VP, Security

๐Ÿข Engine ยท all 94 jobs
๐Ÿ“ United States
๐Ÿ’ฐ USD 298,000 - 400,000 / annual
๐Ÿ“… Posted Sep 18, 2026 ยท via Himalayas
๐Ÿท Vp Security, Security Leadership, AI Security, Security Engineering, Corporate Security, Vp Product Security +6 more
Apply on original site โ†—

About Engine

Engine is the all-in-one travel and spend management platform trusted by 38K+ businesses and groups representing 1.8M+ travelers. We're the retailer and the rails of business travel, one of the fastest-growing companies in travel tech, built on a decade of proprietary technology, supply, and pricing no one else can replicate. Other travel and AI companies run on our infrastructure to book real trips, hold rates, and move payments, without building any of it themselves. We built it, AI-forward at every layer, from how travelers book to how the rails run.

That work has earned recognition as one of Fast Company's Best Workplaces for Innovators (2025), TravelTech's Reservation Platform of the Year (2026), and one of Built In's Best Places to Work (2020โ€“2026).

We're looking for bold, ambitious people to help redefine how businesses manage and experience travel. Working here, you can expect exponential growth, an ambitious pace, full ownership, and high-caliber colleagues who push you to do the best work of your career. Every hire raises the bar.

Come outpace the ordinary and build the future of travel with us.

The Role

We're hiring a VP of Security to own security at Engine end to end: strategy, engineering, operations, and the trust posture that carries us through future funding and beyond. This is not a maintain-the-program role. The program is healthy: clean SOC 2 and PCI audits, established AppSec, SecOps, and CloudSec functions, modern tooling across the stack. The mandate is to build what comes next.

What comes next is AI. Agents inheriting human credentials in cloud environments with real access sprawl. Prompt injection and data exfiltration attempts against customer-facing AI surfaces. Shadow AI usage across every function of the business. Non-engineers shipping AI-built software that never touches a review path. Adversaries using the same models we do, at machine speed. We need a leader who sees this wave clearly, has strong conviction about what to build, and can stand up net-new AI security capability while keeping the fundamentals sharp.

This role reports directly to the SVP of Engine ering and AI and operates as a peer to senior engineering leadership. You'll represent security to the executive team, the board, and enterprise customers.
What You'll Own

- AI Security (the priority). Stand up our AI security function from approved headcount. Build the internal AI gateway: single controlled egress for all internal AI usage, with authN, per-tool authZ, central prompt and output logging, inline DLP, and model allowlisting that discovers and absorbs shadow AI. Define agent identity in AWS so agents get scoped roles and short-lived credentials, never inherited human permissions. Harden consumer-facing AI surfaces: authenticated MCP with gateway-enforced per-tool authorization, a bad-prompt detection pipeline feeding the SIEM, output filtering on sensitive fields, and a red team scenario suite that runs as CI regression on every AI surface.

- Security Engine ering. Lead AppSec and SecArch, SecOps, and CloudSec, roughly ten people at full staffing across the current team and approved reqs, plus the corporate IT function. Drive the roadmap already in motion: secure-by-design intake, secrets refactoring, org-wide RBAC mapped to Okta groups, detection engineering on our next-gen SIEM, automated response playbooks, and identity log onboarding across Okta, Salesforce, and AWS.

- GTM and Operations Security. Harden how the business operates: Salesforce least privilege, contractor and BPO access through VDI on managed hardware, insider threat monitoring, and production data hygiene.

- Enterprise Trust and Series D Readiness. Own the security narrative for fundraising diligence and enterprise sales. Run point on customer security reviews and build the trust artifacts that shorten enterprise deals. Own the technical controls behind SOC 2 and PCI in close partnership with our legal team, which o

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels โ†’

โ† All remote jobs

Get new remote jobs like this by email
Daily email, only when there's something new. One click to stop.

Get remote jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you