Booking Holdings Romania - Security Engineer - Data Detection & Response

Booking Booking · Hospitality · Bucharest, Romania · Security & Infrastructure

Security Engineer focused on Data Detection & Response, responsible for engineering, maintaining, and optimizing CASB and DLP systems for high-fidelity detection and automated incident response. This role involves applying SRE practices, implementing 'Security as Code', developing detection logic, and creating Python-based automation playbooks within a SOAR platform. The engineer will also ensure compliance with regulations like PCI-DSS, GDPR, and SOX.

What you'd actually do

  1. Owns the end-to-end technical lifecycle, deployment, and optimization of enterprise Data Security platforms (specifically CASB/DLP) across multi-cloud and enterprise environments.
  2. Applies SRE (Site Reliability Engineering) practices to ensure the continuous availability and performance of security telemetry pipelines and detection engines.
  3. Implements "Security as Code" using Terraform, Puppet, and Git to automate the deployment of data protection policies across all Booking Holdings brands.
  4. Designs and implements high-fidelity detection logic by correlating data security telemetry with wider security datasets (SIEM/XDR) to identify advanced threat actor TTPs.
  5. Develops and maintains Python-based automation playbooks within the SOAR platform to execute real-time, automated containment actions (e.g., automated session revocation).

Skills

Required

  • CASB/DLP
  • SRE practices
  • Security as Code
  • Terraform
  • Puppet
  • Git
  • Detection logic development
  • SIEM/XDR
  • Python Scripting
  • SOAR platform
  • SQL
  • Logscale
  • KQL
  • SPL
  • DevOps
  • IaC
  • CI/CD
  • GitHub
  • GitLab
  • Identity & Access Governance
  • Okta
  • Entra ID
  • Public Cloud Security
  • Container Security
  • AWS
  • Azure
  • GCP
  • Data Security
  • Compliance
  • Security Systems Integration
  • SOC
  • IR
  • CSIRT

Nice to have

  • Tines

What the JD emphasized

  • high-fidelity detection
  • automated incident response
  • Data Protection
  • Security as Code
  • PCI-DSS
  • GDPR
  • SOX