Booking Holdings Romania - Cyber Security Incident Response Team Manager

Booking Booking · Hospitality · Bucharest, Romania · Security & Infrastructure

Manage a team of Incident Responders and Threat Hunters, focusing on proactive threat hunting, automation, and incident response strategy. The role involves technical command during critical incidents and stakeholder communication.

What you'd actually do

  1. Lead, mentor, and grow a team of multiple elite Incident Responders.
  2. Partner with Cyber Defense & Response (CDR) leadership to build and implement a forward-looking strategy for our defense capabilities.
  3. Define clear, actionable goals for the team and track success through impactful metrics (MTTD, MTTR) rather than just tracking busywork
  4. Oversee day-to-day cyber operations across multiple defense services, including our Threat Hunting Capabilities
  5. Act as the ultimate escalation point. When a complex, Sev-1 incident hits, you are rolling up your sleeves, guiding the technical investigation, and driving mitigation.

Skills

Required

  • Incident Response
  • SOC
  • Threat Hunting
  • DFIR
  • Malware Analysis
  • Team leadership and mentoring
  • Cybersecurity strategy development
  • Incident command and coordination
  • Automation of security tasks
  • Understanding of attacker TTPs
  • Enterprise IT infrastructure knowledge (networking, cloud)
  • OS security (Windows, Linux, macOS)
  • IR playbook development and maintenance
  • Communication and stakeholder management

Nice to have

  • GCIH
  • GCFA
  • OSCP
  • OSCE
  • GREM

What the JD emphasized

  • heavy operational security experience
  • direct management experience
  • Proven ability to step into the chaos of a complex, high-impact security incident
  • Practitioner at Heart
  • Deep, practical understanding of modern attacker methodologies
  • Robust understanding of enterprise IT
  • Solid experience writing, tuning, and maintaining operational IR playbooks