New company? Get a free Business Ad with weekly updates (€269)
Free
Search jobs
Career
Salaries
Offer for companies
IT Risk & Compliance Officer (PCI)
BOOKING HOLDINGS ROMANIA S.R.L.
1 position
Job verified

Job verified

The eJobs team has verified the content of this job ad in order to eliminate any possible mistakes or discriminating text.

Ideal Candidate

  • Bachelor’s degree or equivalent practical experience in Information Security, Technology Risk, IT Audit, Compliance or a related field.
  • 5-8 years of relevant experience in IT risk, IT compliance, internal controls, IT audit or security governance, with strong hands-on PCI-DSS experience.
  • Demonstrated ownership of PCI-DSS recertification activities, including scope management, evidence collection, walkthrough support, remediation tracking and auditor or QSA engagement.
  • Strong knowledge of PCI-DSS requirements, PCI scoping concepts, CDE and connected systems, and artefacts such as AOC, ROC, SAQ and shared-responsibility documentation.
  • Experience designing, implementing and monitoring technical and administrative controls in modern technology environments, including cloud, IAM, change management, vulnerability management, logging and monitoring, key management, secure SDLC and segmentation-related controls.
  • Experience leading risk assessments, identifying control gaps, performing root cause analysis and driving practical, risk-based remediation.
  • Strong stakeholder management skills with the ability to challenge constructively, influence engineering teams and translate technical details into clear risk and compliance language for business and audit audiences.
  • Strong written and spoken English, with clear and structured communication across cross-functional discussions.
  • Familiarity with Jira, ServiceNow and similar reporting or workflow tools used for evidence, issue and compliance tracking.
  • Preferred: Professional certifications such as PCI ISA, CISA, CRISC, ISO 27001 or similar.

Job Description

The Risk & Compliance Officer (PCI) is an individual contributor with expert-level domain knowledge, proactive and analytical professional with a strong foundation in risk management principles and control management and monitoring. A demonstrated ability to automate and monitor complex processes is a benefit. They will be responsible for partnering with multiple risk owners and business unit managers to identify the regulatory requirements from an IT perspective for PCI-DSS, SOX, NIS2 and other, and will drive appropriate control monitoring, IT compliance monitoring and implementation. The Risk & Compliance Officer (PCI) partners closely with internal and external PCI audit teams, IT Control owners and Business owners, to ensure consistency, timeliness and especially compliance with the PCI Certification requirements. This person must possess a strong understanding and experience of typical PCI IT And Audit phases and requirements and also exhibit versatility in various PCI tech domains and can build a comprehensive knowledge of the end-to-end Booking IT environment and pertinent PCI controls.

The Risk & Compliance Officer (PCI) is also a subject matter expert leveraging a deep understanding of the enterprise risk discipline combining deep knowledge of theory and organizational practice or expertise across several different disciplines within a function. Successful risk expertise requires dynamic individuals who are able to liaise with various senior stakeholders and thus need to be articulate communicators, foster collaboration, integrate perspectives and drive to business beneficial outcomes. They will lead the PCI-DSS control efforts to ensure that the PCI requirements are translated into right-sized scalable controls, that audit readiness is maintained throughout the year and that evidence, remediation and risk decisions are coordinated effectively across a complex technology landscape. The role operates as a highly independent first-line risk partner, bridging engineering teams, control owners, internal auditors and external assessors, including QSA.

This position requires strong stakeholder management skills and requires an individual who can convince others who are skeptical or unwilling to accept new concepts, practices, and approaches.

This role provides a hybrid way of working with an onsite presence of 2 days/week.


Key Job Responsibilities and Duties
  • Leads the annual PCI-DSS recertification cycle end-to-end, including planning, scope maintenance, walkthrough preparation, evidence coordination, stakeholder management (follow up, communication, preparation), issue management and support for QSA and audit activities.
  • Acts as the PCI risk partner to platform, service, payments and engineering teams by translating PCI-DSS requirements into practical control expectations and right-sized guidance for cloud, on-prem and DevOps environments.
  • Leads PCI scoping reviews and risk assessments for new services, architectural changes and third-party integrations, and determines impacts to the cardholder data environment, connected systems, control design and evidence requirements.
  • Designs, enhances and monitors technical and administrative controls and guardrails that keep PCI compliance embedded in engineering processes rather than added late in the delivery lifecycle.
  • Drives remediation and continuous improvement by tracking deficiencies, performing root cause analysis, coordinating risk-based action plans, standardizing control practices and improving reporting through tools such as JIRA and ServiceNow.
  • Is responsible for the evidence collection throughout the PCI-DSS recertification process and partnering with the engineering and QSA teams for ensuring timely and complete delivery of the required information.

Benefits
  • Health insurance
  • Prepaid medical subscription (Regina Maria)
  • Life insurance
  • Meal vouchers
  • Learning wallet
  • Travel benefit
  • Annual vacation leave of 25 business days, pro rata with the working period
  • Birthday day off
  • Summer break (short Fridays during summer)
  • Work from Abroad program (up to 20 days/year in EU)
  • Floating days off
  • 2 Volunteer days/ year
  • Home office one-time bonus
  • Bookster
  • Linkedin learning platform
  • Headspace
  • Employee discounts (travel, gym, dental, vision)

Company Description

Booking Holdings Center of Excellence is part of Booking Holdings, the world's leading provider of online travel and related services, with a rich heritage of digital innovation. The Center provides access to specialized and highly skilled talent, supports projects powered by new and emerging technologies, leverages industry best practices, and fosters collaboration opportunities across all of the Booking Holdings brands, including Booking.com, Priceline, Agoda, KAYAK and OpenTable.

If you are interested to find out more about the Booking Holdings Center of Excellence visit our website: www.bookingholdings-coe.com.

Booking Holdings (NASDAQ: BKNG) is the world’s leading provider of online travel and related services, provided to consumers and local partners in more than 220 countries and territories through five primary consumer facing brands: Booking.com, Priceline, Agoda, KAYAK and OpenTable. The mission of Booking Holdings is to make it easier for everyone to experience the world.

Published Aug 18, 2026Updated Aug 18, 2026Expires Sep 17, 2026
Similar jobs
Manage cookies 🍪

We use cookies to offer you the best job hunting experience.

Please allow cookies in order to have access to all the platform's features.

You can check our Cookie Policy here.