Booking Holdings Romania - IT Risk & Compliance Officer (PCI)
Adaugat: 1 săptămână în urmă
Booking Holdings
Booking Holdings Romania - IT Risk & Compliance Officer (PCI)
Adaugat: 1 săptămână în urmă
Booking Holdings
Acest anunt este cu aplicare externa. Cand dati click pe Aplicare Externa veti fi redirectionat pe un alt site pentru a aplica.
Booking Holdings Romania is a Center of Excellence based in Bucharest, Romania and was created to support the increasing business demands of the Booking Holdings Brands. The Center of Excellence provides access to specialized and highly skilled talent, leading industry best practices, and collaboration opportunities across all of our Brands.
As part of our Booking Holdings Romania team, you will have the opportunity to be a part of the world's leading provider of online travel, with a mission of making it easier for everyone to experience the world through six-primary consumer facing brands: Booking.com, Priceline, Agoda, KAYAK, OpenTable and Rentalcars.com.
Role description
The Risk & Compliance Officer (PCI) is an individual contributor with expert-level domain knowledge, proactive and analytical professional with a strong foundation in risk management principles and control management and monitoring. A demonstrated ability to automate and monitor complex processes is a benefit. They will be responsible for partnering with multiple risk owners and business unit managers to identify the regulatory requirements from an IT perspective for PCI-DSS, SOX, NIS2 and other, and will drive appropriate control monitoring, IT compliance monitoring and implementation. The Risk & Compliance Officer (PCI) partners closely with internal and external PCI audit teams, IT Control owners and Business owners, to ensure consistency, timeliness and especially compliance with the PCI Certification requirements. This person must possess a strong understanding and experience of typical PCI IT And Audit phases and requirements and also exhibit versatility in various PCI tech domains and can build a comprehensive knowledge of the end-to-end Booking IT environment and pertinent PCI controls.
The Risk & Compliance Officer (PCI) is also a subject matter expert leveraging a deep understanding of the enterprise risk discipline combining deep knowledge of theory and organizational practice or expertise across several different disciplines within a function. Successful risk expertise requires dynamic individuals who are able to liaise with various senior stakeholders and thus need to be articulate communicators, foster collaboration, integrate perspectives and drive to business beneficial outcomes. They will lead the PCI-DSS control efforts to ensure that the PCI requirements are translated into right-sized scalable controls, that audit readiness is maintained throughout the year and that evidence, remediation and risk decisions are coordinated effectively across a complex technology landscape. The role operates as a highly independent first-line risk partner, bridging engineering teams, control owners, internal auditors and external assessors, including QSA.
This position requires strong stakeholder management skills and requires an individual who can convince others who are skeptical or unwilling to accept new concepts, practices, and approaches.
This role provides a hybrid way of working with an onsite presence of 2 days/week.
Key Job Responsibilities and Duties
Leads the annual PCI-DSS recertification cycle end-to-end, including planning, scope maintenance, walkthrough preparation, evidence coordination, stakeholder management (follow up, communication, preparation), issue management and support for QSA and audit activities
Acts as the PCI risk partner to platform, service, payments and engineering teams by translating PCI-DSS requirements into practical control expectations and right-sized guidance for cloud, on-prem and DevOps environments
Leads PCI scoping reviews and risk assessments for new services, architectural changes and third-party integrations, and determines impacts to the cardholder data environment, connected systems, control design and evidence requirements.
Designs, enhances and monitors technical and administrative controls and guardrails that keep PCI compliance embedded in engineering processes rather than added late in the delivery lifecycle.
Drives remediation and continuous improvement by tracking deficiencies, performing root cause analysis, coordinating risk-based action plans, standardizing control practices and improving reporting through tools such as JIRA and ServiceNow
Is responsible for the evidence collection throughout the PCI-DSS recertification process and partnering with the engineering and QSA teams for ensuring timely and complete delivery of the required information.
Role Qualifications and Requirements
Bachelor's degree or equivalent practical experience in Information Security, Technology Risk, IT Audit, Compliance or a related field.
5-8 years of relevant experience in IT risk, IT compliance, internal controls, IT audit or security governance, with strong hands-on PCI-DSS experience.
Demonstrated ownership of PCI-DSS recertification activities, including scope management, evidence collection, walkthrough support, remediation tracking and auditor or QSA engagement.
Strong knowledge of PCI-DSS requirements, PCI scoping concepts, CDE and connected systems, and artefacts such as AOC, ROC, SAQ and shared-responsibility documentation.
Experience designing, implementing and monitoring technical and administrative controls in modern technology environments, including cloud, IAM, change management, vulnerability management, logging and monitoring, key management, secure SDLC and segmentation-related controls.
Experience leading risk assessments, identifying control gaps, performing root cause analysis and driving practical, risk-based remediation.
Strong stakeholder management skills with the ability to challenge constructively, influence engineering teams and translate technical details into clear risk and compliance language for business and audit audiences.
Strong written and spoken English, with clear and structured communication across cross-functional discussions.
Familiarity with Jira, ServiceNow and similar reporting or workflow tools used for evidence, issue and compliance tracking.
Preferred: Professional certifications such as PCI ISA, CISA, CRISC, ISO 27001 or similar.
Benefits & Perks
Contributing to a high-scale, complex, world renowned product and seeing real-time impact of your work on millions of travelers worldwide
Working in a fast-paced and performance driven culture
Technical, behavioral and interpersonal competence advancement via on-the-job opportunities, experimental projects, hackathons, conferences and active community participation
Competitive compensation and benefits package
Vast amounts of data to validate your ideas and the opportunity to experiment with real users
Booking Holdings is proud to be an equal opportunity workplace and is an affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.
Sfaturi de siguranta
- Nu trimiteti niciodata BANI in avans sau acte de identitate pentru aplicarea la un loc de munca. Nu trimiteti bani in avans pentru promisiuni de angajare sau alte oferte similare.
- Daca aveti impresia ca acest anunt nu este real, va rugam sa il raportati apasand butonul "Raporteaza Job"
This action will pause all job alerts. Are you sure?
Locuri de munca similare
Fii informat
Aboneaza-te la newsletter-ul nostru si primeste cele mai recente oferte de munca si informatii despre cariera direct in inbox-ul tau.
Securitatea datelor dumneavoastra este importanta pentru noi. Citeste Politica de confidentialitate.