It Risk & Control Officer

Booking Booking · Hospitality · Amsterdam, Netherlands · Finance

This role is an IT Risk & Control Officer responsible for supporting FP&A and OTC processes, designing and maintaining internal controls, assessing risks for new initiatives, and ensuring compliance with SOx, Security, GDPR, and business continuity requirements. The role involves performing IT risk assessments, guiding stakeholders on compliance, and enabling continuous improvement of the controls framework. Experience with AI, Cybersecurity, and Cloud is advantageous.

What you'd actually do

  1. Support the FP&A and OTC business units to understand risks according to SOx, Security, GDPR, business continuity requirements and assist them in determining optimal controls to mitigate risks in the product environment
  2. Perform comprehensive IT risk assessments and assist process and control owners in determining and designing optimal controls to mitigate risks
  3. Support the business to design controls based on risks in support areas for the IT and business processes
  4. Monitor changes occurring to the platforms and processes to guide stakeholders to aim sustaining compliance by design
  5. Enable continuous improvement, maintaining B.com controls framework, by providing general and technical guidance on how to maintain relevant controls

Skills

Required

  • 6+ years of experience in IT Risk Management, IT audit and compliance, and IT general control design
  • Advanced risk management & compliance knowledge
  • IT Risk Management and IT Governance
  • Operational Risk Management
  • SOx, ICOFR, COSO
  • Experience with high priority technology domains incl. Data, AI, Cybersecurity (NIST, ISO 27001), and Cloud
  • Experience in other relevant compliance domains (e.g. GDPR, DMA, DSA, FCRM)
  • Hands on experience with leading risk assessments and financial audits
  • Self-motivation, organization, and responsibility for workload
  • Ability to work in a fast-paced environment with challenging stakeholders
  • Fully comfortable working in English

Nice to have

  • Qualifications related to any of the above are advantageous (incl. CRISC, CRM, CRMP, FRM, CISM, CCSP, CGEIT, CIPM, CPA, ACCA, CIA, CISA)

What the JD emphasized

  • SOx
  • risk management
  • internal controls