Candidatul Ideal
- 3 - 5 years of relevant experience
- Bachelor’s Degree
- Experience in assisting and managing a PCI DSS program, scope and controls including mapping to PCI Requirements 1–12 and ensuring ongoing PCI compliance across in-scope endpoints, systems, and processes.
- Lead risk assessments in identifying gaps and drive risk-based remediation, vulnerability management, and evidence collection for audits.
- Design, implement, and maintain internal controls (technical and administrative) aligned with risk appetite and regulatory expectations; monitor control effectiveness.
- Drive continuous improvement, third-party PCI risk management, audit readiness, risk reporting (KPI/dashboards), and foster PCI awareness across engineering and business teams.
- Cloud Security and compliance experience (AWS, Azure, etc) would be an advantage
- Familiarity with a wide range of technologies (internally developed applications, Windows, Linux, Databases, Gitlab, etc) from a risk and security perspective.
- Hands-on experience in business analysis, auditing, IT governance, risk management or internal controls with PCI context.
- Ability to develop solid relationships with engineering/application teams in order to drive the adoption of a risk management culture.
- Technical understanding of internal control requirements and able to design/apply them in various businesses.
- Ability to split large tasks into logical, manageable and decoupled actions which are managed effectively and delivered on time.
- Be flexible and agile in response to the change in business, stakeholder expectations and/or change in regulatory/operating environment.
- Strong independent contributor and be a strong team player.
- Strong communication skills; fully comfortable working in English, both written and spoken
Descrierea jobului
(R&C) is the first-line risk team responsible for Central Tech business unit risks and Security, Safety & Fraud (SS&F) risks across the company. The IT Risk & Compliance Analyst for Central Tech is responsible for partnering with the platform and capability owners throughout the Central Tech business function to design and maintain IT security and compliance controls in line with our risk appetite and regulatory requirements and to maintain the quality of our processes.
The role requires close collaboration with platform owners and development teams to have a solid high level understanding of the risks and environment while diving into the details as required to understand the solution design and designing effective controls.
This role provides a hybrid way of working with an onsite presence of 2 days/week.
Key Job Responsibilities and Duties
Risk and Compliance Partnership:
- Act as a Risk Partner to platform/service owners and development teams, providing expertise guidance with regards to PCI-DSS, NIST, SOx, NIS2 and general security best practices and tailoring compliance requirements to cloud and devops environments.
- Architect "Guardrails" for secure and compliant onboarding to solutions and services, ensuring that security and compliance is "baked in" rather than "bolted on."
- Provide Right-Sized Advisory on control design, promoting agile and scalable solutions that address any risks without overengineering and ensuring controls are effective and not obstructive.
- Bridge the Gap between technical and audit teams; working with platform/service teams to translate complex tech or application stacks into risk-based language for Internal/External Audit.
Risk Assessments
- Lead/perform Risk Assessments for new services and/or major architectural changes to existing services or solutions. Assist teams in identifying risks and supporting them in implementing appropriate controls and safeguards.
- Maintain the Risk Inventory. Systematically track and monitor identified issues originating from audits, penetration tests, and/or risk assessments to ensure Booking.com maintains a robust and resilient risk posture against current and emerging attack vectors.
- Work with teams to Perform Root Cause Analysis on issues to identify systemic risks and drive improvements to the control framework.
Automation & Continuous Improvement
- Drive Automation Initiatives by identifying manual compliance bottlenecks and designing efficient workflows leveraging automation and AI whenever possible.
- Standardize controls across platforms to simplify compliance and reduce "compliance fatigue" for engineering teams.
- Enhance Methodology: Contribute to the refinement of risk assessment procedures to keep pace with the dynamic nature of a high-growth tech environment.
Risk Reporting & Compliance Execution
- Deliver Data-Driven Risk Insights by reporting on risk coverage and issues using internal tools like Jira and ServiceNow.
- Support Audit Readiness by working with platform/service owners to ensure they are prepared for regulatory cycles, walkthrough preparation and facilitation, coordinating evidence requests and drafting remediation & mitigation memos as needed and aligning with engineering teams.
Benefits
- Health insurance
- Prepaid medical subscription (Regina Maria)
- Life insurance
- Meal vouchers
- Learning wallet
- Travel benefit
- Annual vacation leave of 25 business days, pro rata with the working period
- Birthday day off
- Summer break (short Fridays during summer)
- Work from Abroad program (up to 20 days/year in EU)
- Floating days off
- 2 Volunteer days/ year
- Home office one-time bonus
- Bookster
- Linkedin learning platform
- Headspace
- Employee discounts (travel, gym, dental, vision)
Descrierea companiei
Booking Holdings Center of Excellence is part of Booking Holdings, the world's leading provider of online travel and related services, with a rich heritage of digital innovation. The Center provides access to specialized and highly skilled talent, supports projects powered by new and emerging technologies, leverages industry best practices, and fosters collaboration opportunities across all of the Booking Holdings brands, including Booking.com, Priceline, Agoda, KAYAK and OpenTable.
If you are interested to find out more about the Booking Holdings Center of Excellence visit our website: www.bookingholdings-coe.com.
Booking Holdings (NASDAQ: BKNG) is the world’s leading provider of online travel and related services, provided to consumers and local partners in more than 220 countries and territories through five primary consumer facing brands: Booking.com, Priceline, Agoda, KAYAK and OpenTable. The mission of Booking Holdings is to make it easier for everyone to experience the world.


