Magnet.me  -  The smart network where students and professionals find their internship or job.

The smart network where students and professionals find their internship or job.

Risk Officer

Posted 27 May 2026
Share:
Work experience
6 to 10 years
Full-time / part-time
Full-time
Job function
Degree level
Required language
English (Fluent)
Deadline
22 May 2027

Build your career on Magnet.me

Create a profile and receive smart job recommendations based on your liked jobs.

Role Description

We are looking for a Risk Officer to join our Accommodations Risk Partner Team as the first line of defense. You will act as a risk and control subject matter expert, bridging the gap between operational business and technical IT risk and controls. Your mission is to proactively identify risks, design appropriate controls, and help the business to safely navigate SOx regulatory requirements, ensuring our business stays secure and compliant without slowing down innovation.

This role requires a blend of business and technical acumen, and sharp communication skills. You will partner directly with business and tech teams to implement a robust internal control framework, translating complex business and IT risks into practical business solutions. If you want to be part of a product used by millions of travelers daily and you have a passion for risk management, we want to hear from you!

Responsibilities

Internal control framework design and implementation:

  • Develop, implement, and maintain internal control frameworks aligned with industry best practices and applicable regulatory requirements (e.g., SOX, COSO, COBIT, NIST, ISO 27001, other compliance frameworks).
  • Collaborate with 2nd line Risk partners, process owners, control owners and management to ensure the frameworks are practical, effective and tailored to business needs.
  • Maintain a central repository of policies, procedures, control matrices.
  • Develop RACI and a standardized approach for implementation including training and communication.
  • Develop an approach for ongoing review and continuous improvement.
  • Enable business partners with guidelines, templates and tooling.
  • Maintain a central register of all framework documents.
  • Contribute to risk and control reporting and assurance in the business unit.

Act as SOx design authority:

  • Partner with R&C and ABU business and IT stakeholders by providing guidance and ensuring that critical SOx controls are adequately designed and documented, in order to strengthen the control environment, mitigate company risks and support the business in achieving objectives.
  • Provide SME guidance to R&C and ABU business and IT stakeholders and 1st line business owners in relation to observations and deficiencies, from initial assessment/triage through to mitigation and remediation.
  • Support audit management by acting as an SME to support critical audit management activities such as audit planning and issue management.
  • Support testing of business and IT controls and management certification (SOX Section 302 and 404, other compliance frameworks) by providing guidance to the testing team and reviewing the testing documentation.
  • Collaborate with the GRC team and 1st/2nd line Risk partners to develop solutions and improve how risks, controls and issues are maintained in the GRC platform.
  • Act as a risk ambassador within Booking.com to further enhance risk awareness and culture, including by facilitating formal training sessions.

Required skillset

  • 6+ years of previous work experience in internal controls, audit, risk management, or compliance.
  • Bachelor's degree or higher in a relevant field (Master’s degree is preferable).
  • Strong knowledge of internal control frameworks (e.g., COSO, COBIT, NIST, ISO 27001) and regulatory requirements (e.g., SOX, GDPR, DMA, DSA), and experience in applying them in various business areas/functions.
  • Qualifications related to any of the above are advantageous, including CISM, CRISC, ACCA, CIA, and CISA.
  • Experience with Data Governance, cloud platforms, SaaS applications, business continuity management, and emerging technologies (AI/ML, RPA) is a plus.
  • Comfortable with modern tech environments such as DevOps (Kubernetes, GitLab, Terraform etc.) and cloud-based environments/platforms (AWS, GCP etc.).
  • Good stakeholder management skills.
  • Flexibility to adapt to an ever-evolving and dynamic work environment.
  • Self-starter with a strong sense of responsibility.
  • Energetic and very proactive.
  • Process-, problem-solving-, and action-oriented mindset.
  • Strong communication and relationship-building skills.
  • High level of integrity, confidentiality and professionalism.
  • Ability to develop strong relationships with business partners in order to drive risk management culture and implementation.
  • Fluent in English, both written and spoken (other languages would be a plus).
  • Project management skills are a plus.

Welcome to the world of Booking.com Compass. This is the space and community we have created at Booking.com for all of you who have just started navigating your first career journey.
If you join our unique 15-month Graduate Software Engineering Program or Data Science & Analytics Graduate Program in our Amsterdam office, you’ll be offered a permanent role with a clear pathway to step into the next career level.

IT
Amsterdam
Active in 70 countries
12,000 employees
60% men - 40% women
Average age is 32 years