Risk and Compliance - Ic - E

Booking Booking · Hospitality · Amsterdam, Netherlands · Security & Infrastructure

This role partners with platform owners and development teams to design and maintain IT security and compliance controls, focusing on cloud and devops environments. It involves executing technical risk assessments, maintaining a risk inventory, and driving automation initiatives, including leveraging AI for compliance bottlenecks. The role also requires reporting on risk insights and supporting audit readiness.

What you'd actually do

  1. Act as a Risk Partner to platform owners and development teams, providing expertise in NIST, SOX, PCI-DSS, NIS2 and security best practices and tailoring compliance requirements to cloud and devops environments
  2. Architect "Guardrails" for secure and compliant onboarding to cloud environments, ensuring that security is "baked in" rather than "bolted on."
  3. Execute Technical Risk Assessments for new platforms and major architectural changes.
  4. Drive Automation Initiatives by identifying manual compliance bottlenecks and designing efficient workflows leveraging automation and AI.
  5. Deliver Data-Driven Risk Insights by reporting on risk coverage and issues using tools like Jira and ServiceNow.

Skills

Required

  • Cloud Security and Compliance (AWS, GCP, Azure, etc)
  • DevOps domain
  • business analysis
  • auditing
  • IT governance
  • risk management
  • internal controls
  • NIST
  • SOX
  • PCI-DSS
  • NIS2
  • Jira
  • ServiceNow

Nice to have

  • software development
  • software engineering

What the JD emphasized

  • Cloud Security and Compliance (AWS, GCP, Azure, etc) and DevOps domain is a MUST