Description
Role Overview:
This is a leadership role at the heart of a highly mature capability within our Enterprise Security Cyber Defence organisation.
If you build threat-informed defence for a living and want to lead exceptional people doing it at scale, read on.
This team exists to stay ahead of adversaries, understanding how they operate, closing the gaps that matter before they can be exploited, and engineering scalable, production-grade solutions that make our cyber defence faster and more effective.
Threat-informed defence is the heartbeat of this team: study how real adversaries operate, then turn that insight into measurable protection across a large, global technology environment.
It's a group of nine specialists across Amsterdam and Bucharest, a mix of senior and core threat researchers and engineers operating as one team across two connected disciplines.
On the research side, they turn the world's threat reporting APT and ransomware tradecraft, supply chain attack trends, emerging AI-driven threats into action in our environment: proactive threat hunts, custom detections, custom preventions, and continuously maturing response playbooks.
They run adversary emulation and security-control validation week in, week out to prove our defences against real tradecraft then close the gaps they find, themselves and with partner teams.
Proactive, not reactive.
On the engineering side, they bring detection and response engineering built to a modern industry standard: high-fidelity detection-as-code, telemetry and log-source onboarding, platform and pipeline health, and coverage engineered deliberately against MITRE ATT&CK.
They own the full lifecycle not just shipping a detection, but monitoring it, tuning it, managing false positives, and supporting it in production.
And they build the automation, SOAR workflows, and AI-driven capabilities that strip out manual toil and make the wider defence organisation faster so skilled people spend their time on the problems that genuinely need human expertise.
Everything this team does exists to make detection and response sharper, coverage broader, and investigations faster.
Key Job Responsibilities and Duties:
Shape strategy in partnership with leadership — translate the broader Cyber Defence strategy into a clear, risk-based plan for the team, set priorities, and own resource assignment and capacity planning so the team works from one aligned plan
Expand coverage where it counts most — lead the push for high-value telemetry and detection coverage across our crown jewels, identity, cloud, and the parts of the estate where visibility doesn't exist yet or needs maturity, always knowing where we're strong and where to invest next.
Establish detection & response engineering at scale — bring the cutting edge of how the industry does detection engineering into how we do it: detection-as-code, peer review, testing and validation, CI/CD, tuning, and retirement of stale logic — and make sure prototypes become documented, tested, maintainable, supportable production capabilities, not one-off experiments.
Run validation as a program — own a structured adversary-emulation and control-validation practice that mimics real adversary behaviour to test our detection and response, surface the gaps that matter, and drive them to documented closure — sharpening investigation speed and quality along the way.
Own the metrics — design, track, and report the KPIs that prove the team's value: ATT&CK-aligned coverage, detection quality and false-positive performance, validation and gap-closure outcomes, automation impact, and improvements in detection and response effectiveness — turning them into decisions and investment cases
Use AI as a force multiplier — drive automation and AI to ship detections faster and at greater scale than rule-writing alone allows, and to make investigation and response more efficient so specialists spend their time on the meaningful, complex work that genuinely needs human expertise.
Lead exceptional people — this is a people-first role above all.
Build visibility & partnerships across the business — represent the team's program clearly to senior leadership, and collaborate with a broad set of stakeholders across the organisation Enterprise IT, product security, infrastructure security, and the wider cyber defence portfolio challenging requests that aren't risk-based or scalable.
The leadership this team needs
Confidently lead experienced specialists with strong technical viewpoints creating alignment and clear direction while keeping constructive debate healthy.
Bring structure and prioritisation to senior people: aligned autonomy, clear ownership, and accountability for finishing and productionising what they start.
Coach senior researchers and engineers to grow their impact, and build cohesion across two locations so where you sit never limits your visibility or your work.
Create genuine psychological safety — empathy, humility, room to raise concerns early alongside clear expectations and honest performance conversations.
Delegate well and protect the team from fragmented, low-value work, so deep talent stays focused on what matters.
Connect the team's technical work to business and risk outcomes, and carry that story upward with credibility.
Role Qualifications and Requirements:
5+ years in cybersecurity, security engineering, threat research, or detection & response.
2+ years directly managing and developing engineers, researchers, or other senior technical specialists.
Real breadth across both worlds: threat hunting / research / adversary emulation and detection engineering / telemetry / SIEM / SOAR / response automation this is not a hands-on-keyboard role, but you carry enough technical depth to challenge methodology and evidence, review engineering proposals with judgement, and win the respect of a team of experts.
Fluency in adversary TTPs, MITRE ATT&CK, and modern detection engineering practice (detection-as-code, lifecycle management, coverage measurement).
A track record of moving initiatives from prototype to owned, measurable, maintained production capability.
Strong stakeholder communication — translating complex work into business impact and risk reduction.
A people-first leadership style that pairs empathy with accountability.
This role includes shared participation in the team's on-call rotation, alongside the detections and automation the team runs and supports in production.
No specific degree or certification required — proven technical and leadership impact is what matters.
Benefits & Perks - Global Impact, Personal Relevance:
Booking.com’s Total Rewards Philosophy is not only about compensation but also about benefits.
We offer a competitive compensation and benefits package, as well unique-to-Booking.com benefits which include:
Annual paid time off and generous paid leave scheme including: parent, grandparent, bereavement, and care leave
Hybrid working including flexible working arrangements, and up to 20 days per year working from abroad (home country)
Industry leading product discounts - up to 1400 per year - for yourself, including automatic Genius Level 3 status and Booking.com wallet credit
Diversity, Equity and Inclusion (DEI) at Booking.com:
Diversity, Equity & Inclusion have been a core part of our company culture since day one.
This ongoing journey starts with our very own employees, who represent over 140 nationalities and a wide range of ethnic and social backgrounds, genders and sexual orientations.
Take it from our Chief People Officer, Paulo Pisano: “At Booking.com, the diversity of our people doesn’t just build an outstanding workplace, it also creates a better and more inclusive travel experience for everyone.
Inclusion is at the heart of everything we do.
It’s a place where you can make your mark and have a real impact in travel and tech.”
We ensure that colleagues with disabilities are provided the adjustments and tools they need to participate in the job application and interview process, to perform crucial job functions, and to receive other benefits and privileges of employment.
Application Process:
Let’s go places together: How we Hire
This role does not come with relocation assistance.
Booking.com is proud to be an equal opportunity workplace and is an affirmative action employer.
All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law.
Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law.
Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.