Conferința Top Angajatori Undelucram.ro

Descoperă cum se schimbă piața muncii și cum arată realitatea din spatele brandului la angajatori.

Booking Holdings Romania - Senior Security Engineer I - BOOKING HOLDINGS ROMANIA SRL
Aplică extern

Booking Holdings Romania - Senior Security Engineer I

Publicat 28.01.2026 | Expiră 14.03.2026

Descriere job

Booking Holdings Romania is a Center of Excellence based in Bucharest, Romania and was created to support the increasing business demands of the Booking Holdings Brands. The Center of Excellence provides access to specialized and highly skilled talent, leading industry best practices, and collaboration opportunities across all of our Brands.

As part of our Booking Holdings Romania team, you will have the opportunity to be a part of the world’s leading provider of online travel, with a mission of making it easier for everyone to experience the world through six-primary consumer facing brands: Booking.com, Priceline, Agoda, KAYAK, OpenTable and Rentalcars.com.



Role description

 

The Senior Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies such as middle-tier systems and databases. Additionally, the senior security engineer addresses legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. As issues are uncovered, the senior security engineer communicates with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk. Senior Security Engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused.

 

This role provides a hybrid way of working with an onsite presence of 2 days/week.

 

Key Job Responsibilities and Duties

  • Conduct threat modeling and security design reviews for new and changing application features, APIs, and integrations; provide actionable guidance to engineering and product teams.

  • Own incident triage and response for application/security events: coordinate stakeholders, drive containment/eradication/recovery, and ensure clear communications throughout the incident lifecycle.

  • Partner with Product and Engineering to translate business requirements into security requirements, performing risk assessments and defining compensating controls when needed.

  • Validate feature-level security controls and ensure alignment with compliance and industry best practices.

  • Drive post-incident and post-release learning: lead root cause analysis, write postmortems, and track corrective actions to completion (detection improvements, guardrails, design changes).

  • Translate vulnerability findings and incident learnings into prioritized remediation plans and mitigations, including short-term risk reduction and long-term design improvements.

  • Collaborate across teams to anticipate emerging threats, incorporate them into design reviews, and improve detection/response playbooks.

  • Build and maintain automation and tooling to streamline incident investigation (telemetry, alert enrichment, evidence collection) and application vulnerability management workflows.

  • Evaluate and implement vendor security solutions that improve detection, response, and secure design (e.g., logging/SIEM, SOAR, runtime protections, SAST/DAST), ensuring effective integration into SDLC and IR processes.

 

 

Role Qualifications and Requirements

  • 5-8 years of combined Information Security or Information Technology Experience

  • B.S. or M.S. Computer Science or a related field, or equivalent experience

  • You have a breadth of knowledge and experience in incident response, application, infrastructure, and systems security domains.

  • You are a fast learner and have experience partnering with cross-functional teams. 

  • You have experience managing a bug bounty program, including triaging and providing strategic recommendations to engineering leads.  

  • Technical certifications within information security are a plus (CISSP, CCSP, OSCP, OSWE or equivalents)

  • Hacker mindset, passion for security always strive to think like an attacker

  • Experience in assessing new Application Features and establish secure guidelines for Product teams

  • Professional development experience

  • Excellent written and oral communication skills

  • Vulnerability and penetration-testing skills.

  • Excellence in communicating business risk from cybersecurity issues.

  • Proficiency in software development (Java, JS, Go, Python, C++, Ruby, etc.).

  • Solid understanding of network and web protocols.

  • Experience with security of intra-company and third-party APIs.

  • Solid experience with Incident Response and Threat Analysis

  • Experience with dynamic and static analysis tools.

  • Operate with a high level of independence with the ability to act as a mentor to junior Cybersecurity Engineers

  • Strong communication skills are required as well as the ability to work both independently and with a team

 

 

Benefits & Perks

  • Contributing to a high-scale, complex, world renowned product and seeing real-time impact of your work on millions of travelers worldwide

  • Working in a fast-paced and performance driven culture

  • Technical, behavioral and interpersonal competence advancement via on-the-job opportunities, experimental projects, hackathons, conferences and active community participation

  • Competitive compensation and benefits package 

  • Vast amounts of data to validate your ideas and the opportunity to experiment with real users

Booking Holdings is proud to be an equal opportunity workplace and is an affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.

 


Pre-Employment Screening

If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.

BOOKING HOLDINGS ROMANIA SRL

BOOKING HOLDINGS ROMANIA SRL

15 anunțuri active

4.54

52 evaluări

Oportunități de avansare

Pachet salarial

Timp la birou vs. timp liber

Management

Proceduri și valori

Criterii job

Tip job Full-time
Orașe Bucharest, Romania