Description
Director Central Tech and SSF Risk Operations
About Booking.com
Established in 1996 in Amsterdam, Booking.com has grown from a small Dutch start-up to one of the largest ecommerce companies in the world.
Booking.com is the largest business within Booking Holdings (NASDAQ: BKNG) and accounts for the vast majority of Booking Holdings’ total revenue.
Booking Holdings is a leading Fortune 500 e-commerce conglomerate with a market cap of roughly $119,69 billion (2023).
Booking.com currently employs approximately 13,000 employees in 140 offices in 70 countries worldwide.
With a mission to make it easier for everyone to experience the world, Booking.com invests in digital technology that helps take the friction out of travel.
Booking.com connects travellers with the world’s largest selection of incredible places to stay, including everything from apartments, vacation homes, and family-run B&Bs to 5-star luxury resorts and even tree houses.
The Booking.com website and mobile apps are available in over 44 languages, offer more than 28M total reported listings, and cover over 174,000 destinations in 229 countries worldwide.
Offering 30 different types of places to stay, including homes, apartments, B&Bs, hostels, farm stays, bungalows, even boats, igloos, and treehouses.
So whether travelling for business or leisure, customers can instantly book their ideal accommodation quickly and easily, without booking fees and backed up by its promise to price match.
Via the customer experience team, customers can reach Booking.com 24/7 for assistance and support in over 44 languages, any time of the day or night.
At Booking.com, we are all involved in making hundreds of decisions every day.
The decisions we make are a reflection of our Values - they reflect what is important to us, both as individuals and as an organisation.
When Values are made explicit, they provide clarity on what “good” looks like.
And when they are shared, they build unity in a group.
They build culture.
Think customer first.
We obsess about adding value for our customers - guests, partners, colleagues - to make it easier for everyone to experience the world.Own it.
We deliver on our promises, make informed decisions and prioritize to get the important things done today.Learn forever.
We are resilient, take time to reflect, and seek to learn – from colleagues, from the outside world and from our failures.Succeed together.
We celebrate team success, through making connections, building trust and valuing the diverse perspectives of others.Do the right thing.
We get the right results the right way.
For each other, our communities and the world around us.
Central Tech - Security, Safety & Fraud (SSF)
The Central Tech - Security, Safety, & Fraud department is looking to hire a Director of Central Tech and Security, Safety & Fraud Risk Operations.
This role is pivotal in shaping our security posture and communicating risks to leadership.
We are looking for a dynamic leader with a passion for security, technology and risk management, ready to make a significant impact by taking into consideration today's evolving digital world.
You will lead risk management efforts across multiple domains, including our Central Tech organisation and the domains of cybersecurity, physical security, fraud, trust and safety across Booking.com.
You will drive impactful initiatives while encouraging a collaborative and inclusive work environment.
Responsibilities:
Reporting to the Senior Director Tech Risk Operations, you will lead and develop a team of 50 employees at Booking.com across the locations of Amsterdam, Manchester, Bucharest and Bangalore.
This role is located in Amsterdam.
You will be responsible for:
Risk Management activities for the Central Tech organization which includes: Core Platforms, IT Services, Data & Machine Learning Platform.
Risk Management activities for the domains of Security, Safety, Fraud and Security in AI/ GenAI Security Awareness GRC Product Policy management Controls and Frameworks
More specifically:
Leadership in Security Risk Management: Lead efforts in safeguarding the organisation's digital and physical assets through robust risk management strategies.Governance Risk & Compliance (GRC): You will have responsibility for GRC for Booking.com SS&F risk subject areas.
This includes the process for creating, updating, and leading SS&F-related policies, standards, and guidelines; as well as providing the risk register for SS&F risks across the enterprise.
You will lead the “next generation” GRC vision for Security Safety and Fraud anchored on product and engineering principles.
First Line of Defence: You will be responsible for the first line risk management activities within the Central Tech organization which includes: providing proactive risk insights, reporting to Central Tech Leadership team & supporting management decisions through proactive risk assessments in various strategic programs.Framework Implementation and risk registers: You will maintain and evolve the risk management system frameworks for Cybersecurity, Trust & Safety, Fraud, & Physical Security.
Drive consistent, repeatable, measurable risk identification, assessment, and mitigation processes.
You will maintain and mature the processes for the risk registers for cybersecurity, fraud, trust & safety, and global security & resilience.Communication and Reporting: You will ensure open and timely reporting on risk posture to leadership and relevant collaborators.Business Partnership: You will collaborate with Central Tech leaders and with the Business Information Security Officers, to communicate risks and develop remediation plans, ensuring alignment with risk management strategy.
You will work with stakeholders across the company to embed risk management into business operations.
Adaptability & Continuous improvement: You will respond and adjust to changing risk management regulatory requirements and emerging threats to maintain effective risk management practices.
You will establish a resilient and repeatable and continuously improving risk management process.
Ideal Experience & Skills:
At least 10 years of experience in Cyber Security (preferred) or Fraud, with significant years leading high-performing, impactful teams.
A dynamic leader with experience in risk management organisational change, influencing executives and or the board.Experienced in cloud-based security frameworksAn enthusiastic and persuasive leader who has driven successful risk management programsA patient and relaxed leader who is skilled at translating technical risks to non-technical audiencesDirect, creative problem solver able to communicate concepts to a broader audience and create clarity.Experience in driving security with engineering teams to embed this in ways of working.Experience in collaborating with finance teams on finance based risk, using a data driven approach.
(e.g quantify how much we have spent in a risk project vs how better prepared we are to face risks) Connects disparate risks to create a clear overall risk pictureConfident leader, adept at handling conflicting prioritiesA balanced background between creating and implementing strategy.
Operational efficiency metrics.Preferred certifications: CISM, CISSP, COSO ERM, or similar risk management certificationOrganised with strong attention to detail and execution skillsFamiliarity with risk frameworks: NIST, ERM GDPR, ISO 27001, NYDFS, etc.Experience in matrix or federation environmentsOTHER PERSONAL CHARACTERISTICS
Character traits: Respectful, high emotional intelligence, and collaborative work style.
Comfortable with ambiguity, creating clarity.Consensus-driven, achieving collaborative solutionsIntegrity, independent thinking, and courageThrives in fast-paced, demanding environmentsOpen mind, learning demeanour, transparent behaviour, positive, multitasker, strong communicator, proactive and collaborative.Strategic problem solver yet focused on execution; able to roll up sleeves to get things done.Data driven, experimental, ready to learn and open to change.Keep the customer at the centre of everything you do.Good cultural and organisational sensitivity.Committed to building a diverse, inclusive work environment.
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law.
Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.