Cyber Defense Technical Operations & Response Team Leader
Adaugat: 2 zile în urmă
BOOKING HOLDINGS ROMANIA S.R.L.
Acest anunt este cu aplicare externa. Cand dati click pe Aplicare Externa veti fi redirectionat pe un alt site pentru a aplica.
This role provides a hybrid way of working with an onsite presence of 2 days/week.
Key Job Responsibilities and Duties
- Identifies and automates manual, repetitive tasks within the security operations center (SOC) workflows, in alignment with departmental continuous improvement goals, in order to remove operational bottlenecks and increase analyst efficiency.
- Leads and mentors a mixed operational shift team of full-time employees and external contractors, in accordance with company human resource guidelines and delivery baselines, in order to maintain high team morale, prevent attrition, and ensure stable shift coverage.
- Evaluates and audits daily security alerts and analyst investigation notes across corporate cloud, identity, network, and endpoint infrastructures, based on established quality assurance standards, in order to identify technical gaps, verify correct alert handling, and prevent missed security incidents.
- Coordinates response and mitigation efforts for complex security events alongside the Incident Response (IR) team and external vendors, utilizing CSIRT playbooks and modern security tools like SIEM, EDR, and SOAR, in order to achieve fast threat containment and determine the root cause of active threats.
- Translates and communicates technical risk and incident status to non-technical business partners, stakeholders, and clients, in alignment with corporate communication and stakeholder protocols, in order to ensure clear visibility, build trust, and resolve cross-departmental security gaps.
- Updates and maintains operational documentation, runbooks, and assigned projects for the detection and response ecosystem, under the direction of the Cyber Detection and Response (CDR) Manager, in order to guarantee standardization of team workflows and protect long-term service stability.
Benefits:
- Health insurance
- Prepaid medical subscription (Regina Maria)
- Life insurance
- Meal vouchers
- Learning wallet
- Travel benefit
- Annual vacation leave of 25 business days, pro rata with the working period
- Birthday day off
- Summer break (short Fridays during summer)
- Work from Abroad program (up to 20 days/year in EU)
- Floating days off
- 2 Volunteer days/ year
- Home office one-time bonus
- Bookster
- Linkedin learning platform
- Headspace
- Employee discounts (travel, gym, dental, vision)
- Experience: 5+ years working in a SOC or an Incident Response environment.
- Leadership: Experience leading a team, managing shift schedules (ROTA), and mentoring junior analysts.
- Problem Solving: A proven track record of changing processes and workflows to make a team more efficient.
- Communication: Clear and direct communication skills in English, both written and spoken.
- Certifications: Security+, CySA+, GCIH, or CISSP are helpful, but your actual work experience is more important to us. Advanced technical certifications (like OSCP or GREM) are a bonus.
- Must have strong experience evaluating security alerts across modern corporate infrastructures (Cloud, Identity, Network, Endpoint).
- Ability to quickly read an analyst's investigation notes, spot technical gaps or missing evidence, and guide the next steps of the incident lifecycle.
- Proven experience using enterprise-grade SIEM, EDR, and SOAR tools to identify attack patterns (such as living-off-the-land techniques or lateral movement).
- Collaborate with the IR team on complex security incidents to achieve efficient mitigation for active threats and identification of the root cause.
- Collaborates on various departmental projects that help the organization improve its cyber security posture and achieve its mission/objectives
- Collaborates with different CDR stakeholders and vendors to remediate any identified gaps
- Masters and uses CSIRT’s playbooks, runbooks, workflows, operational documentation, and processes. Contributes to the writing and maintenance of all such documents.
- Owns and delivers on assigned projects (often around improvements to detections, processes and playbooks) while balancing execution and deliveries with operations and IR workload; Supports other team members in projects.
- Drives continuous improvements of our detection and response capabilities by identifying and owning improvement areas in the technology, methods, processes (including opportunities around detection tuning and automation).
- Offers on-call support during the nights, weekends and public holidays (optional)
Booking Holdings Center of Excellence is part of Booking Holdings, the world's leading provider of online travel and related services, with a rich heritage of digital innovation. The Center provides access to specialized and highly skilled talent, supports projects powered by new and emerging technologies, leverages industry best practices, and fosters collaboration opportunities across all of the Booking Holdings brands, including Booking.com, Priceline, Agoda, KAYAK and OpenTable.
If you are interested to find out more about the Booking Holdings Center of Excellence visit our website: www.bookingholdings-coe.com.
Booking Holdings (NASDAQ: BKNG) is the world’s leading provider of online travel and related services, provided to consumers and local partners in more than 220 countries and territories through five primary consumer facing brands: Booking.com, Priceline, Agoda, KAYAK and OpenTable. The mission of Booking Holdings is to make it easier for everyone to experience the world.
Sfaturi de siguranta
- Nu trimiteti niciodata BANI in avans sau acte de identitate pentru aplicarea la un loc de munca. Nu trimiteti bani in avans pentru promisiuni de angajare sau alte oferte similare.
- Daca aveti impresia ca acest anunt nu este real, va rugam sa il raportati apasand butonul "Raporteaza Job"
This action will pause all job alerts. Are you sure?
Locuri de munca similare
Fii informat
Aboneaza-te la newsletter-ul nostru si primeste cele mai recente oferte de munca si informatii despre cariera direct in inbox-ul tau.
Securitatea datelor dumneavoastra este importanta pentru noi. Citeste Politica de confidentialitate.