Booking Holdings Romania - Security Engineer - Vulnerability Management

Booking Booking · Hospitality · Bucharest, Romania · Security & Infrastructure

Security Engineer focused on vulnerability management, automation, and integrating security into the SDLC. Responsibilities include owning the vulnerability management program, deploying scanning agents, integrating scanning into CI/CD, monitoring threat intelligence, building SOAR playbooks, and driving metrics and reporting. Requires experience in vulnerability management, security principles, and scripting.

What you'd actually do

  1. Own end-to-end infrastructure vulnerability management, including scanner deployment, agent lifecycle management, scan policy tuning, and SLA-driven remediation workflows.
  2. Deploy and maintain scanning agents at scale using IaC/CM tooling such as Puppet, Ansible or Chef across heterogeneous environments.
  3. Integrate vulnerability scanning into CI/CD pipelines and conduct supply chain security assessments, tracking open-source dependencies and third-party components for known CVEs and emerging threats.
  4. Monitor and triage threat intelligence feeds (NVD, CISA KEV, vendor advisories, OSINT sources) to assess new vulnerability disclosures and translate them into prioritized remediation actions.
  5. Build and maintain SOAR playbooks to automate alert triage, ticket creation, enrichment, and escalation, reducing manual toil across the vulnerability management lifecycle.

Skills

Required

  • vulnerability management
  • security principles
  • host configurations
  • networking
  • MITRE ATT&CK framework & TTPs
  • configuration management tools (Puppet, Ansible, Chef)
  • software supply chain risks
  • SOAR workflows
  • application and infrastructure security
  • common operating systems, networking protocols, and databases
  • scripting or programming

Nice to have

  • SIEM dashboards
  • cloud environments

What the JD emphasized

  • Own and scale our vulnerability management program
  • reduce exposure, accelerate remediation, and integrate security into the SDLC
  • partnering with infrastructure and engineering teams
  • ensure collection, correlation, and reporting
  • ensure the scan agents'/sources' alerts are healthy, false positives are tuned out, and true alerts are surfaced to the right parties
  • solid understanding of and practical hands-on experience with security principles, host configurations, and networking are required
  • Must be detail oriented, able to manage multiple tasks, and work independently as well as in a team setting
  • Excellent communication skills, collaboration skills and ability to adapt to shifting priorities are critical
  • 3-5 years of focus on vulnerability management programs
  • Firm understanding of MITRE ATT&CK framework & TTPs
  • Practical experience using configuration management tools (Puppet preferred, Ansible or Chef accepted) to manage security tooling at scale
  • Solid understanding of software supply chain risks
  • Hands-on experience building or maintaining SOAR workflows for security automation use cases
  • Strong scripting or equivalent programming experience