Risk and Compliance Officer, Tech
Listed on 2026-05-03
-
IT/Tech
Cybersecurity, Data Security
About the Department and Team
follows a defence in depth strategy for managing its risks. As part of this strategy, Booking has 3 departments focussing on each line of defence. Global Internal Audit (GIA) is responsible for the 3rd line of defence, Risk and Controls (R&C) is responsible for the 2nd line of defence, while the responsibility of 1st line has been distributed between process/control owners and the Trust, Risk, Assurance and Compliance (TRAC) team.
TRAC is the first‑line risk team responsible for Central Tech business unit risks & Security, Safety & Fraud (SS&F) risks across the company.
The Risk & Compliance Officer is an individual contributor with expert‑level domain knowledge, proactive and analytical professional with a strong foundation in risk management principles and a demonstrated ability to automate complex processes.
They will be responsible for partnering with risk owners throughout the SS&F department, and other business units, to identify applicable risks, drive appropriate risk responses, and support the design of fit‑for‑purpose internal controls in line with our risk appetite, maintain the quality of our processes, and ensure regulatory compliance obligations are met. The role requires close collaboration with stakeholders from multiple departments, and to have a strong big picture focus, but be able to zoom in and out of the details to ensure full process understanding.
In addition, the role requires hands‑on experience in automating workflows and processes.
The Risk & Compliance Officer role requires solid stakeholder management skills, and to be comfortable with challenging risk owners to come up with robust, scalable and automated solutions which mitigate key risks while enabling successful business operations.
Key Job Responsibilities and Duties1. Risk and Compliance Partnership
- Act as a Risk Partner to platform owners from the Data & Machine Learning Platform domain and development teams, providing expertise in SOX, NIST, DMA, DSA, EU Act, NIS2 and security best practices and tailoring compliance requirements to cloud and devops environments
- Architect Guardrails for secure and compliant onboarding to cloud environments, ensuring that security is baked in rather than bolted on.
- Provide Right‑Sized Advisory on control design. You will champion agile and scalable solutions that solve problems without over engineering, ensuring controls are effective but not obstructive.
- Bridge the Gap between technical teams and audit functions, translating complex tech stacks into risk‑based language for Internal/External Audit.
2. Risk Assessments
- Execute Technical Risk Assessments for new platforms and major architectural changes. You will identify risks in modern tech stacks and support teams in implementing appropriate safeguards.
- Maintain the Risk Inventory. Systematically track and monitor identified issues originating from audits, penetration tests, and risk assessments to ensure maintains a robust and resilient risk posture against current and emerging attack vectors.
- Perform Root Cause Analysis on issues to identify systemic risks and propose structural improvements to the control framework.
3. Automation & Continuous Improvement
- Drive Automation Initiatives by identifying manual compliance bottlenecks and designing efficient workflows leveraging automation and AI.
- Unify Control Frameworks across various platforms to simplify compliance and reduce compliance fatigue for engineering teams.
- Enhance Methodology:
Contribute to refinement of risk assessment procedures to keep pace with the dynamic nature of a high‑growth tech environment.
4. Risk Reporting & Compliance Execution
- Deliver Data‑Driven Risk Insights by reporting on risk coverage and issues using tools like Jira and Service Now.
- Support Audit Readiness by ensuring that platform owners are prepared for regulatory cycles, walkthrough preparation and facilitation, coordinating evidence requests and drafting remediation & mitigation memos as needed and aligning with engineering teams
You will partner with risk owners by providing guidance and support in designing and implementing appropriate controls to…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: