only by individuals with disabilities who require assistance or adjustments in applying and interviewing for a job. This form is not for inquiring about a position or the status of an application.

Senior Manager, Security Governance and Trust

Our worldview at Expedia Group is “Travel is a force for good”; we believe travel is a force for good in the world. You don’t have to look too closely to realize right now that the world needs all the goodness it can get – it needs more travel. And with that as our worldview, the work we do at Expedia Group becomes more important than ever. Expedia Services is where exceptional technical and businesspeople come together to leverage our two decades in travel and invest in scalable solutions.

Are you a highly motivated, experienced & curious security risk and compliance professional who can address the challenges of increasing our security posture and building trust across Expedia Group (EG)? Can you play a role in an enterprise-wide security risk and compliance strategic initiatives, collaborate cross functionally to identify and communicate security compliance requirements and provide leadership level visibility into current risk, security and compliance posture?  Do you have the discipline to deliver results with a strong passion for ownership?

The Expedia Security & Privacy Organization is seeking a highly motivated, collaborative Senior Manager for our Security Governance and Trust team. This person have a practical self-starter mindset to advise and serve as a subject matter expert and manage all aspects of NIST CSF (National Institute of Standards and Technology Cyber Security Framework) and Privacy by Design (PbD) along with areas of cybersecurity compliance included within NYDFS, CBPR, NIS 2 EU, CCPA, CPRA as well as cloud compliance in support of all areas of cybersecurity compliance.
 

In this role, you will work closely with risk, compliance and security leadership and are responsible for identifying, evaluating, and reporting on the state of NIST CSF, PbD, and other. You will be the primary point of contact for all Cybersecurity Partner Trust. You will manage a team of analysts and the annual NIST CSF lifecycle, including assessments, testing, validation of controls and documentation related to compliance. In addition, the in this role you will keep pace with regulatory changes to ensure the company maintains its positive compliance standing.

This is a unique role that will develop and drive strategy for our security governance NIST CSF program, drive operational excellence and program improvement, and accelerate our mission to power global travel for everyone, everywhere. To be successful, you are organized, resourceful, possess domain knowledge on NIST CSF, PbD principles and security compliance and have a “can-do” attitude. You will be a key member of our security governance, risk, compliance, and privacy team and responsible for providing expert risk analysis and information to business and risk management leadership. In this role, you will establish rapport with cybersecurity leadership, as well as external consultants to help support the company’s overall NIST CSF maturity and PbD principles. The role is charged with implementing and maintaining policies, as well as managing a comprehensive controls framework with industry requirements to ensure enterprise wide NIST CSF and PbD compliance.

The ideal candidate will have diverse backgrounds and understand a variety of systems and services, including new technologies and legacy systems that are intertwined within NIST CSF and PbD scope. You will report to Director Security Governance and Compliance.

We believe diversity and inclusion among our teammates produces better results and is critical to our success as a global company and are committed to recruiting, developing, and retaining the most talented people from a diverse candidate pool.

 

What you’ll do:

  • Identify and document in-scope systems and applications for the NIST CSF and PbD environments. Guide technical teams and stakeholders to implement required controls and meet compliance.

  • Act as the primary point of contact for all Cybersecurity Partner Trust, NIST CSF and PbD requirements, initiatives, and external relationships.

  • Act as the main Cybersecurity Partner Trust, NIST CSF and PbD subject matter expert when internal team members have questions/need guidance and b

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Expedia Group

View company profile →