Description
About Us
At Booking.com, data drives our decisions, technology is at our core, and innovation is everywhere.
Through our products, partners and people, we make it easier for everyone to experience the world.
Role Overview
We are looking for a Risk Officer to join our FinTech Business Unit Risk Partner team, operating as the first line of defence.
You'll partner with the Product/tech teams of Fintech as a risk subject-matter expert and help implement a robust Risk Management Process and Internal Control Framework, ensuring that business processes and IT systems operate effectively, comply with internal policies and external regulations, and that risks - including those arising from emerging technologies such as AI/ML and automation - are identified, assessed and managed proactively.
In this role you'll act as the bridge between operational business requirements and technical IT controls.
Key Responsibilities
Own risk identification and assessment across the FinTech business unit's processes and IT systems, evaluating and mitigating risks, tracking them through to formal resolution, and maintaining the risk register and remediation plans so that exposure stays visible and managed.
Design, implement and operate controls within FinTech products and platforms - including IT general controls, IT automated controls (ITACs) and reconciliation controls - across a modern, cloud-native environment of cloud services, containers, CI/CD pipelines and microservices.
Act as a SOx design authority, partnering with FinTech stakeholders to ensure critical SOx controls are adequately designed and documented, strengthening the control environment and supporting the business in achieving its objectives while keeping company risk in check.
Guide stakeholders through observations and deficiencies, providing subject-matter expertise from initial assessment and triage all the way through to mitigation and remediation at root cause.
Represent FinTech in internal, external and statutory audits and SOC engagements from the auditee side - leading walkthroughs, preparing evidence and control narratives, and responding to audit and regulatory requests.
Partner with Security and Fraud teams on internal and external fraud cases, translating case findings into concrete, durable control improvements that reduce the likelihood of similar events recurring.
Assess risks from emerging technologies such as AI/ML, GenAI, agentic AI and automation (RPA), and help design proportionate controls aligned to frameworks such as the EU AI Act and the organisation's AI risk management approach.
Embed risk ownership and a shift-left mindset within FinTech product and tech teams through enablement and training, and mentor and uplift junior members of the risk team.
Qualifications
7+ years of experience in internal controls, audit, risk management or compliance, with a bachelor's degree or higher in a relevant field.
Hands-on experience leading risk assessments and financial audits in a technologically dynamic environment, going beyond the standard risks around Access and Change Management.
Strong knowledge of IT control frameworks (COSO, COBIT, ITIL, NIST, DORA, ISO 27001 etc.) and regulatory requirements (SOX, GDPR, DMA, DSA), with experience applying them across different business areas.
Hands-on knowledge of e-money and payments regulations (e.g.
PSD2) is a strong plus, particularly in applying them to real products and controls.
Practical risk-management experience in modern engineering environments, working with DevOps and open-source tooling such as GitLab, GitHub, Jenkins, Docker, Kubernetes, Terraform or Puppet.
Familiarity with designing controls for cloud platforms is a strong plus, particularly AWS (GCP an advantage), along with exposure to data governance, SaaS applications, business continuity management and emerging technologies (AI/ML, RPA).
An IT-related degree and/or professional certifications such as CISA, CISM, CRISC, CISSP.
Strong stakeholder engagement and communication skills, with the ability to build relationships that drive a risk-management culture across the business.
A self-starter who makes sound decisions, resolves problems effectively, and thrives in a changing, agile environment.
Fully comfortable working in English, both written and spoken (additional languages a plus).
Benefits & Perks - Global Impact, Personal Relevance:
Booking.com’s Total Rewards Philosophy is not only about compensation but also about benefits.
We offer a competitive compensation and benefits package, as well unique-to-Booking.com benefits which include:
Annual paid time off and generous paid leave scheme including: parent, grandparent, bereavement, and care leave
Hybrid working including flexible working arrangements, and up to 20 days per year working from abroad (home country)
Industry leading product discounts - up to 1400 per year - for yourself, including automatic Genius Level 3 status and Booking.com wallet credit
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law.
Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.