
Risk and Compliance Officer
Booking.com
Risk and Compliance Officer
Booking.com is seeking a senior AI Risk & Compliance Officer to join the Tech Risk Operations team in Amsterdam. The role involves identifying, assessing, and reporting AI and GenAI risks, translating regulatory frameworks into practical requirements, and partnering with engineering and governance teams. Requires 5-8 years of experience in risk management within complex technology environments.
Risk and Compliance Officer
Booking.com is seeking a senior AI Risk & Compliance Officer to join the Tech Risk Operations team in Amsterdam. The role involves identifying, assessing, and reporting AI and GenAI risks, translating regulatory frameworks into practical requirements, and partnering with engineering and governance teams. Requires 5-8 years of experience in risk management within complex technology environments.
Salary
Core Qualifications
Technical (Must-have)
Soft Skills
Preferred Qualifications
Technical (Nice-to-have)
Key Responsibilities
- Act as a Risk Partner to platform owners and development teams, providing expertise in NIST, EU AI Act, NIS2 and security best practices.
- Architect 'Guardrails' for secure and compliant AI systems development.
- Provide Right-Sized Advisory on control design.
- Bridge the Gap between technical teams and audit functions.
- Lead or perform risk assessments for new AI initiatives, material changes, new providers, high-impact use cases, and AI systems requiring enhanced review.
- Evaluate security and control implications of model access, data flows, prompt and input handling, tool permissions, external integrations, model outputs, human oversight, and fallback mechanisms.
- Provide clear, risk-based conclusions and pre-launch conditions.
- Maintain the AI Risk Inventory.
- Develop and monitor AI risk indicators and metrics.
- Analyse trends, recurring findings, control weaknesses, and changes in the threat or regulatory environment.
- Support risk owners in selecting and documenting appropriate treatment options.
- Follow up on remediation plans and ensure that out-of-appetite risks, overdue actions, and significant control gaps are escalated.
- Perform root-cause analysis on AI-related findings.
- Drive Automation Initiatives by identifying manual compliance bottlenecks and designing efficient workflows.
- Unify Control Frameworks across various platforms.
- Enhance Methodology: Contribute to refinement of risk assessment procedures.
- Contribute to the evolution of Booking.com’s AI risk management framework.
- Identify opportunities to automate risk assessments, evidence collection, control monitoring, issue tracking, and management reporting.
- Deliver Data-Driven Risk Insights by reporting on risk coverage and issues using tools like Jira and ServiceNow.
- Coordinate responses to internal and external assurance activities.
- Support readiness for EU AI Act requirements and other applicable obligations.