Booking NL
Risk Officer (For independent contractors)
We are looking for a Risk Officer to join our Accommodations Business Unit (ABU) Risk Partner team, which operates as the first line of defense at Booking.com.
This role is responsible for supporting the business in managing and mitigating both business and information technology risks through partnering with the business as a risk subject matter expert, and the implementation of a robust Risk Management Process and Internal Control Framework.
As a Risk Officer in ABU, the primary focus is to ensure that our business processes and IT systems operate effectively, comply with internal policies and external regulations, and that risks are identified, assessed, and managed proactively. This position requires a professional who can bridge the gap between operational business requirements and technical IT controls.
B.Responsible: key areas of responsibility will include, but are not limited to:
Develop, implement, and maintain internal control frameworks aligned with industry best practices and applicable regulatory requirements (e.g.,SOX, COSO, COBIT, NIST, ISO 27001, other compliance frameworks)
Collaborate with 2nd line Risk partners, process owners, control owners and management to ensure the frameworks are practical, effective and tailored to business needs
Maintain a central repository of policies, procedures, control matrices
Develop RACI and standardized approach for implementation including training and communication
Develop approach for ongoing review & continuous improvement
Enable business partners with guidelines, templates and tooling
Maintain a central register of all framework documents
Contribute to risk and control reporting and assurance in the business unit
Act as SOx design authority
Partner with R&C and ABU business and IT stakeholders by providing guidance and ensuring that critical SOx controls are adequately designed and documented, in order to strengthen the control environment, mitigate the company risks and support the business in achieving objectives
Provide SME guidance to R&C and ABU business and IT stakeholders and 1st line business owners in relation to observations and deficiencies, from initial assessment/triage through to mitigation and remediation
Support Audit management - act as an SME to support critical audit management activities such as audit planning and issue management
Support testing of business and IT controls and management certification (SOX Section 302 and 404, other compliance frameworks) by providing guidance to the testing team and reviewing the testing documentation.
Collaborate with GRC team and 1st/2nd line Risk partners to develop solutions and improve how risks, controls and issues are maintained in our GRC platform
Act as a risk ambassador within Booking.com to further enhance risk awareness and culture, including by facilitating formal training sessions
B.Skilled
6+ years of previous work experience in internal controls, audit, risk management, or compliance
Bachelor's degree or higher in a relevant field (Master’s Degree is preferable).
Strong knowledge of internal control frameworks (e.g., COSO, COBIT, NIST, ISO 27001) and regulatory requirements (e.g., SOX, GDPR, DMA, DSA), and experience in applying them in various business areas/functions
Qualifications related to any of the above are advantageous (incl. CISM, CRISC, ACCA, CIA, CISA)
Experience with Data Governance, Cloud platforms, SaaS applications, business continuity management, and emerging technologies (AI/ML, RPA) is a plus
Comfortable with modern tech environments such as Devops (Kubernetes, Gitlab, terraform etc.) and also cloud based (AWS, GCP etc.)
Good stakeholder management skills
Flexibility to adapt to an ever-evolving and dynamic work environment
Self-starter with strong sense of responsibility
Energetic and very proactive
Process, problem solving and action oriented mindset
Strong communication and relationship building skills
High level of integrity, confidentiality & professionalism
Ability to develop strong relationships with business partners in order to drive risk management culture and implementation
Fluent in English, both written and spoken (other languages would be a plus)
Project management skills a plus