Description
Booking Holdings (NASDAQ: BKNG) is the world leader in online travel and related services, provided to customers and partners in over 220 countries and territories through six primary consumer-facing brands - Booking.com, KAYAK, Priceline, Agoda.com, Rentalcars.com, and OpenTable.
The mission of Booking Holdings is to make it easier for everyone to experience the world.
During 2019, the Company had consolidated revenues and net income of $15.1 billion and $4.9 billion, respectively, and a current market value of approximately $90 billion.
Booking Holdings Bangalore is a Center of Excellence based in Bangalore, India and a legal entity of Booking Holdings Inc.
The Center was created to support the increasing business demands of the Booking Holdings Brands.
The Center of Excellence provides access to specialized and highly skilled talent, leading industry best practices, and collaboration opportunities across all of the Booking Holdings brands and business units.
At Booking.com, data drives our decisions.
Technology is at our core.
And innovation is everywhere.
But our company is more than datasets, lines of code or A/B tests.
We’re the thrill of the first night in a new place.
The excitement of the next morning.
The friends you make.
The journeys you take.
The sights you see.
And the food you sample.
Through our products, partners and people, we can empower everyone to experience the world.
Role description
The Senior Penetration Tester defines and leads the execution of highly technical and specialized engagements and designs new techniques of testing based on the evolution of industry best practices over time, including emerging areas such as AI and machine learning–driven systems.
They are both performing hands-on technical testing without requiring supervision and are coordinating teams of testers to ensure that the engagement objectives are met.
They strengthen Booking’s security posture by proactively identifying vulnerabilities and security control gaps in our systems and applications.
The Senior Penetration Tester provides critical input to the Senior Manager - Threat Management with the development of the security assurance strategic plan based on subject matter expertise to increase the impact and value added through this area of focus.
The Senior Penetration Tester also helps further grow the security assurance area by mentoring other team members and members of other technical non-pentester communities within Booking.
The Senior Penetration Tester has strong stakeholder management skills that enable effective communication of technical information to multi-level (up to CISO/CSO level), technical and non-technical audiences both within Booking and the broader Booking Holdings organization.
Key Responsibilities
Defines and leads the execution of highly technical penetration tests and security assurance
engagements that deliver value to Booking by independently performing hands-on, detailed
technical tests without requiring supervision.Owns the design of new technical testing engagements to best serve the current and future
needs of the organization, being able to adapt industry best practices to the local technical
and cultural environment.Owns the responsibility to ensure that the budget allocated to pentesting activities performed
by external vendors, delivers the necessary value and results in a good return on investment.Actively contributes to the mid- and long-term security assurance strategic plan definition by
introducing domain expertise insights and ensuring the plan is effective and impactful.Grows the security assurance area of focus within security by understanding the current and
target security posture of the business and identifying the skills and resources needed to
effectively deliver on those needs.Mentors junior and core penetration testers, driving their career growth within this highly
specialized technical craft.Provides deep technical expertise to the business in the following highly specialized domains:
1.
Threat modeling
2.
Web application / API penetration Testing
3.
Mobile application penetration testing
4.
Infrastructure and cloud penetration testing
5.
Purple team assessments
6.
AI/ML-powered systems (including LLMs and AI-assisted developer tooling), identifying and exploiting AI-specific threats such as prompt injection, data poisoning, and model abuse.Provides guidance and recommendations to teams, taking into account the current state of their technical environment, their future roadmap and strategy, and the risk associated with the underlying findings and vulnerabilities.Keeps up to date with the latest developments in vulnerabilities and threats within their domain of expertise, including AI/ML-related attack techniques, using this to assess the security posture of Booking to new trends and attacksDrives and coordinates multi-disciplined teams (including internal testers, external contractors, engagement managers) to conduct and successfully deliver pentest engagements of booking systems and services.Drives the reporting of penetration test outcomes by drafting, disseminating, and presenting them to technical and non-technical stakeholders at multiple levels (junior analyst to leadership team).Collaborates and coordinates with cross-functional technical and non-technical stakeholders within Booking.com and Booking Holdings to achieve a successful testing engagement that delivers critical security value.Supports the cross-brand security assurance program throughout Booking Holdings by engaging with key security personnel (CISOs to engineers)Mentors and trains non-pentesters, such as developers and other technical roles, in the relevant aspects of penetration testing and vulnerability identification to scale their impact across the department and booking.Requirements of special knowledge/skills Required:
Threat Modeling
■ 2-3 years of threat modeling experience.
Familiarity with threat modeling
methodologies such as STRIDE or PASTA
○ Web application / API Penetration Testing
■ Expert level understanding of application security concepts at both technical and
procedural level
■ Expert level understanding and exploitation skills for web application vulnerabilities
(OWASP - SQLi, XSS, CSRF, XXE, IDOR, SSRF, etc )
■ Expertise on at least one of the following DAST tools (AppScan, BurpSuite, Acunetix,
Web Inspect, etc)
■ Experience of creating attack trees/chains
■ Experience of automating penetration testing tasks such as import API spec (
Swagger, Open API, etc ) to pentesting tools
■ Understanding (technical aspects of) penetration testing and results (including
scoping and organizing of pentests, use of vulnerability scanners, vulnerability
management tools)
○ Secure SDLC
■ Good understanding of application security tooling integration with CI/CD pipelines of
applications
■ Good understanding of how git works, good to have experience of Gitlab CI/CD
■ Ability to read code (Perl, Java, JS) and identify vulnerabilities
■ Ability to provide remediation recommendations to developers
● Infrastructure and Cloud Penetration Testing
■ 3+ years experience of performing penetration tests for infrastructure and network
■ Good understanding of kubernetes and virtualization technologies
■ Expert level understanding of vulnerabilities and exploitation techniques such as RCE,
buffer overflows, subdomain takeover, dns exfiltration, privilege escalation, etc)
■ Hands on security experience of performing cloud security reviews for at least one of
the following cloud platforms ( AWS, GCP, Azure )
● AI / ML Security
■ Hands-on experience assessing the security of AI/ML systems (including LLMs or
AI-based features), with exposure to threats such as prompt injection, data poisoning,
model exfiltration, and abuse of model-integrated tools and plugins
■ Understanding of how AI/ML components integrate into web, mobile, and backend
architectures, and how to adapt existing security testing methodologies to cover these
assets
■ Ability to translate AI-specific vulnerabilities into clear business risk and remediation
guidance for product, data science, and platform teamsManage Penetration Testing LabExperience of creating and managing penetration testing lab/infrastructureDesirable:
● 7+ years of experience in information security
● 5+ years of relevant hands-on experience in offensive security testing and engagement
management
● Expertise in at least one of the following areas: (Web) application security,
infrastructure and cloud security, mobile security
● Excellence in communicating business risk and remediation requirements from
assessments
● Excellent stakeholder management skills
● Proficient in scripting languages such as Python, PowerShell, Bash, and Ruby.
● Competent with testing frameworks and tools
● Understanding of OWASP, the MITRE ATT&CK framework and the software
development lifecycle (SDLC).
● Analytical and problem-solving mindset.
● Highly organized and efficient
Desirable:
● Experience in offensive tactics
● Software development experience
● Experience with using tools such as Burp Suite, AppScan, Acunetix , Zap ,Web Inspect, ,
Metasploit, Nessus / Qualys and OSINT tools
● One or more of the following certifications: OSCP, OSCE, GPEN, GWAPT, CEH, CISSP or
a similar recognized certification in their domain of expertise
We’re a truly global e-commerce company, with business operations in nearly every country and city on the planet.
And we want to make it easy for everyone, anywhere in the world, to pay for their travel or do business with our platform - whenever and however it’s convenient for them.
Through the Booking Holdings brands, we help our customers reach all corners of the earth.
Our ability to provide great service rests on how well we understand our diverse customer base, which is why having a diverse team is so important to us.
We bring together employees from all walks of life and we are proud to provide the kind of inclusive environment that stimulates innovation, creativity and collaboration.
EEO Statement:
Booking Holdings is an equal opportunity employer in accordance with all applicable federal, state and local laws.
We ensure equal employment opportunity to all employees and applicants without discrimination or harassment based on race, religious creed, color, age, sex, sexual orientation, gender identity, national origin, religion, marital status, medical condition, disability, military service, pregnancy, childbirth and related medical conditions, or any other classification protected by federal, state, or local law.
Booking Holdings also extends this policy to every phase of the employment process including, but not limited to, recruitment, selection, placement, transfer, training and development, position elimination, restructure, promotion, compensation, benefits, layoffs, termination, and all other conditions or privileges of employment.
Booking Holdings and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers including individuals with disabilities and veterans with disabilities.
If you have a disability and believe you need reasonable accommodation in order to search for a job opening or apply for a position, please email reasonableaccommodation@bookingholdings.com with your request.
M/F/V/D/SO
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law.
Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law.
Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.