- This is a leadership role at the heart of a highly mature capability within our Enterprise Security Cyber Defence organisation. If you build threat-informed defence for a living and want to lead exceptional people doing it at scale, read on
- This team exists to stay ahead of adversaries, understanding how they operate, closing the gaps that matter before they can be exploited, and engineering scalable, production-grade solutions that make our cyber defence faster and more effective
- Threat-informed defence is the heartbeat of this team: study how real adversaries operate, then turn that insight into measurable protection across a large, global technology environment. It’s a group of nine specialists across Amsterdam and Bucharest, a mix of senior and core threat researchers and engineers operating as one team across two connected disciplines
- On the research side, they turn the world’s threat reporting APT and ransomware tradecraft, supply chain attack trends, emerging AI-driven threats into action in our environment: proactive threat hunts, custom detections, custom preventions, and continuously maturing response playbooks. They run adversary emulation and security-control validation week in, week out to prove our defences against real tradecraft then close the gaps they find, themselves and with partner teams. Proactive, not reactive
- On the engineering side, they bring detection and response engineering built to a modern industry standard: high-fidelity detection-as-code, telemetry and log-source onboarding, platform and pipeline health, and coverage engineered deliberately against MITRE ATT&CK
- They own the full lifecycle not just shipping a detection, but monitoring it, tuning it, managing false positives, and supporting it in production. And they build the automation, SOAR workflows, and AI-driven capabilities that strip out manual toil and make the wider defence organisation faster so skilled people spend their time on the problems that genuinely need human expertise
- Everything this team does exists to make detection and response sharper, coverage broader, and investigations faster
- Shape strategy in partnership with leadership — translate the broader Cyber Defence strategy into a clear, risk-based plan for the team, set priorities, and own resource assignment and capacity planning so the team works from one aligned plan
- Expand coverage where it counts most — lead the push for high-value telemetry and detection coverage across our crown jewels, identity, cloud, and the parts of the estate where visibility doesn’t exist yet or needs maturity, always knowing where we’re strong and where to invest next
- Establish detection & response engineering at scale — bring the cutting edge of how the industry does detection engineering into how we do it: detection-as-code, peer review, testing and validation, CI/CD, tuning, and retirement of stale logic — and make sure prototypes become documented, tested, maintainable, supportable production capabilities, not one-off experiments
- Run validation as a program — own a structured adversary-emulation and control-validation practice that mimics real adversary behaviour to test our detection and response, surface the gaps that matter, and drive them to documented closure — sharpening investigation speed and quality along the way
- Own the metrics — design, track, and report the KPIs that prove the team’s value: ATT&CK-aligned coverage, detection quality and false-positive performance, validation and gap-closure outcomes, automation impact, and improvements in detection and response effectiveness — turning them into decisions and investment cases
- Use AI as a force multiplier — drive automation and AI to ship detections faster and at greater scale than rule-writing alone allows, and to make investigation and response more efficient so specialists spend their time on the meaningful, complex work that genuinely needs human expertise
- Lead exceptional people — this is a people-first role above all
- Build visibility & partnerships across the business — represent the team’s program clearly to senior leadership, and collaborate with a broad set of stakeholders across the organisation Enterprise IT, product security, infrastructure security, and the wider cyber defence portfolio challenging requests that aren’t risk-based or scalable
- Confidently lead experienced specialists with strong technical viewpoints creating alignment and clear direction while keeping constructive debate healthy
- Bring structure and prioritisation to senior people: aligned autonomy, clear ownership, and accountability for finishing and productionising what they start
- Coach senior researchers and engineers to grow their impact, and build cohesion across two locations so where you sit never limits your visibility or your work
- Create genuine psychological safety — empathy, humility, room to raise concerns early alongside clear expectations and honest performance conversations
- Delegate well and protect the team from fragmented, low-value work, so deep talent stays focused on what matters
- Connect the team’s technical work to business and risk outcomes, and carry that story upward with credibility
- This role includes shared participation in the team’s on-call rotation, alongside the detections and automation the team runs and supports in production
Benefits
- Health insurance
- Free access to Headspace for you and your loved ones
- Global Employee Assistance Program
- Meditation and Breastfeeding rooms at the office
- Booking Cares - 2 days per year to volunteer and learn
- Life insurance
- Disability insurance
- Pension plan
- Annual paid time off
- Parental leave - 22 weeks
- Grandparent leave - 10 days
- Care leave - 10 days
- Bereavement leave - up to 4 weeks
- Anniversary leave
- Working from Home Furniture and Ergonomic Support
- Working from Abroad - up to 20 days per year
- Discounts & Wallet credits to spend on our products
- Upgrade to Booking.com Genius Level 3
- Friends & Family Booking.com discount vouchers
- Free access to online learning platforms
- Development and mentorship programs to support career growth
- Access to trainings and workshops
- Team development opportunities
- Local discount programs
- Game rooms in offices
- On-site meals, coffee and snacks including vegan options
2+ years directly managing and developing engineers, researchers, or other senior technical specialists5+ years in cybersecurity, security engineering, threat research, or detection & responseA people-first leadership style that pairs empathy with accountabilityA track record of moving initiatives from prototype to owned, measurable, maintained production capabilityReal breadth across both worlds: threat hunting / research / adversary emulation and detection engineering / telemetry / SIEM / SOAR / response automation this is not a hands-on-keyboard role, but you carry enough technical depth to challenge methodology and evidence, review engineering proposals with judgement, and win the respect of a team of expertsStrong stakeholder communication — translating complex work into business impact and risk reductionFluency in adversary TTPs, MITRE ATT&CK, and modern detection engineering practice (detection-as-code, lifecycle management, coverage measurement)No specific degree or certification required — proven technical and leadership impact is what matters