Risk & Compliance Manager

Booking.com

Netherlands

On-site

EUR 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Relocation to Amsterdam with support
Hybrid work with flexible hours
Bonuses and stock options
Wellbeing and development programs

Job summary

Booking.com is seeking a Risk Manager for Platform Risk who will lead a team responsible for identifying technology risks across Central Tech platforms. The role requires strong DevOps security knowledge, experience with public cloud and on‑premise environments, and collaboration with Senior Engineering Managers and product teams.

As a people manager, you will drive risk governance, implement IT controls, and promote secure software development across CI/CD pipelines, balancing risk mitigation

Qualifications

  • Strong risk and control background across IT and security domains.
  • Experience with cloud platforms and DevOps tooling in fast-paced environments.
  • Ability to lead first-line risk programs with senior technical stakeholders.
  • Knowledge of regulatory requirements (SOX, GDPR, PCI-DSS) and cybersecurity frameworks.

Responsibilities

  • Lead and grow a Platform Risk team aligned with Central Tech objectives.
  • Engage with senior stakeholders to identify risks and define controls.
  • Embed secure SDLC practices (SAST/DAST/ SCA) into BAU DevOps workstreams.
  • Drive risk awareness and regulatory compliance across business units.
  • Liaise with other risk and audit teams to ensure effective risk reporting.

Skills

Risk management
IT risk management
Stakeholder management
Leadership
Communication
DevOps risk
Regulatory compliance
Cloud security (AWS/GCP/Azure)
Security controls

Education

Bachelor/Master

Tools

AWS
GCP
Azure
Kubernetes
CI/CD tooling
SAST
DAST
SCA

Job description

Role Description

The Risk Manager - Platform Risk reports to the Senior Manager of Risk Management and IT Compliance team within Tech Risk Operations (TRO). This is a first‑line of defense risk team responsible for Central Tech business unit risks & Security risks across the company. The Risk Manager - Platform Risk is a people manager role, focused on leading a team of individuals to enable consistent identification of technology‑related risks for key Central Tech business unit technology platforms. These technology platforms enable the business to build and run in‑house developed applications that support the core of our Business.

The Risk Manager - Platform Risk possesses both a strong technical understanding of DevOps IT technology and expertise in various risk domains. These domains include cybersecurity, IT, privacy, regulatory compliance, broader enterprise risks, Trust & Safety, cybersecurity regulatory compliance, and e‑commerce fraud. This role involves identifying technology‑related risks across core DevOps technology platforms, encompassing both public cloud and on‑premise infrastructure. This includes (but is not limited to) public and private cloud platforms, like AWS, GCP, Azure, Kubernetes, Gitlab, CI/CD Tooling, etc.

This role also requires embedding secure software development principles and tooling (SAST, DAST, SCA) into BAU development practices, to apply them effectively to DevOps technology platforms. The Risk Manager - Platform Risk is also a subject matter expert leveraging a deep understanding of the enterprise risk discipline combining deep knowledge of theory and organizational practice or expertise across several different disciplines within a function. Effective first‑line risk professionals are adaptable individuals who can engage with diverse senior technical stakeholders (Senior Engineering Managers, Product Owners, developers, etc.). This necessitates strong communication skills, technical proficiency, an ability to foster collaboration, incorporate different viewpoints, and steer efforts toward positive business results in managing IT risks and ensuring IT regulatory compliance obligations are met.

This role requires engaging with senior stakeholders to identify appropriate risk responses, and supporting and maintaining a fit‑for‑purpose IT controls framework, including the development of additional IT controls to manage risks. It requires a demonstrated ability to simplify and automate complex processes and ensure we are managing risks in line with our risk appetite.

This position requires strong stakeholder management skills and requires an individual who can convince others who are skeptical or unwilling to accept new concepts, practices and approaches. This position involves extensive collaboration with senior technical stakeholders to ensure the consistent maintenance of existing IT controls across the organization. Success in this role requires exceptional stakeholder management skills, including the ability to build strong relationships, effectively communicate complex information, and persuasively influence individuals and teams, even when faced with resistance to necessary changes and the adoption of new security protocols. The ability to navigate organizational complexities and foster a culture of IT risk management, security awareness and compliance is critical. This role is also a people manager position and is fully responsible for managing a team of individuals and continuously improving the area under their scope. This manager will be responsible for leading and managing a team of internal and/or external resources (e.g. Risk Analysts, Risk Officers, consultants). They are comfortable leading a team to come up with robust, scalable and automated solutions that mitigate key risks while enabling successful business operations across multiple core platforms.

Key Responsibilities and Duties
  • Attract, engage, develop, and retain talent to their full potential by fostering a supportive work environment that emphasizes continuous feedback, coaching, and mentorship programs, ensuring comprehensive growth for all crafts.
  • Coaching your team on and consistently role model the Booking values on Think Customer First, Own It, Learn Forever, Succeed Together, and Do the Right Thing.
  • Drive initiatives effectively involving multiple technical first‑line senior stakeholders, re‑prioritising tasks when beneficial.
  • Formulate and implement tactical plans and objectives within Platform Risk Management that are in alignment with Central Tech business objectives and ensure the achievement of annual goals. Establish team priorities, delegate projects, allocate resources, and provide regular communication to management and business partners regarding business performance and project progress.
  • Advise first‑line stakeholders with specialized knowledge and expertise in IT risk, cybersecurity and regulatory compliance risk. Assume responsibility for the identification of technological risks and the formulation of control design proposals. Offer guidance on control design that is sustainable and appropriately scaled, ensuring that solutions are commensurate with the complexity of the issues addressed and avoiding unnecessary overengineering.
  • Drive business engagement in the Central Tech business unit to provide risk and compliance awareness for teams that have a clear need to manage risks without significantly affecting their development velocity and/or play a key role towards achieving strategic objectives in the company.
  • Develop and maintain IT and security policies and procedures for secure software development & collaborate with development teams to integrate secure software development practices and principles into CI/CD pipelines.
  • Support senior stakeholders across central tech helping to promote and embed risk and compliance ownership across the business as well as to broaden and expand their knowledge base of both the internal and external risk environment.
  • Follow broader ERM strategy defined by R&C and implement it into execution within the first‑line of defense (business) and drive continuous improvement of risk assessment methodologies through ongoing collaboration with second‑line risk and controls teams, ensuring alignment with practical business objectives.
  • Support the team to identify ways to increase their business impact and improve the team's product(s) and ways of working.
  • Liaise with other risk and audit teams (Risk and Controls, Internal Audit, external auditors, etc.) to provide a more in‑depth technical risk perspective, as needed.
  • Stay current with emerging cyber threats and security best practices in DevOps environments.
Knowledge and Skills
  • Requirements of special knowledge/skills:
  • Technical Specialization (specify per sub competence and Level):
  • Strong risk and control or audit/assurance background with a deep understanding of operational and technology risk - L4
  • Strong working experience with IT General Controls (ITGCs), especially in fast‑paced DevOps environments
  • Strong understanding of technology risk management, controls, and compliance, especially for public cloud platforms and DevOps Tooling - L4
  • Experience and understanding of applicable regulations such as Sarbanes Oxley, PCI-DSS, GDPR and CCPA - L4
  • Familiarity with industry‑standard Cybersecurity regulatory frameworks such as NIST, ISO27001 and CIS - L3
  • Understanding of cybersecurity risks and data protection principles - L3
  • Technical AWS certifications (AWS Certified Solutions Architect, AWS Certified Security) are a plus
  • Knowledge of secure software development practices and tooling (SAST, DAST, and SCA tools)
  • Ability to cultivate solid relationships with business partners in order to drive the adoption of the risk management culture
  • Thorough technical understanding of internal control requirements and design and experience in applying them in various businesses
  • Able to split large tasks into logical, manageable and decoupled actions which are managed effectively and delivered on time
  • Be flexible and agile in response to the change in business, change in stakeholder expectations and/or change in regulatory/operating environment of B.com
  • Level of Education: Bachelor/Master
  • Years of relevant Job Knowledge: Extensive Knowledge (8 - 12 years)
Benefits & Perks: Global Impact, Personal Relevance
  • Headquarters located in one of the most dynamic and cosmopolitan cities in Europe: Amsterdam.
  • Contribute to a high‑scale, sophisticated, world‑class product and see the real‑time impact of your work on millions of travelers worldwide.
  • Be part of a truly international fast‑paced environment and performance‑driven culture.
  • Full relocation support for you and your family to move to Amsterdam. We have fine‑tuned this process by successfully relocating hundreds of Technology professionals to Amsterdam in recent years.
  • Performance‑based company that offers 29 vacation days, career advancement, and lucrative compensation, including bonuses and stock potential.
  • Discount on Booking.com accommodations with the "Booking Deal" including other perks and benefits.
  • Company‑sponsored family and social activities to help our employees become integrated with each other and Dutch culture.
  • Diverse and creative colleagues from every corner of the world.
  • Health, life, and disability insurance*.
  • Annual paid time off and generous paid leave scheme including: parent, grandparent, bereavement, and care leave.
  • Hybrid working including flexible working arrangements, and up to 20 days per year working from abroad (home country).
  • Industry‑leading product discounts for yourself, friends, and family, including automatic Genius Level 3 status and quarterly Booking.com wallet credit.
  • Free access to online learning platforms, development and mentorship programs, and a complimentary Headspace membership.
  • On‑site meals, coffee, and snacks, including healthy and vegan options, daily*.
  • Benefits may vary slightly depending on location and contract type.
#Think Inclusion: Wellbeing & Inclusion at Booking.com

Inclusion, Diversity, Belonging, Wellbeing and Volunteering (IDBWV) have been a core part of our company culture since day one. This ongoing journey starts with our very own employees, who represent over 140 nationalities and a wide range of ethnic and social backgrounds, genders, and sexual orientations.

Take it from our Chief People Officer, Paulo Pisano:

"At Booking.com, the diversity of our people doesn't just create a unique workplace, it also creates a better and more inclusive travel experience for everyone. Inclusion is at the heart of everything we do. It's a place where you can make your mark and have a real impact in travel and tech."

We will ensure that individuals with disabilities are provided reasonable adjustment to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment.

Booking.com is proud to be an equal opportunity workplace and is an affirmative action employer.

Pre-Employment Screening

If your application is successful, your personal data may be used for a pre‑employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre‑employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk & Compliance Manager
Risk & Compliance Manager

Booking.com • Amsterdam

Hybrid
EUR 90,000 - 125,000
Relocation support
29 vacation days
Booking deals and product discounts
+1
Risk and Compliance Officer
Risk and Compliance Officer

Booking Holdings, Inc. • Amsterdam

On-site
EUR 120,000 - 170,000
Hybrid working with flexible schedules
Up to 20 days/year abroad
Risk and Compliance - IC - F
Risk and Compliance - IC - F

Booking.com • Amsterdam

On-site
EUR 110,000 - 150,000
Hybrid working
Generous paid time off
Product discounts
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking Holdings, Inc. • Amsterdam

On-site
EUR 70,000 - 100,000
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking.com • Amsterdam

Hybrid
EUR 65,000 - 95,000
Paid time off
Hybrid work
Product discounts
Software Engineer I - Backend
Software Engineer I - Backend

Booking Holdings, Inc. • Amsterdam

Hybrid
EUR 75,000 - 110,000
Annual paid time off + generous leave
Hybrid working with up to 20 days/year
Product discounts & wallet credits
Technical Product Manager
Technical Product Manager

Booking Holdings, Inc. • Amsterdam

On-site
EUR 90,000 - 120,000
Parental leave
Hybrid working
HQ Campus Amsterdam
+4
Senior Program Manager - CBO
Senior Program Manager - CBO

Booking.com • Amsterdam

Hybrid
EUR 120,000 - 160,000
Hybrid working including flexible work
Industry leading travel discounts
Travel/days abroad up to 20 per year
Business Operations Manager - Marketplace
Business Operations Manager - Marketplace

Booking.com • Amsterdam

Hybrid
EUR 150,000 - 230,000
Hybrid working
HQ in Amsterdam
Commuting allowance
+2
Senior Security Architect
Senior Security Architect

Booking.com • Amsterdam

Hybrid
EUR 120,000 - 160,000
Hybrid work
Product discounts
Global impact
+1