Booking Holdings Romania - Cyber Defense Technical Operations & Response Team Leader
Adaugat: 3 săptămâni în urmă
Booking Holdings
Booking Holdings Romania - Cyber Defense Technical Operations & Response Team Leader
Adaugat: 3 săptămâni în urmă
Booking Holdings
Acest anunt este cu aplicare externa. Cand dati click pe Aplicare Externa veti fi redirectionat pe un alt site pentru a aplica.
Booking Holdings Romania is a Center of Excellence based in Bucharest, Romania and was created to support the increasing business demands of the Booking Holdings Brands. The Center of Excellence provides access to specialized and highly skilled talent, leading industry best practices, and collaboration opportunities across all of our Brands.
As part of our Booking Holdings Romania team, you will have the opportunity to be a part of the world's leading provider of online travel, with a mission of making it easier for everyone to experience the world through five-primary consumer facing brands: Booking.com, Priceline, Agoda, KAYAK and OpenTable.
We are looking for a Cyber Defense Team Lead, who will manage a small team of cyber defense analysts (up to a max of 10), which includes both internal employees and external contractors. The primary job of the role is to keep daily operations running smoothly and help the team grow. We are not looking for a passive checklist follower. We want someone who sees a broken process or a slow tool and fixes it without waiting for their manager to tell them to. The candidate would need to understand how a SOC works technically, but their real value will come from leading people, improving workflows, and understanding how our security work protects the company's business. The structure and reporting lines for this role are governed by the Sustainable Team Principles to ensure organizational agility and balanced spans of control within the local and brand specific team.
This role provides a hybrid way of working with an onsite presence of 2 days/week.
Key Job Responsibilities and Duties
Proactivity and Process Improvement: You constantly look for better ways to do things. You identify manual, repetitive tasks and work to automate them or make them faster.
People Skills and Leadership (EQ): You know how to talk to people, understand their frustrations, and keep team morale high during busy or stressful times. You can manage a mixed team of internal staff and third-party contractors fairly.
Business and Risk Awareness: You understand how security risks affect the wider company. You can explain technical issues clearly to business partners and clients who are not technical.
Technical Foundation: You understand SOC tools like SOAR, EDR, XDR, IPS/IDS, SIEM, Sandbox, Cloud security and Email Security. You do not need to be a malware genius, but you must understand the alerts your team is investigating every day.
Role Qualifications and Requirements
Experience: 5+ years working in a SOC or an Incident Response environment.
Leadership: Experience leading a team, managing shift schedules (ROTA), and mentoring junior analysts.
Problem Solving: A proven track record of changing processes and workflows to make a team more efficient.
Communication: Clear and direct communication skills in English, both written and spoken.
Certifications: Security+, CySA+, GCIH, or CISSP are helpful, but your actual work experience is more important to us. Advanced technical certifications (like OSCP or GREM) are a bonus.
Must have strong experience evaluating security alerts across modern corporate infrastructures (Cloud, Identity, Network, Endpoint).
Ability to quickly read an analyst's investigation notes, spot technical gaps or missing evidence, and guide the next steps of the incident lifecycle.
Proven experience using enterprise-grade SIEM, EDR, and SOAR tools to identify attack patterns (such as living-off-the-land techniques or lateral movement).
Collaborate with the IR team on complex security incidents to achieve efficient mitigation for active threats and identification of the root cause.
Collaborates on various departmental projects that help the organization improve its cyber security posture and achieve its mission/objectives
Collaborates with different CDR stakeholders and vendors to remediate any identified gaps
Masters and uses CSIRT's playbooks, runbooks, workflows, operational documentation, and processes. Contributes to the writing and maintenance of all such documents.
Owns and delivers on assigned projects (often around improvements to detections, processes and playbooks) while balancing execution and deliveries with operations and IR workload; Supports other team members in projects.
Drives continuous improvements of our detection and response capabilities by identifying and owning improvement areas in the technology, methods, processes (including opportunities around detection tuning and automation).
Offers on-call support during the nights, weekends and public holidays (optional)
Benefits & Perks
Contributing to a high scale, complex, world renowned product and seeing real-time impact of your work on millions of travelers worldwide
Working in a fast-paced and performance driven culture
Technical, behavioral and interpersonal competence advancement via on-the-job opportunities, experimental projects, hackathons, conferences and active community participation
Competitive compensation and benefits package
Vast amounts of data to validate your ideas and the opportunity to experiment with real users
Booking Holdings is proud to be an equal opportunity workplace and is an affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.
Sfaturi de siguranta
- Nu trimiteti niciodata BANI in avans sau acte de identitate pentru aplicarea la un loc de munca. Nu trimiteti bani in avans pentru promisiuni de angajare sau alte oferte similare.
- Daca aveti impresia ca acest anunt nu este real, va rugam sa il raportati apasand butonul "Raporteaza Job"
This action will pause all job alerts. Are you sure?
Locuri de munca similare
Fii informat
Aboneaza-te la newsletter-ul nostru si primeste cele mai recente oferte de munca si informatii despre cariera direct in inbox-ul tau.
Securitatea datelor dumneavoastra este importanta pentru noi. Citeste Politica de confidentialitate.