Senior GRC Engineer
Skills
About the role
Role Description:
Company Introduction :
Booking Holdings (NASDAQ: BKNG) is the world leader in online travel and related services, provided to customers and partners in over 220 countries and territories through six primary consumer-facing brands - Booking.com, KAYAK, priceline, agoda.com, and OpenTable. The mission of Booking Holdings is to make it easier for everyone to experience the world.
Job Overview :
Booking Holdings India is a Center of Excellence (COE) based in Bangalore, India and was created to support the increasing business demands of Booking Holdings Inc. and its Brands. The COE is a key enabler of Booking Holdings Inc.’s global talent strategy for several technology functions such as Cybersecurity, Fraud monitoring/analytics, IT, and others across our Brand subsidiaries.
At Booking.com, data drives our decisions. Technology is at our core. And innovation is everywhere. But our company is more than datasets, lines of code or A/B tests. We’re the thrill of the first night in a new place. The excitement of the next morning. The friends you encounter. The journeys you take. The sights you see. And the memories you make. Through our products, partners and people, we make it easier for everyone to experience the world.
Booking.com follows a defence‑in‑depth strategy for managing its risks, with three lines of defence. Global Internal Audit (GIA) is responsible for the 3rd line, Risk & Controls (R&C) for the 2nd line, while the 1st line risk responsibilities for Central Tech and Security, Safety & Fraud (SS&F) are embedded in business teams and the Tech Risk Operations group.
The GRC Engineering Manager leads a team of engineers responsible for building, operating and continuously improving the technology, data and automation that underpin our governance, risk and compliance (GRC) capabilities.
The role will be key to defining the “next generation” SS&F and CT operational risk management practices using GenAI in the core, ensuring smart and pragmatic regulatory compliance and risk based decision making.
About the Role
To help us accelerate on this journey, we are looking for an Engineering Manager to join our team. The GRC Principal Engineer provides technical leadership for the technology, data and automation that underpin governance, risk and compliance (GRC) capabilities, driving architectural direction, engineering standards and cross-functional execution.
You will provide technical mentorship, guidance and thought leadership across engineering teams, helping raise engineering quality, technical capability and delivery effectiveness in alignment with organizational objectives.
You should be a role model, technically strong to help your team develop and be able to be hands-on when needed. The GRC Senior Engineer drives the technical direction of critical engineering initiatives, ensuring solutions are scalable, reliable, secure and aligned with business objectives.. The role holder is required to analyze technology trends, human talent needs, and market demand to plan projects to ensure resilience in line with current demand and future ambition.
In addition to this, the role will confer with leaders, product, and key stakeholders to determine engineering feasibility, cost effectiveness, scalability, and time-to-market for new and existing products.
B.Responsible
1. Leadership & Strategy
Define the GRC engineering vision, roadmap and operating model, aligned with security, risk and business strategy.
Provide technical leadership and mentorship across engineering teams, establishing engineering standards, promoting technical excellence, and helping engineers grow through coaching, design reviews and knowledge sharing.
Act as a trusted partner to senior stakeholders in Tech Risk Operations, as well as 2nd line Risk.
Champion a culture of automation, data-driven decision making and continuous improvement in how we manage risk and compliance.
2. GRC Platform & Tooling Ownership
Own the GRC technology stack (e.g. GRC platform, risk & controls inventory, evidence management, reporting).
Design and oversee integrations between GRC tooling and core systems (e.g. CI/CD, cloud platforms, identity, ticketing tools such as Jira/ServiceNow, data platforms).
Ensure the GRC platform supports end-to-end workflows for risk assessments, control design, testing, issues and remediation.
Drive scalability and reliability of GRC tooling, including access control, performance, availability and data quality.
3. Control & Compliance Automation
Translate requirements from frameworks such as NIST, PCI-DSS, SOX, GDPR, NIS2, EU AI/DSA/DMA into technical patterns and guardrails.
Lead the design and implementation of control-as-code / policy-as-code and automated checks in CI/CD, cloud, and application environments.
Identify manual compliance bottlenecks and lead initiatives to automate evidence collection, reporting and testing using scripting, APIs and workflow engines.
Partner with security engineering and platform teams to ensure security and compliance are baked into standard platform offerings.
4. Collaboration with Audit, Security & Compliance Functions
Oversee technical risk assessments for new platforms, major architectural changes and high-risk initiatives.
Act as a bridge between engineering teams and internal/external audit, helping translate technical designs into risk and control language.
Support audit and assurance cycles (e.g. SOX, PCI, ISO 27001, SOC 2) by ensuring GRC tooling can surface reliable evidence.
Partner with Legal, Privacy and Security to operationalise new regulatory requirements into sustainable engineering and process changes.
5. Ways of Working & Continuous Improvement
Establish and refine standards, patterns, runbooks and documentation for GRC engineering solutions.
Define and track KPIs (e.g. control automation coverage, time-to-remediate, number of manual attestations replaced by automation).
Continuously improve methodologies for risk assessment, control design and testing to keep pace with evolving technologies and regulations.
B.Skilled
Level of Education : Bachelor or Master’s degree in Information Technology, Computer Science, Engineering, Information Security, Business, or a related field. Relevant professional certifications (e.g. CISA, CISM, CISSP, CRISC, cloud certifications) are a plus.
Years of relevant Job Knowledge : Extensive Knowledge (8-12 years)
Requirements of special knowledge/skills
8-12 years of relevant job experience, with previous experience in people management
Strong technical skills (coding & system design) and a deep understanding of software development in a team, as well as a track record of developing and shipping software
Inspire and motivate multiple cross functional product teams
Lead by example by taking ownership, being proactive, and collaborating
Foster a great culture that innovates, work together as a team, partner with other Booking.com teams and roles, and celebrates unified success
Respects the Booking.com values and uses them as a guide to the way we work
Mastery in technology leadership including shaping ways of working
Engineering delivery, quality, and practices within own team including delivery management
Delivery of the wider Engineering strategic objectives
Embed Agile ways of working and values within the organization
Get into the technical detail where required to coach, support, and mentor the team
Engineering Craftsmanship including coaching and mentoring the team
Adhere to the default principles for Architecture, quality, and non-functional requirements
Drive a culture of ownership and technical excellence, including reactive work such as incident escalations
Learn new technologies and keep abreast of existing technologies and be able to share learning’s and apply these to a variety of projects as applicable
Thought partner for Product to define, shape, and deliver the roadmap
Build new products, processes, and operational plans
Negotiate on the strategic importance of own product roadmap features
Drive innovation in own team
Own the architecture across own team
This role may be required to work on an on-call rotation
Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.