Responsibilities:
Reporting to the Chief Security Officer you will shape our cybersecurity, safety, trust, and fraud risk management efforts. You will lead and develop a team of 70 full-time employees at Booking.com, and work with an additional 100 FTEs in the Centers of Excellence in Romania and India.
This role is located in Amsterdam, The Netherlands.
You will be responsible for: Building a risk management system for security, safety, and fraud in order to demonstrate to the leadership and the board how we are leading risk at a corporate level. You will be taking a broad view to explain how we are identifying, leading and measuring risk across the Security, Safety, & Fraud subject areas.
Leadership in Security Risk Management: Lead efforts in safeguarding the organisation's digital and physical assets through robust risk management strategies. Governance Risk & Compliance (GRC): You will have responsibility for GRC for Booking.com SS&F risk subject areas. This includes the process for creating, updating, and leading SS&F-related policies, standards, and guidelines; as well as providing the risk register for SS&F risks across the enterprise. First Line of Defence : You will be responsible for the Business Information Security Officer (BISO) Program, including leading the BISOs directly, and creating and providing metrics to report to the respective BUs in order to ensure that the BU’s are leading the SS&F risks to their business. This will include projects that drive the culture of the organization to encourage security, safety, and compliance "by design," such as embedding security into their product lifecycle. Strategic Vision : Work with SS&F to develop long-term strategy for the organization, and establish a process to identify budgetary and hiring needs based on the strategic goals, risks, and priorities. . Framework Implementation and risk registers: You will also set up risk management system frameworks for Cybersecurity, Trust & Safety, Fraud, & Physical Security. Accountable for implementing and maintaining cohesive Information Security Management System (ISMS) and Risk Management System (RMS) frameworks. Drive consistent, repeatable, measurable risk identification, assessment, and mitigation processes. You will develop and maintain risk registers for cybersecurity, fraud, trust & safety, and global security & resilience. Communication and Reporting: You will ensure open and timely reporting on risk posture to leadership and relevant collaborators, including contributing to Board and risk committee materials. Business Partnership: You will collaborate with business leaders to communicate risks and develop remediation plans, ensuring alignment with risk management strategy. You will work with stakeholders across the company to embed risk management into business operations. You will quantify risks to prioritise projects and initiatives across Security, Safety & Fraud and business units. Adaptability & Continuous improvement: You will respond and adjust to changing risk management regulatory requirements and emerging threats to maintain effective risk management practices. You will establish a resilient and repeatable and continuously improving risk management process. Cross-functional Leadership & collaboration: You will lead cross-departmental projects and initiatives to strengthen security posture and ensure projects are delivered on time and within budget. Work closely with collaborators to align risk management strategies with business priorities and must-dos. Ideal Experience & Skills:
Substantial years of experience in Cyber Security (preferred) or Fraud, with significant years leading high-performing, impactful teams A dynamic leader with experience in risk management organisational change, influencing executives and or the board. Experienced in cloud-based security solutions An enthusiastic and persuasive leader who has driven successful risk management programs A patient and relaxed leader who is skilled at translating technical risks to non-technical audiences Direct, creative problem solver able to communicate concepts to a broader audience and create clarity. Experience in driving security with engineering teams to embed this in ways of working. Experience in collaborating with finance teams on finance based risk, using a data driven approach. (e.g quantify how much we have spent in a risk project vs how better prepared we are to face risks) Connects disparate risks to create a clear overall risk picture Confident leader, adept at handling conflicting priorities A balanced background between creating and implementing strategy. Operational efficiency metrics. Preferred certifications: CISM, CISSP, COSO ERM, or similar risk management certification Organised with strong attention to detail and execution skills Familiarity with risk frameworks: NIST, ERM GDPR, ISO 27001, NYDFS, etc. Experience in matrix or federation environments OTHER PERSONAL CHARACTERISTICS
Character traits: Respectful, high emotional intelligence, and collaborative work style. Comfortable with ambiguity, creating clarity. Consensus-driven, achieving collaborative solutions Integrity, independent thinking, and courage Thrives in fast-paced, demanding environments Open mind, learning demeanour, transparent behaviour, positive, multitasker, strong communicator, proactive and collaborative. Strategic problem solver yet focused on execution; able to roll up sleeves to get things done. Data driven, experimental, ready to learn and open to change. Keep the customer at the centre of everything you do. Good cultural and organisational sensitivity. Committed to building a diverse, inclusive work environment. Pre-Employment Screening:
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.