Back to jobs
New

VP, Security

Remote - US

About Engine

Engine is the all-in-one travel and spend management platform trusted by 38K+ businesses and groups representing 1.8M+ travelers. We're the retailer and the rails of business travel, one of the fastest-growing companies in travel tech, built on a decade of proprietary technology, supply, and pricing no one else can replicate. Other travel and AI companies run on our infrastructure to book real trips, hold rates, and move payments, without building any of it themselves. We built it, AI-forward at every layer, from how travelers book to how the rails run.

That work has earned recognition as one of Fast Company's Best Workplaces for Innovators (2025), TravelTech's Reservation Platform of the Year (2026), and one of Built In's Best Places to Work (2020–2026).

We're looking for bold, ambitious people to help redefine how businesses manage and experience travel. Working here, you can expect exponential growth, an ambitious pace, full ownership, and high-caliber colleagues who push you to do the best work of your career. Every hire raises the bar. 

Come outpace the ordinary and build the future of travel with us.

The Role

We're hiring a VP of Security to own security at Engine end to end: strategy, engineering, operations, and the trust posture that carries us through future funding and beyond. This is not a maintain-the-program role. The program is healthy: clean SOC 2 and PCI audits, established AppSec, SecOps, and CloudSec functions, modern tooling across the stack. The mandate is to build what comes next.

What comes next is AI. Agents inheriting human credentials in cloud environments with real access sprawl. Prompt injection and data exfiltration attempts against customer-facing AI surfaces. Shadow AI usage across every function of the business. Non-engineers shipping AI-built software that never touches a review path. Adversaries using the same models we do, at machine speed. We need a leader who sees this wave clearly, has strong conviction about what to build, and can stand up net-new AI security capability while keeping the fundamentals sharp.

This role reports directly to the SVP of Engineering and AI and operates as a peer to senior engineering leadership. You'll represent security to the executive team, the board, and enterprise customers.

What You'll Own

  • AI Security (the priority). Stand up our AI security function from approved headcount. Build the internal AI gateway: single controlled egress for all internal AI usage, with authN, per-tool authZ, central prompt and output logging, inline DLP, and model allowlisting that discovers and absorbs shadow AI. Define agent identity in AWS so agents get scoped roles and short-lived credentials, never inherited human permissions. Harden consumer-facing AI surfaces: authenticated MCP with gateway-enforced per-tool authorization, a bad-prompt detection pipeline feeding the SIEM, output filtering on sensitive fields, and a red team scenario suite that runs as CI regression on every AI surface.
  • Security Engineering. Lead AppSec and SecArch, SecOps, and CloudSec, roughly ten people at full staffing across the current team and approved reqs, plus the corporate IT function. Drive the roadmap already in motion: secure-by-design intake, secrets refactoring, org-wide RBAC mapped to Okta groups, detection engineering on our next-gen SIEM, automated response playbooks, and identity log onboarding across Okta, Salesforce, and AWS.
  • GTM and Operations Security. Harden how the business operates: Salesforce least privilege, contractor and BPO access through VDI on managed hardware, insider threat monitoring, and production data hygiene.
  • Enterprise Trust and Series D Readiness. Own the security narrative for fundraising diligence and enterprise sales. Run point on customer security reviews and build the trust artifacts that shorten enterprise deals. Own the technical controls behind SOC 2 and PCI in close partnership with our legal team, which owns compliance, privacy, and audit programs.
  • Corporate IT. Own identity, endpoint fleet, and SaaS administration. Our Okta unification work makes identity the connective tissue between security and IT, and this role owns both sides of it: joiner-mover-leaver automation, entitlement hygiene, and a managed environment that holds up as agents become first-class users of our systems.

What Success Looks Like in Year One

  • AI security team hired and shipping: internal AI gateway live, agent identity model enforced ahead of broad agent rollout, prompt abuse pipeline running in production
  • security diligence and a customer-facing trust posture that accelerates enterprise deals rather than slowing them
  • RBAC, secrets remediation, and JML automation moving access from person-accumulated to role-driven
  • SOC 2 and PCI technical controls sustained without heroics, with a crisp operating boundary established with legal's compliance and privacy function
  • A security org that engineering wants to work with: gates that block only when the issue is real and the fix is clear

Who You Are

  • 12+ years in security with 5+ leading security organizations, ideally through hypergrowth and a major fundraise or IPO-track diligence process
  • Deep technical credibility: you can whiteboard an agent identity model, argue the details of an AI gateway architecture, and review a detection engineering backlog without a translator
  • Genuine, current conviction about AI security. You've thought hard about prompt injection, agentic access, model-mediated data exfiltration, and LLM red teaming, and you have opinions about what actually works
  • Builder of net-new functions, not just an operator of mature ones. You've taken a domain from zero headcount to a working team with real controls
  • Fluent in cloud-native security: AWS identity, CSPM, EDR and SIEM operations, modern AppSec tooling in CI
  • Comfortable owning corporate IT: identity platforms, endpoint fleets, and SaaS governance as extensions of the security mission, not a side duty
  • Executive presence: you can brief a board, close an enterprise customer's security review, and tell leadership no with a better alternative attached
  • Bias toward enablement. You believe security's job is to make the safe path the fast path, and you remove low-value controls as readily as you add high-value ones

Nice to Have

  • Experience securing customer-facing AI or LLM products at scale
  • Background in payments, travel, or another PCI-regulated, high-transaction-volume environment
  • Experience partnering with legal on privacy programs and regulatory frameworks (GDPR, CCPA, emerging AI regulation)

Why This Role

Most VP of Security roles are about maturing what exists. This one is about defining how an AI-native company defends itself while the threat model is still being written. You'll inherit a clean foundation, approved headcount, executive air cover, and a company that treats AI as its operating model rather than a feature. Join us on this mission to reshape how businesses experience travel, and help build the security foundation every AI at Engine runs on.

We accept applications for this role on an ongoing basis. We review applications as they are received and encourage interested candidates to apply early.

Compensation
Our compensation packages are based on several factors, including your experience, expertise, and location. In addition to a competitive base salary, all roles receive equity. Depending on the role, total compensation may also include an annual bonus. Your recruiter will share your complete compensation package as you move through the process.

Base Pay Range

$298,000 - $400,000 USD

The Engine Edge: Perks & Compensation
We believe in rewarding great work with great benefits:

  • Compensation: Competitive base pay tied to role and experience, with equity for all employees. Some roles are also eligible for bonuses or commissions.
  • Benefits: Check out our full list at engine.com/culture 
  • Environments for Success: Different roles have different needs in terms of the environments that drive success which is why we have a hybrid-hub model. Whether you are in one of our amazing offices or fully remote, we'll make sure you have what you need to succeed.

Perks and benefits may vary based on employment type, location, and more

Create a Job Alert

Interested in building your career at Engine? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...

Select...
Select...

If you’ll require Engine to commence, i.e., “sponsor,” an immigration or work permit case in order to employ you, either now or at some point in the future, then you should answer yes. An example of an immigration or work permit case that may require sponsorship now or in the future would be an H-1B or other employment-based work permit sponsorship.

Select...