Description
Booking Holdings Romania is a Center of Excellence based in Bucharest, Romania and was created to support the increasing business demands of the Booking Holdings Brands.
The Center of Excellence provides access to specialized and highly skilled talent, leading industry best practices, and collaboration opportunities across all of our Brands.
As part of our Booking Holdings Romania team, you will have the opportunity to be a part of the world’s leading provider of online travel, with a mission of making it easier for everyone to experience the world through five-primary consumer facing brands: Booking.com, Priceline, Agoda, KAYAK and OpenTable.
This role provides a hybrid way of working with an onsite presence of 2 days/week.
Role description
The Senior Cyber Security Incident Responder is a key player in providing in-depth investigation and response to cyber security attacks and threats such as ransomware, spear-phishing, cloud-based or supply chain attacks, and Advanced Persistent Threats (APTs).
This highly specialized technical subject matter expert position focuses on investigating threats and alerts within large-scale cross-platform environments, performing threat hunting and digital forensics in order to identify intrusions and effectively respond to mitigate security threats on the business.
Key Job Responsibilities and Duties
Investigate and validate incidents escalated by the BKNG CDR team (assessing escalation, evidence completeness, and initial hypothesis).
Lead complex security investigations end-to-end, from initial triage through containment, eradication, recovery, and post-incident review.
Act or support the incident lead or incident commander for high-priority and high-severity incidents..
Coordinates incident, response, escalation, and reporting of cybersecurity incidents.
Performs technical investigation on complex security incidents to achieve efficient mitigation for active threats and identification of the root cause.
Perform hands-on log analysis, endpoint forensics, identity investigation, cloud investigation, email investigation, network analysis.
Investigate and respond to AI/LLM-specific incidents (prompt injection, model or agent misuse, AI sandbox escapes, AI supply chain risks).
Contribute to emerging AI threat detection and response (AIDR) playbooks and readiness.
Collaborates on various departmental projects that help the organization improve its cyber security posture and achieve its mission/objectives.
Collaborates with different CDR stakeholders and vendors to remediate any identified gaps.
Define and use CSIRT’s playbooks, runbooks, workflows, operational documentation, and processes.
Contributes to the writing and maintenance of all such documents.
Looks for opportunities to improve documentation and standardization of CSIRT processes.
Owns and delivers on assigned projects (often around automations, AI usage, and improvements to detections, processes and playbooks) while balancing execution and deliveries with operations and IR workload; Supports other team members in projects.
Identify detection gaps, false positive drivers, visibility gaps, and automation opportunities based on investigation findings.
Contribute to the design and improvement of detection rules, workflows, and operational automation.
Drive threat hunting to proactively identify threats and validate detection coverage.
Participate in tabletop exercises, retrospectives, lessons-learned sessions, and service improvement initiatives.
Mentor and technically guide other analysts: improving investigation quality, structure, and consistency across the team
Review investigation work and escalation packages for quality and completeness.
Share knowledge through team & community sessions, written documentation, and informal coaching.
Works on shifts covering 16/5 (Monday to Friday, 7 AM - 10 PM).
Offers on-call support during the nights, weekends and public holidays.
Role Qualifications and Requirements
This role requires technology subject matter expertise in performing hands-on technical incident response, in-depth technical investigations and Threat Hunting.
It is an individual who reads logs, collects technical evidence and puts together the full picture.
The ideal candidate is well plugged in the world of hacking and defense and adversary techniques, all with a hands-on keyboard perspective.
5+ years of hands-on operational security experience in incident response, SOC, threat hunting, or CSIRT roles.
Relevant certifications such as GCIH, GCIA, GCFA, GCFE, GCFR, GREM, GEIR, GCIL, GSEC, GCED, AWS, OSCP, OSCE, or equivalent.
Strong, demonstrable experience leading complex investigations across multiple evidence sources and domains.
Practical experience as incident lead or support/scribe analyst during high-severity incidents.
Deep understanding of attacker techniques, tactics, and procedures & practical application of frameworks such as MITRE ATT&CK
Strong endpoint investigation experience: process trees, command-line analysis, persistence mechanisms, lateral movement artifacts etc.
Strong identity investigation experience: account compromise, MFA bypass, session hijacking, identity provider abuse.
Strong cloud security investigation experience (AWS, GCP, Azure).
Ability to analyse logs from multiple sources and reconstruct incident timelines.
Ability to operate effectively under pressure, with ambiguous information, and within time constraints.
Ability to write clear, structured investigation summaries and executive-ready incident updates.
Ability to coordinate across technical and non-technical stakeholders during active incidents, if needed.
Ability to mentor analysts and improve team investigation quality.
Strong judgement for containment and escalation decisions: knowing when to act, when to wait, and when to escalate.
Experience working with external MSSPs: understanding service boundaries, escalation protocols, and quality governance.
Experience with building or improving automation workflows.
Experience investigating supply chain compromises, developer tooling abuse, or CI/CD pipeline threats.
Experience with macOS and Linux forensics in addition to Windows.
Comfortable using AI-assisted tooling (copilots, agentic automation) to accelerate triage, investigation, response and documentation.
Highly disciplined and motivated: a self-starter who is able to both work independently or as a member of a team.
Demonstrates a Can-Do, delivery-focused and solution-oriented approach (rather than problem-oriented); Flexible, practical, and positive mindset.
Is quick to adapt to changing situations.
Constantly demonstrates ownership and proactiveness in seeking to improve and optimize in anything related to their and their team’s work.
Familiarity with AI/LLM attack surfaces and emerging AI-specific threat patterns (prompt injection, model exfiltration, agentic tool misuse).
( Preferred)
Benefits & Perks
Contributing to a high scale, complex, world renowned product and seeing real-time impact of your work on millions of travelers worldwide
Working in a fast-paced and performance driven culture
Technical, behavioral and interpersonal competence advancement via on-the-job opportunities, experimental projects, hackathons, conferences and active community participation
Competitive compensation and benefits package
Vast amounts of data to validate your ideas and the opportunity to experiment with real users
Booking Holdings is proud to be an equal opportunity workplace and is an affirmative action employer.
All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law.
Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.