Director Central Technology and Security, Safety & Fraud (SSF) Risk Operations
Build your career on Magnet.me
Create a profile and receive smart job recommendations based on your liked jobs.
Central Tech - Security, Safety & Fraud (SSF)
The Central Tech - Security, Safety, & Fraud department is looking to hire a Director Central Technology and Security, Safety & Fraud (SSF) Risk Operations. This role is pivotal in shaping our security posture and communicating risks to leadership. We are looking for a dynamic leader with a passion for security, technology and risk management, ready to make a significant impact by taking into consideration today's evolving digital world. You will lead risk management efforts across multiple domains, including our Central Tech organisation and the domains of cybersecurity, physical security, fraud, trust and safety across Booking.com. You will drive impactful initiatives while encouraging a collaborative and inclusive work environment.
Reporting to the Senior Director Tech Risk Operations, you will lead and develop a team of 50 employees at Booking.com across the locations of Amsterdam, Manchester, Bucharest and Bangalore. This role is located in Amsterdam.
Responsibilities:
You will be responsible for:
- Risk Management activities for the Central Tech organization which includes: Core Platforms, IT Services, Data & Machine Learning Platform.
- Risk Management activities for the domains of Security, Safety, Fraud and Security in AI/ GenAI
- Security Awareness
- GRC Product
- Policy management
- Controls and Frameworks
More specifically:
- Leadership in Security Risk Management: Lead efforts in safeguarding the organisation's digital and physical assets through robust risk management strategies.
- Governance Risk & Compliance (GRC): You will have responsibility for GRC for Booking.com SS&F risk subject areas. This includes the process for creating, updating, and leading SS&F-related policies, standards, and guidelines; as well as providing the risk register for SS&F risks across the enterprise. You will lead the “next generation” GRC vision for Security Safety and Fraud anchored on product and engineering principles.
- First Line of Defence: You will be responsible for the first line risk management activities within the Central Tech organization which includes: providing proactive risk insights, reporting to Central Tech Leadership team & supporting management decisions through proactive risk assessments in various strategic programs.
- Framework Implementation and risk registers: You will maintain and evolve the risk management system frameworks for Cybersecurity, Trust & Safety, Fraud, & Physical Security. Drive consistent, repeatable, measurable risk identification, assessment, and mitigation processes. You will maintain and mature the processes for the risk registers for cybersecurity, fraud, trust & safety, and global security & resilience.
- Communication and Reporting: You will ensure open and timely reporting on risk posture to leadership and relevant collaborators.
- Business Partnership: You will collaborate with Central Tech leaders and with the Business Information Security Officers, to communicate risks and develop remediation plans, ensuring alignment with risk management strategy. You will work with stakeholders across the company to embed risk management into business operations.
- Adaptability & Continuous improvement: You will respond and adjust to changing risk management regulatory requirements and emerging threats to maintain effective risk management practices. You will establish a resilient and repeatable and continuously improving risk management process.
Ideal Experience & Skills:
- At least 10 years of experience in Cyber Security (preferred) or Fraud, with significant years leading high-performing, impactful teams.
- A dynamic leader with experience in risk management organisational change, influencing executives and or the board.
- Experienced in cloud-based security frameworks
- An enthusiastic and persuasive leader who has driven successful risk management programs
- A patient and relaxed leader who is skilled at translating technical risks to non-technical audiences
- Direct, creative problem solver able to communicate concepts to a broader audience and create clarity.
- Experience in driving security with engineering teams to embed this in ways of working.
- Experience in collaborating with finance teams on finance based risk, using a data driven approach. (e.g quantify how much we have spent in a risk project vs how better prepared we are to face risks)
- Connects disparate risks to create a clear overall risk picture
- Confident leader, adept at handling conflicting priorities
- A balanced background between creating and implementing strategy. Operational efficiency metrics.
- Preferred certifications: CISM, CISSP, COSO ERM, or similar risk management certification
- Organised with strong attention to detail and execution skills
- Familiarity with risk frameworks: NIST, ERM GDPR, ISO 27001, NYDFS, etc.
- Experience in matrix or federation environments
OTHER PERSONAL CHARACTERISTICS
- Character traits: Respectful, high emotional intelligence, and collaborative work style. Comfortable with ambiguity, creating clarity.
- Consensus-driven, achieving collaborative solutions
- Integrity, independent thinking, and courage
- Thrives in fast-paced, demanding environments
- Open mind, learning demeanour, transparent behaviour, positive, multitasker, strong communicator, proactive and collaborative.
- Strategic problem solver yet focused on execution; able to roll up sleeves to get things done.
- Data driven, experimental, ready to learn and open to change.
- Keep the customer at the centre of everything you do.
- Good cultural and organisational sensitivity.
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.
Welcome to the world of Booking.com Compass. This is the space and community we have created at Booking.com for all of you who have just started navigating your first career journey.
If you join our unique 15-month Graduate Software Engineering Program or Data Science & Analytics Graduate Program in our Amsterdam office, you’ll be offered a permanent role with a clear pathway to step into the next career level.