- The Central Tech - Security, Safety, & Fraud department is looking to hire a Director of Central Tech and Security, Safety & Fraud Risk Operations
- This role is pivotal in shaping our security posture and communicating risks to leadership
- We are looking for a dynamic leader with a passion for security, technology and risk management, ready to make a significant impact by taking into consideration today’s evolving digital world
- You will lead risk management efforts across multiple domains, including our Central Tech organisation and the domains of cybersecurity, physical security, fraud, trust and safety across Booking.com
- You will drive impactful initiatives while encouraging a collaborative and inclusive work environment
- Reporting to the Senior Director Tech Risk Operations, you will lead and develop a team of 50 employees at Booking.com across the locations of Amsterdam, Manchester, Bucharest and Bangalore. This role is located in Amsterdam
- Risk Management activities for the Central Tech organization which includes: Core Platforms, IT Services, Data & Machine Learning Platform
- You will be responsible for:
- Risk Management activities for the domains of Security, Safety, Fraud and Security in AI/ GenAI
- Security Awareness
- GRC Product
- Policy management
- Controls and Frameworks
- Leadership in Security Risk Management: Lead efforts in safeguarding the organisation’s digital and physical assets through robust risk management strategies
- Governance Risk & Compliance (GRC): You will have responsibility for GRC for Booking.com SS&F risk subject areas. This includes the process for creating, updating, and leading SS&F-related policies, standards, and guidelines; as well as providing the risk register for SS&F risks across the enterprise. You will lead the “next generation” GRC vision for Security Safety and Fraud anchored on product and engineering principles
- First Line of Defence: You will be responsible for the first line risk management activities within the Central Tech organization which includes: providing proactive risk insights, reporting to Central Tech Leadership team & supporting management decisions through proactive risk assessments in various strategic programs
- Framework Implementation and risk registers: You will maintain and evolve the risk management system frameworks for Cybersecurity, Trust & Safety, Fraud, & Physical Security. Drive consistent, repeatable, measurable risk identification, assessment, and mitigation processes. You will maintain and mature the processes for the risk registers for cybersecurity, fraud, trust & safety, and global security & resilience
- Communication and Reporting: You will ensure open and timely reporting on risk posture to leadership and relevant collaborators
- Business Partnership: You will collaborate with Central Tech leaders and with the Business Information Security Officers, to communicate risks and develop remediation plans, ensuring alignment with risk management strategy. You will work with stakeholders across the company to embed risk management into business operations
- Adaptability & Continuous improvement: You will respond and adjust to changing risk management regulatory requirements and emerging threats to maintain effective risk management practices. You will establish a resilient and repeatable and continuously improving risk management process
Benefits
- Health insurance
- Free access to Headspace for you and your loved ones
- Global Employee Assistance Program
- Meditation and Breastfeeding rooms at the office
- Booking Cares - 2 days per year to volunteer and learn
- Life insurance
- Disability insurance
- Pension plan
- Annual paid time off
- Parental leave - 22 weeks
- Grandparent leave - 10 days
- Care leave - 10 days
- Bereavement leave - up to 4 weeks
- Anniversary leave
- Working from Home Furniture and Ergonomic Support
- Working from Abroad - up to 20 days per year
- Discounts & Wallet credits to spend on our products
- Upgrade to Booking.com Genius Level 3
- Friends & Family Booking.com discount vouchers
- Free access to online learning platforms
- Development and mentorship programs to support career growth
- Access to trainings and workshops
- Team development opportunities
- Local discount programs
- Game rooms in offices
- On-site meals, coffee and snacks including vegan options
Connects disparate risks to create a clear overall risk picturePreferred certifications: CISM, CISSP, COSO ERM, or similar risk management certificationDirect, creative problem solver able to communicate concepts to a broader audience and create clarityA balanced background between creating and implementing strategy. Operational efficiency metricsAt least 10 years of experience in Cyber Security (preferred) or Fraud, with significant years leading high-performing, impactful teamsExperience in collaborating with finance teams on finance based risk, using a data driven approach. (e.g quantify how much we have spent in a risk project vs how better prepared we are to face risks)A patient and relaxed leader who is skilled at translating technical risks to non-technical audiencesAn enthusiastic and persuasive leader who has driven successful risk management programsA dynamic leader with experience in risk management organisational change, influencing executives and or the boardOrganised with strong attention to detail and execution skillsIntegrity, independent thinking, and courageOpen mind, learning demeanour, transparent behaviour, positive, multitasker, strong communicator, proactive and collaborativeData driven, experimental, ready to learn and open to changeFamiliarity with risk frameworks: NIST, ERM GDPR, ISO 27001, NYDFS, etcExperienced in cloud-based security frameworksCharacter traits: Respectful, high emotional intelligence, and collaborative work style. Comfortable with ambiguity, creating clarityExperience in matrix or federation environmentsGood cultural and organisational sensitivityKeep the customer at the centre of everything you doCommitted to building a diverse, inclusive work environmentThrives in fast-paced, demanding environmentsStrategic problem solver yet focused on execution; able to roll up sleeves to get things doneConfident leader, adept at handling conflicting prioritiesExperience in driving security with engineering teams to embed this in ways of workingConsensus-driven, achieving collaborative solutions