Description
Booking Holdings Romania is a Center of Excellence based in Bucharest, Romania and was created to support the increasing business demands of the Booking Holdings Brands.
The Center of Excellence provides access to specialized and highly skilled talent, leading industry best practices, and collaboration opportunities across all of our Brands.
As part of our Booking Holdings Romania team, you will have the opportunity to be a part of the world’s leading provider of online travel, with a mission of making it easier for everyone to experience the world through five-primary consumer facing brands: Booking.com, Priceline, Agoda, KAYAK and OpenTable.
Role description
The IT Risk & Compliance Officer for Cloud is responsible for partnering with the platform and capability owners throughout the Central Tech business function to design and maintain IT security and compliance controls in line with our risk appetite and regulatory requirements and to maintain the quality of our processes.
The role requires to work closely with platform owners and development teams to have a solid high level understanding of risks, but be able to zoom in and out of the details to ensure understanding of the solution design for designing effective controls.
This role provides a hybrid way of working with an onsite presence of 2 days/week.
Key Job Responsibilities and Duties
Provide cybersecurity, IT risk, and regulatory compliance advice to platform owners, development teams, and business functions, in line with internal policies and standards such as NIST, SOX, PCI-DSS, and other relevant best practices, in order to support secure and compliant cloud adoption.
Perform IT risk assessments for new platforms and significant platform changes, using the organization’s risk and control framework, in order to identify key risks, assess control effectiveness, and recommend appropriate remediation actions.
Advise stakeholders on the design of sustainable, proportionate, and scalable controls, including cloud control requirements for identity and access management, logging, encryption, network security, and configuration governance, in order to strengthen risk management and compliance.
Develop and enhance cloud guardrails, standards, and control requirements, in line with internal governance and regulatory expectations, in order to support secure onboarding and consistent use of cloud services across platforms.
Drive the continuous improvement and harmonization of cloud controls across platforms, following internal control standards and compliance requirements, in order to simplify compliance and improve control consistency.
Coordinate with Security, Risk and Controls, Internal Audit, External Audit, Business Continuity, IT Disaster Recovery, and Service Continuity teams, and support audit evidence requests as needed, in order to ensure effective risk oversight and timely audit support.
Role Qualifications and Requirements
5 - 8 years of relevant experience
Bachelor’s Degree
Experience in Cloud Security and Compliance (AWS, GCP, Azure, etc) and DevOps domain
Familiarity/experience working with a wide range of technologies (internally developed applications, Windows, Linux, Databases, Gitlab, etc) from a risk and security perspective.
Hands-on experience in business analysis, auditing, corporate governance, risk management or internal controls.
Ability to develop solid relationships with business partners in order to drive the adoption of the risk management culture.
Basic technical understanding of internal control requirements and design and experience in applying them in various businesses.
Stay flexible to meet the dynamic business needs, while maintaining robust solutions that strengthen the IT control environment.
Able to split large tasks into logical, manageable and decoupled actions which are managed effectively and delivered on time.
Be flexible and agile in response to the change in business, change in stakeholder expectations and/or change in regulatory/operating environment of B.com.
Strong independent contributor, while still a strong team player.
Benefits & Perks
Contributing to a high scale, complex, world renowned product and seeing real-time impact of your work on millions of travelers worldwide
Working in a fast-paced and performance driven culture
Technical, behavioral and interpersonal competence advancement via on-the-job opportunities, experimental projects, hackathons, conferences and active community participation
Competitive compensation and benefits package
Vast amounts of data to validate your ideas and the opportunity to experiment with real users
Booking Holdings is proud to be an equal opportunity workplace and is an affirmative action employer.
All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law.
Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.