Risk and Compliance - IC - F

Booking.com

Amsterdam

On-site

EUR 110,000 - 150,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid working
Generous paid time off
Product discounts

Job summary

Booking.com is seeking an AI Risk & Compliance Officer within the TRO Risk Management team to identify, assess, and monitor AI and GenAI risks across the lifecycle. You will translate risk appetite and standards into practical requirements for design, procurement, deployment, and operation of AI systems.

You will partner with AI governance, security, legal, and engineering teams to ensure a robust risk posture, with clear traceability, and actionable risk decisions across business and technical

Qualifications

  • Experience assessing and managing risks in complex technology environments.

Responsibilities

  • Partner with platform owners to apply NIST, EU AI Act, and security best practices.

Skills

Risk management
AI risk & GenAI
NIST framework
EU AI Act
Cyber security
Audit liaison
Strong communicator
English proficiency
5-8 years experience

Tools

Jira
ServiceNow

Job description

About the team:

Booking.com follows a defense in depth strategy for managing its risks. As part of this strategy, Booking has 3 departments focusing on each line of defense. Global Internal Audit (GIA) is responsible for the 3rd line of defense, Risk and Controls (R&C) is responsible for the 2nd line of defense, while the responsibility of the 1st line has been distributed between process/control owners and the Tech Risk Operations (TRO) team. TRO is the first-line risk team responsible for Central Tech business unit risks and Security, Safety & Fraud (SS&F) risks across the company.



About the role:

The AI Risk & Compliance Officer is a senior individual contributor in the TRO Risk Management team. The role will help Booking.com identify, assess, treat, monitor, and report AI and GenAI risks across the AI lifecycle. The role will translate risk appetite, internal standards, regulatory expectations, and recognised frameworks into practical requirements that teams can apply when designing, procuring, deploying, changing, and operating AI systems.


The role will operate across business and technology environments. It will partner closely with AI and Data Governance, Security, Legal, Regulatory Compliance, engineering teams,, and internal and external assurance stakeholders. The successful candidate will be able to understand AI and cyber security architecture at a level sufficient to identify material risk, challenge control design, and support proportionate, actionable risk decisions.


The role is expected to strengthen the connection between policy and execution by making AI risk decisions traceable, measurable, and embedded into existing risk management, intake, issue management, control, and assurance processes.



Key Responsibilities and Duties:


  • Risk and Compliance Partnership

  • Act as a Risk Partner to platform owners and development teams, providing expertise in NIST, EU AI Act, NIS2 and security best practices and tailoring compliance requirements to AI systems deployment.

  • Architect \"Guardrails\" for secure and compliant AI systems development, ensuring that security is \"baked in\" rather than \"bolted on.\"

  • Provide Right-Sized Advisory on control design. You will champion agile and scalable solutions that solve problems without overengineering, ensuring controls are effective but not obstructive.

  • Bridge the Gap between technical teams and audit functions, translating complex tech stacks into risk-based language for Internal/External Audit.

  • Risk Assessments

  • Lead or perform risk assessments for new AI initiatives, material changes, new providers, high-impact use cases, and AI systems requiring enhanced review.

  • Evaluate security and control implications of model access, data flows, prompt and input handling, tool permissions, external integrations, model outputs, human oversight, and fallback mechanisms.

  • Provide clear, risk-based conclusions and pre-launch conditions, including required mitigations, monitoring, ownership, escalation paths, and residual-risk decisions.

  • Maintain the AI Risk Inventory. Systematically track and monitor identified issues originating from audits, penetration tests, and risk assessments to ensure Booking.com maintains a robust and resilient risk posture against current and emerging attack vectors.

  • Develop and monitor AI risk indicators and metrics, including measures related to shadow AI, assessment coverage, control implementation, vulnerability remediation, AI inventory completeness, agent and tool access, monitoring coverage, incidents, and overdue actions.

  • Analyse trends, recurring findings, control weaknesses, and changes in the threat or regulatory environment to identify systemic risk and prioritise treatment.

  • Support risk owners in selecting and documenting appropriate treatment options, including mitigation, avoidance, transfer, or acceptance in line with risk appetite.

  • Follow up on remediation plans and ensure that out-of-appetite risks, overdue actions, and significant control gaps are escalated through the appropriate TRO and security governance forums.

  • Perform root-cause analysis on AI-related findings and recommend structural improvements rather than isolated corrective actions.

  • Automation & Continuous Improvement

  • Drive Automation Initiatives by identifying manual compliance bottlenecks and designing efficient workflows leveraging automation and AI.

  • Unify Control Frameworks across various platforms to simplify compliance and reduce \"compliance fatigue\" for engineering teams.

  • Enhance Methodology: Contribute to refinement of risk assessment procedures to keep pace with the dynamic nature of a high-growth tech environment.

  • Contribute to the evolution of Booking.com’s AI risk management framework, including the AI risk taxonomy, risk statements, control requirements, assessment methodology, risk appetite measures, and reporting model.

  • Identify opportunities to automate risk assessments, evidence collection, control monitoring, issue tracking, and management reporting.

  • Risk Reporting & Compliance Execution

  • Deliver Data-Driven Risk Insights by reporting on risk coverage and issues using tools like Jira and ServiceNow.

  • Coordinate responses to internal and external assurance activities, including evidence requests, walkthroughs, control testing, maturity assessments, and follow-up of findings.

  • Support readiness for EU AI Act requirements and other applicable AI, cyber security, data, technology, and digital-resilience obligations.



Qualifications and Skills:


  • Demonstrated experience assessing and managing risks in complex technology environments, preferably involving AI, machine learning, generative AI, cloud platforms, software engineering, or data-intensive products.

  • Strong understanding of AI and GenAI risks across the lifecycle, including data, model, application, human, operational, cyber security, third-party, regulatory, privacy, safety, reliability, and responsible-use risks.

  • Working knowledge of AI governance and risk frameworks, especially NIST AI RMF, EU AI Act requirements, ISO/IEC 42001, and relevant cyber security frameworks.

  • Familiarity with AI-specific security risks and mitigations, including prompt injection, model or data poisoning, sensitive-data leakage, insecure tool use, excessive agency, supply-chain risks, and insufficient monitoring.

  • Technical understanding of internal control requirements and design and experience in applying them in various businesses.

  • Stay flexible to meet the dynamic business needs, while maintaining robust solutions that strengthen the IT control environment.

  • Able to split large tasks into logical, manageable and decoupled actions which are managed effectively and delivered on time.

  • Be flexible and agile in response to the change in business, change in stakeholder expectations and/or change in regulatory/operating environment of B.com.

  • Strong independent contributor, while still a strong team player.

  • Previous experience in software development, software engineering is a plus

  • Strong communication skills; fully comfortable working in English, both written and spoken

  • Years of relevant Job Knowledge - Advanced Knowledge (5 - 8 years)



Benefits & Perks - Global Impact, Personal Relevance:

Booking.com’s Total Rewards Philosophy is not only about compensation but also about benefits. We offer a competitive compensation and benefits package, as well unique-to-Booking.com benefits which include:



  • Annual paid time off and generous paid leave scheme including: parent, grandparent, bereavement, and care leave

  • Hybrid working including flexible working arrangements, and up to 20 days per year working from abroad (home country)

  • Industry leading product discounts - up to 1400 per year - for yourself, including automatic Genius Level 3 status and Booking.com wallet credit



Diversity, Equity and Inclusion (DEI) at Booking.com:

Diversity, Equity & Inclusion have been a core part of our company culture since day one. This ongoing journey starts with our very own employees, who represent over 140 nationalities and a wide range of ethnic and social backgrounds, genders and sexual orientations.


Take it from our Chief People Officer, Paulo Pisano: “At Booking.com, the diversity of our people doesn’t just build an outstanding workplace, it also creates a better and more inclusive travel experience for everyone. Inclusion is at the heart of everything we do. It’s a place where you can make your mark and have a real impact in travel and tech.”


We ensure that colleagues with disabilities are provided the adjustments and tools they need to participate in the job application and interview process, to perform crucial job functions, and to receive other benefits and privileges of employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk and Compliance Officer
Risk and Compliance Officer

Booking Holdings, Inc. • Amsterdam

On-site
EUR 120,000 - 170,000
Hybrid working with flexible schedules
Up to 20 days/year abroad
Risk & Compliance Manager
Risk & Compliance Manager

Booking.com • Netherlands

Hybrid
EUR 120,000 - 180,000
Relocation to Amsterdam with support
Hybrid work with flexible hours
Bonuses and stock options
+1
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking.com • Amsterdam

Hybrid
EUR 65,000 - 95,000
Paid time off
Hybrid work
Product discounts
Principal Software Engineer I - Data & AI - Marketplace
Principal Software Engineer I - Data & AI - Marketplace

Booking Holdings, Inc. • Amsterdam

On-site
EUR 150,000 - 190,000
Paid time off
Hybrid working options
HQ Amsterdam campus with on-site meals
+3
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking Holdings, Inc. • Amsterdam

On-site
EUR 70,000 - 100,000
Principal Software Engineer I - Marketplace Data & AI
Principal Software Engineer I - Marketplace Data & AI

Booking Holdings, Inc. • Amsterdam

Hybrid
EUR 120,000 - 190,000
HQ Amsterdam Campus
Hybrid working
Commuting allowance
+3
Principal Software Engineer I - Marketplace Data & AI
Principal Software Engineer I - Marketplace Data & AI

Booking.com • Amsterdam

On-site
EUR 150,000 - 195,000
Time off
Hybrid work
Ergonomic support
+3
Principal Data Engineer - Data & AI, Marketplace
Principal Data Engineer - Data & AI, Marketplace

Booking Holdings, Inc. • Amsterdam

On-site
EUR 140,000 - 190,000
Annual paid time off
Hybrid working
HQ Campus in Amsterdam
+4
Business Solution Architect II
Business Solution Architect II

Booking Holdings, Inc. • Amsterdam

Hybrid
EUR 60,000 - 100,000
Annual paid time off
Generous paid leave scheme
Flexible working arrangements
+2
Risk & Compliance Manager
Risk & Compliance Manager

Booking.com • Amsterdam

Hybrid
EUR 90,000 - 125,000
Relocation support
29 vacation days
Booking deals and product discounts
+1