Manager, Proactive Cyber Defence & Engineering

Booking Holdings, Inc.

Amsterdam

Hybrid

EUR 170,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Generous paid leave
Hybrid work including up to 20 days ab
Product discounts & benefits

Job summary

Booking.com in Amsterdam seeks a senior leader to guide a mature Cyber Defence capability, shaping strategy and leading a team of threat researchers and engineers across Amsterdam and Bucharest. You will own detection engineering, validation programs, and metrics to prove value in a global tech environment.

The role requires 5+ years in cybersecurity and proven leadership, with a focus on adversary emulation, MITRE ATT&CK, and scalable automation.

Qualifications

  • 5+ years in cybersecurity, security engineering, threat research, or detection & response.
  • 2+ years directly managing and developing engineers, researchers, or other senior technical specialists.
  • Breadth across threat hunting, adversary emulation, detection engineering, telemetry, SIEM, SOAR, and response automation.
  • Fluency in adversary TTPs, MITRE ATT&CK, and modern detection engineering practice (detection-as-code, lifecycle management).
  • Track record of moving initiatives from prototype to production.
  • Strong stakeholder communication translating complex work into business impact.
  • People-first leadership with empathy and accountability.

Responsibilities

  • Shape strategy in partnership with leadership — translate Cyber Defence strategy into a risk-based plan and allocate resources.
  • Expand coverage where it counts — lead telemetry and detection expansion across crown jewels, identity and cloud.
  • Establish detection & response engineering at scale — implement detection-as-code, CI/CD, testing, tuning, and production readiness.
  • Run validation as a program — manage adversary-emulation and control-validation to surface gaps and drive closure.
  • Own the metrics — design and report KPIs like ATT&CK coverage, detection quality, and automation impact.
  • Use AI as a force multiplier — drive automation to ship detections faster and reduce manual toil.
  • Lead exceptional people — coach and develop a high-performing team.
  • Build visibility & partnerships — represent the program to senior leadership and stakeholders across Enterprise IT and product security.

Skills

Cybersecurity
Threat research
Detection & response
MITRE ATT&CK
Adversary TTPs
Leadership
Stakeholder communication

Tools

SIEM
SOAR
CI/CD

Job description

Role Overview:

This is a leadership role at the heart of a highly mature capability within our Enterprise Security Cyber Defence organisation. If you build threat-informed defence for a living and want to lead exceptional people doing it at scale, read on.

This team exists to stay ahead of adversaries, understanding how they operate, closing the gaps that matter before they can be exploited, and engineering scalable, production-grade solutions that make our cyber defence faster and more effective.

Threat-informed defence is the heartbeat of this team: study how real adversaries operate, then turn that insight into measurable protection across a large, global technology environment. It's a group of nine specialists across Amsterdam and Bucharest, a mix of senior and core threat researchers and engineers operating as one team across two connected disciplines.

On the research side, they turn the world's threat reporting APT and ransomware tradecraft, supply chain attack trends, emerging AI-driven threats into action in our environment: proactive threat hunts, custom detections, custom preventions, and continuously maturing response playbooks. They run adversary emulation and security-control validation week in, week out to prove our defences against real tradecraft then close the gaps they find, themselves and with partner teams. Proactive, not reactive.

On the engineering side, they bring detection and response engineering built to a modern industry standard: high-fidelity detection-as-code, telemetry and log-source onboarding, platform and pipeline health, and coverage engineered deliberately against MITRE ATT&CK. They own the full lifecycle not just shipping a detection, but monitoring it, tuning it, managing false positives, and supporting it in production. And they build the automation, SOAR workflows, and AI-driven capabilities that strip out manual toil and make the wider defence organisation faster so skilled people spend their time on the problems that genuinely need human expertise.

Everything this team does exists to make detection and response sharper, coverage broader, and investigations faster.

Key Job Responsibilities and Duties:
  • Shape strategy in partnership with leadership — translate the broader Cyber Defence strategy into a clear, risk-based plan for the team, set priorities, and own resource assignment and capacity planning so the team works from one aligned plan

  • Expand coverage where it counts most — lead the push for high-value telemetry and detection coverage across our crown jewels, identity, cloud, and the parts of the estate where visibility doesn't exist yet or needs maturity, always knowing where we're strong and where to invest next.

  • Establish detection & response engineering at scale — bring the cutting edge of how the industry does detection engineering into how we do it: detection-as-code, peer review, testing and validation, CI/CD, tuning, and retirement of stale logic — and make sure prototypes become documented, tested, maintainable, supportable production capabilities, not one-off experiments.

  • Run validation as a program — own a structured adversary-emulation and control-validation practice that mimics real adversary behaviour to test our detection and response, surface the gaps that matter, and drive them to documented closure — sharpening investigation speed and quality along the way.

  • Own the metrics — design, track, and report the KPIs that prove the team's value: ATT&CK-aligned coverage, detection quality and false-positive performance, validation and gap-closure outcomes, automation impact, and improvements in detection and response effectiveness — turning them into decisions and investment cases

  • Use AI as a force multiplier — drive automation and AI to ship detections faster and at greater scale than rule-writing alone allows, and to make investigation and response more efficient so specialists spend their time on the meaningful, complex work that genuinely needs human expertise.

  • Lead exceptional people — this is a people-first role above all.

  • Build visibility & partnerships across the business — represent the team's program clearly to senior leadership, and collaborate with a broad set of stakeholders across the organisation Enterprise IT, product security, infrastructure security, and the wider cyber defence portfolio challenging requests that aren't risk-based or scalable.

The leadership this team needs
  • Confidently lead experienced specialists with strong technical viewpoints creating alignment and clear direction while keeping constructive debate healthy.

  • Bring structure and prioritisation to senior people: aligned autonomy, clear ownership, and accountability for finishing and productionising what they start.

  • Coach senior researchers and engineers to grow their impact, and build cohesion across two locations so where you sit never limits your visibility or your work.

  • Create genuine psychological safety — empathy, humility, room to raise concerns early alongside clear expectations and honest performance conversations.

  • Delegate well and protect the team from fragmented, low-value work, so deep talent stays focused on what matters.

  • Connect the team's technical work to business and risk outcomes, and carry that story upward with credibility.

Role Qualifications and Requirements:
  • 5+ years in cybersecurity, security engineering, threat research, or detection & response.

  • 2+ years directly managing and developing engineers, researchers, or other senior technical specialists.

  • Real breadth across both worlds: threat hunting / research / adversary emulation and detection engineering / telemetry / SIEM / SOAR / response automation this is not a hands-on-keyboard role, but you carry enough technical depth to challenge methodology and evidence, review engineering proposals with judgement, and win the respect of a team of experts.

  • Fluency in adversary TTPs, MITRE ATT&CK, and modern detection engineering practice (detection-as-code, lifecycle management, coverage measurement).

  • A track record of moving initiatives from prototype to owned, measurable, maintained production capability.

  • Strong stakeholder communication — translating complex work into business impact and risk reduction.

  • A people-first leadership style that pairs empathy with accountability.

This role includes shared participation in the team's on-call rotation, alongside the detections and automation the team runs and supports in production.

No specific degree or certification required — proven technical and leadership impact is what matters.

Benefits & Perks - Global Impact, Personal Relevance:

Booking.com’s Total Rewards Philosophy is not only about compensation but also about benefits. We offer a competitive compensation and benefits package, as well unique-to-Booking.com benefits which include:

  • Annual paid time off and generous paid leave scheme including: parent, grandparent, bereavement, and care leave

  • Hybrid working including flexible working arrangements, and up to 20 days per year working from abroad (home country)

  • Industry leading product discounts - up to 1400 per year - for yourself, including automatic Genius Level 3 status and Booking.com wallet credit

Diversity, Equity and Inclusion (DEI) at Booking.com:

Diversity, Equity & Inclusion have been a core part of our company culture since day one. This ongoing journey starts with our very own employees, who represent over 140 nationalities and a wide range of ethnic and social backgrounds, genders and sexual orientations.

Take it from our Chief People Officer, Paulo Pisano: “At Booking.com, the diversity of our people doesn’t just build an outstanding workplace, it also creates a better and more inclusive travel experience for everyone. Inclusion is at the heart of everything we do. It’s a place where you can make your mark and have a real impact in travel and tech.”

We ensure that colleagues with disabilities are provided the adjustments and tools they need to participate in the job application and interview process, to perform crucial job functions, and to receive other benefits and privileges of employment.

Application Process:
  • Let’s go places together: How we Hire

  • This role does not come with relocation assistance.

Booking.com is proud to be an equal opportunity workplace and is an affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.

Pre-Employment Screening

If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II
Security Engineer II

Booking Holdings, Inc. • Amsterdam

On-site
EUR 80,000 - 120,000
Hybrid working
Annual paid time off
Product discounts
+2
Senior Security Architect
Senior Security Architect

Booking.com • Netherlands

Hybrid
EUR 120,000 - 180,000
Hybrid work
Work from abroad
Product discounts
+3
Security Engineer II
Security Engineer II

Booking.com • Amsterdam

Hybrid
EUR 90,000 - 130,000
Hybrid working
Product discounts
Amsterdam living benefits
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking Holdings, Inc. • Amsterdam

On-site
EUR 70,000 - 100,000
Software Engineer II - Partner Identity & Access Management - ABU
Software Engineer II - Partner Identity & Access Management - ABU

Booking Holdings, Inc. • Amsterdam

On-site
EUR 90,000 - 130,000
Annual paid time off
Hybrid working with flexible remote/
Product discounts – up to 1400 per yr
Director Central Technology and Security, Safety & Fraud (SSF) Risk Operations
Director Central Technology and Security, Safety & Fraud (SSF) Risk Operations

Booking.com • Amsterdam

On-site
EUR 180,000 - 240,000
Solution Engineer I
Solution Engineer I

Booking Holdings, Inc. • Amsterdam

On-site
EUR 60,000 - 90,000
Hybrid working
Annual leave
Product discounts
Solution Engineer I
Solution Engineer I

Booking.com • Amsterdam

Hybrid
EUR 55,000 - 75,000
Annual paid time off
Hybrid working with international per-
Product discounts
Director Central Technology and Security, Safety & Fraud (SSF) Risk Operations
Director Central Technology and Security, Safety & Fraud (SSF) Risk Operations

Booking Holdings, Inc. • Amsterdam

Hybrid
EUR 180,000 - 240,000
Software Engineer II - Partner Identity & Access Management - ABU
Software Engineer II - Partner Identity & Access Management - ABU

Booking.com • Amsterdam

Hybrid
EUR 110,000 - 140,000
Annual leave and paid time off
Hybrid working arrangements
Discounts on Booking.com products