Skip to content
Security Engineer

Security Engineer

Booking Holdings Romania - Cybersecurity Incident Responder II, Enterprise Security

Booking Holdings (NASDAQ: BKNG)

Bucharest

Apply on the employer's site

Role description

Booking Holdings Romania is a Center of Excellence based in Bucharest, Romania and was created to support the increasing business demands of the Booking Holdings Brands. The Center of Excellence provides access to specialized and highly skilled talent, leading industry best practices, and collaboration opportunities across all of our Brands.

As part of our Booking Holdings Romania team, you will have the opportunity to be a part of the world’s leading provider of online travel, with a mission of making it easier for everyone to experience the world through five-primary consumer facing brands: Booking.com, Priceline, Agoda, KAYAK and OpenTable.

This role provides a hybrid way of working with an onsite presence of 2 days/week.
Role Description
The Cyber Security Incident Responder is a key player in providing detection, investigation and response to cyber security attacks and threats such as ransomware, spear-phishing, cloud-based attacks, and Advanced Persistent Threats (APTs).

This highly specialized technical subject matter expert position focuses on investigating threats and alerts within large-scale cross-platform environments, performing threat hunting and digital forensics in order to identify intrusions and effectively respond to mitigate security threats on the business.

Key Job Responsibilities And Duties

  • Responsible for investigating the incidents escalated by the 24/7 Triage & Monitoring team.
  • Assists the 24/7 Triage & Monitoring team with in-depth investigating cybersecurity alerts raised by a wide variety of security tools like: SOAR, EDR, XDR, IPS/IDS, SIEM, Sandbox, Cloud Security, Email Security, GitLab Security, Container Security.
  • Coordinates incident, response, escalation, and reporting of cybersecurity incidents.
  • Performs technical investigation on complex security incidents to achieve efficient mitigation for active threats and identification of the root cause.
  • Performs quality hands-on technical incident response, log analysis, and threat hunting.
  • Collaborates on various departmental projects that help the organization improve its cyber security posture and achieve its mission/objectives.
  • Collaborates with different CDR stakeholders and vendors to remediate any identified gaps.
  • Define and use CSIRT’s playbooks, runbooks, workflows, operational documentation, and processes. Contributes to the writing and maintenance of all such documents.
  • Looks for opportunities to improve documentation and standardization of CSIRT processes.
  • Owns and delivers on assigned projects (often around improvements to detections, processes and playbooks) while balancing execution and deliveries with operations and IR workload; Supports other team members in projects.
  • Drives continuous improvements of our detection and response capabilities quality and efficiency by identifying and owning improvement areas in the technology, methods, processes (including opportunities around detection tuning and automation).
  • Works on shifts covering 16/5 (Monday to Friday, 7 AM - 10 PM).
  • Offers on-call support during the nights, weekends and public holidays.

Role Qualifications And Requirements

  • This role requires technology subject matter expertise in performing hands-on technical incident response, in-depth technical investigations and Threat Hunting. It is an individual who reads logs, collects technical evidence and puts together the full picture. The ideal candidate is well plugged in the world of hacking and defense and adversary techniques, all with a hands-on keyboard perspective.
  • 3+ years of operational security experience (SOC, Incident Response, Malware Analysis, etc.).
  • Bachelor's Degree OR equivalent experience and relevant certification (such as CompTIA Security+, Network+, CySA+, CCNA, CCNA CyberOps, GCIH, GCFR, GEIR, GCIA, GCFA, GCFE, GSEC, GCED, GREM, OSCP, OSCE, and similar).
  • Experience working independently to detect, handle, investigate and effectively respond to cybersecurity incidents.
  • Ability to assess security incidents quickly and communicate/coordinate a course of action to respond to the incident, while mitigating risk and limiting the impact.
  • Practical experience identifying adversary techniques, tactics, and procedures with enterprise security tools with a demonstrable understanding of modern attacker methodologies.
  • Experience developing and maintaining operations playbooks, runbooks, and operational documentation.
  • Robust understanding of IT fundamentals across networking, system, cloud, virtualization platforms , application layers and advanced understanding of at least one operating system (Windows, Linux, OSX).
  • Good interpersonal and communication skills in order to share knowledge and to communicate effectively with different stakeholders (IT and business partners).
  • Experience with projects or issues of high complexity that require knowledge across multiple technical areas and business units.
  • Highly disciplined and motivated: a self-starter who is able to both work independently or as a member of a team.
  • Demonstrates a Can-Do, delivery-focused and solution-oriented approach (rather than problem-oriented); Flexible, practical, and positive mentality. Is quick to adapt to changing situations.
  • Constantly demonstrates ownership and proactiveness in seeking to improve and optimize in anything related to their and their team’s work.

Benefits & Perks

  • Contributing to a high scale, complex, world renowned product and seeing real-time impact of your work on millions of travelers worldwide
  • Working in a fast-paced and performance driven culture
  • Technical, behavioral and interpersonal competence advancement via on-the-job opportunities, experimental projects, hackathons, conferences and active community participation
  • Competitive compensation and benefits package
  • Vast amounts of data to validate your ideas and the opportunity to experiment with real users

Booking Holdings is proud to be an equal opportunity workplace and is an affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.

Pre-Employment Screening
If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

Coming to this page

A resume for this role — and a ticket to the draw

We take the posting apart down to the real requirements and rewrite your resume against it — by asking, not inventing: no line appears without your confirmation. Sign in to get it first, and to enter the draw.

  • A resume for this exact role, not a universal one
  • Answers are kept: edit any one, not the whole conversation
  • All in your account — open it from any device

On the wheel

A discount on mentoring

Winners are drawn at random among entries with a confirmed email. The date and the full rules are on the draw page.

Draw rules

Security Engineer

Senior Information Security GRC Specialist

Reconomy

Bucharestfulltimesenior

Apply on the employer's site

Role description

Department:
Technology

Employment Type:
Fixed Term - Full Time

Location:
Bucharest

Reporting To:
Tom Whitheouse

Compensation:
RON29,060 - RON34,238 / month

Description
RecoTek is Reconomy’s new centralized technology hub located in Bucharest, Romania, officially launched in February 2024. Serving as the backbone of Reconomy’s tech operations, it consolidates inhouse expertise across all Reconomy brands to accelerate platform development and enhance service delivery.

Reconomy is an international circular economy specialist that combines technology, skills and incredible people to enable businesses to better manage their resources, helping reduce waste, optimise their supply chains, and contribute in a meaningful way toward the circular economy

Reconomy is bending the edges of linear business models across the world, integrating circular economy strategies and processes into everyday operations. We have the tools, talent and technology that enable customers to harness the full and inherent value of their resources, with integrated global operations in over 80 countries across the world.

Reconomy’s full range of capabilities are organized into 3 ‘loops’: Recycle, Comply and Re-use, each providing opportunities for circularity within the wider resource cycle.

  • Recycle loop is utilising the latest technology and data to enable customers to make the best possible use of their materials.
  • Comply loop is enabling customers to solve increasingly complex environmental regulatory challenges using data, expert knowledge and thought leadership to drive business accountability across the globe.
  • Re-use loop is providing intelligent technology platforms and agile delivery models for pre-retail logistics and product returns, fulfilment and processing, on behalf of many of Europe’s largest retailers.

About The Role
Are you passionate about information security, governance, and driving meaningful change in a global organisation? Join Reconomy as a
Senior Information Security GRC Specialist
on a
12-month fixed-term contract
and play a key role in shaping and strengthening our Governance, Risk & Compliance (GRC) programme across an international business operating in more than
25 countries
.

In this role, you'll work at the intersection of security, technology, and business, partnering with senior stakeholders to ensure our security and compliance programmes not only meet evolving regulatory requirements but also enable business growth.

You'll lead strategic compliance initiatives, oversee major certification audits such as
ISO 27001
and
SOC 2
, manage relationships with external auditors, and drive the continuous evolution of our GRC framework. From implementing new compliance standards and improving risk management processes to introducing automation and developing executive-level reporting, you'll have the opportunity to make a visible impact across the organisation.

Beyond delivering operational excellence, you'll act as a trusted advisor to the business, mentor colleagues, and collaborate with cross-functional teams to build a strong culture of security and compliance.

This is an excellent opportunity for an experienced GRC professional looking to take ownership of high-impact initiatives, work in a collaborative international environment, and influence the future of information security within a fast-growing global organisation.

What We Need From You

  • 5+ years of experience in Information Security Governance, Risk & Compliance (GRC) or a similar compliance-focused role.
  • Proven experience leading security and compliance programmes in complex or international organisations.
  • Strong knowledge of industry frameworks and standards such as ISO 27001, SOC 2, GDPR, and other relevant regulatory requirements.
  • Experience planning, coordinating, and successfully managing internal and external audits.
  • Excellent understanding of risk management principles and the ability to translate regulatory requirements into practical business solutions.
  • Strong stakeholder management and communication skills, with confidence engaging technical teams, business leaders, and senior executives.
  • Experience working across multiple business functions in a collaborative, fast-paced environment.
  • Hands-on experience with GRC platforms and security compliance tools.
  • Strong analytical and problem-solving skills, with the ability to interpret data and provide meaningful insights.
  • Bachelor's degree in Information Security, Cyber Security, Computer Science, Risk Management, or a related field (or equivalent experience).
  • Professional certifications such as CISA, CISM, CRISC, or equivalent are highly desirable.
  • A proactive mindset with a passion for continuous improvement, process optimisation, and driving positive change.
  • Experience within a global organisation, high-growth environment, or private equity-backed business would be an advantage.
  • Experience with vendor risk management, privacy programmes, cloud compliance, or security automation is a plus.
  • Willingness to travel internationally when required (up to 20%).
  • A strategic thinker who can balance business objectives with security and compliance requirements.
  • A confident communicator who can influence stakeholders at all levels of the organisation.
  • Comfortable leading complex initiatives while managing multiple priorities.
  • Passionate about building scalable, efficient, and effective GRC processes.
  • Curious, collaborative, and always looking for opportunities to improve the way we work.
  • Someone who embodies Reconomy's values: Real, Inclusive, Collaborative, and Inventive.

What We Offer

  • This role offers you the chance to work in a friendly, diverse and international environment, along with colleagues who will share your passion for innovation, agile-working and growth. You will also be able to develop your skills within the exciting and challenging market of Reverse Logistics!
  • Hybrid working environment
  • Training and development to keep you in touch with the latest technologies and the opportunities to apply your learning.
  • We offer a competitive salary alongside other benefits*
  • Our office is easily accessible located near the city center of Bucharest, and designed to make you feel at home
  • 22 working days of annual leave, plus 2 additional days allowed for participation in volunteering programs, and 1 extra day off for your birthday
  • Meal vouchers: 45 RON per working day (taxed according to current legislation)
  • Private medical subscription at Regina Maria.

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

Security Engineer

Security Operation Center Coordinator

Molson Coors GBS

Bucharest

Apply on the employer's site

Role description

Requisition ID:
39630

Molson Coors is a leading brewer with 18,000+ employees, 30+ breweries and 130+ beer brands, consumed in more than 50 countries. Our GBS history in Romania started in 2017, when Molson Coors Global Business Services was established in Bucharest, and since then we have become a 650 people strong organization and growing continuously.

We deliver centralized operations to our Molson Coors Business Units across the Globe in Finance, Master Data, Commercial, HR and IT Business Services. Our impressive brands portfolio across the world includes Miller Genuine Draft, Madri, Staropramen and Bergenbier.

The job holder is responsible for coordinating and improving cybersecurity incident response, threat hunting, and data analysis to protect and maintain the overall security of the enterprise.

They analyze security incident response procedures and security controls, evaluating trends, looking for gaps in process, offering suggestions for control improvements, and identifying gaps in analyst effectiveness to management.

They will respond to security incidents with higher impacts or in areas without established response guidance.

The job holder is the functional subject matter expert in the security incident handling process.

KEY RESPONSIBILITIES:

  • Manage the incident handling process by coordinating the IT security analyst's work.
  • Triage different incidents, if needed, and direct IT analysts to work on higher priority incidents.
  • Create new security incident handling processes and update procedures for security analysts to follow as systems change, controls are updated, or as new threats and attack behaviors are identified.
  • Create additional training material for IT security analysts to further aid in the incident handling process, materials that will be reviewed and approved by management.
  • Act as key contributor to the Security Incident Response Plan, evaluating impact to IT systems, and analyzing effectiveness of the incident handling processes.
  • Assess of the IT environment for undetected threat activity by researching on new threat activity trends, identifying indicators of compromise, and prioritizing data sources to hunt for areas of undetected threat activity.
  • Report identified activity to management.
  • Coordinate MSSP IR teams.

SKILLS & RELEVANT WORK EXPERIENCE:

  • At least 3 years of experience in information security, with a demonstrated track record of progressively increasing responsibility.
  • Professional certifications: CompTIA Security+, CISSP, GCIH (Preferred)
  • Experience with common security tools SIEM, IPS/IDS, EDR, AV, Scanners, NetFlow, Firewall, VPN, Cloud Azure/AWS, Log Management, etc.
  • Knowledge of at least 1 of the following programming languages such as PowerShell, Python, Perl, C/C++, PowerBI, etc.
  • Strong knowledge of information security best practices, standards, and regulations.
  • Knowledge of operating systems including Linux/Unix or Windows.
  • Deep understanding of computer intrusion activities, incident response techniques, tools, and procedures.
  • Thorough knowledge of incident response methodology as well as at least of the following: security architecture, system administration and networking.
  • Excellent leadership and team management skills.
  • Effective communication and interpersonal skills.
  • Strong problem-solving and analytical capabilities.
  • Good time management and organizational skills.
  • Ability to navigate ambiguous situations.
  • Resilience
  • Ability to work well under pressure

Job Posting Grade: 11
Molson Coors Global Business Services is an equal opportunity employer. We invite applications from candidates of all backgrounds, race, color, religion, sex, national origin, age, disability, veteran status or any other characteristic. If you have a disability and need any kind of support during the application or recruitment process, please send us an email at GBScareers@molsoncoors.com and our team will gladly assist you.

Pay and Benefits:
At Molson Coors Global Business Services, we believe in rewarding our people fairly, transparently, and equitably for the impact they make.

Our Total Rewards package includes a gross base salary of
lei250,800.00
-
lei329,200.00
(posting salary range) plus a
18 %
target annual bonus, alongside a comprehensive benefits offering designed to support different needs and life stages: a medical subscription (with dental and vision coverage), life insurance, a monthly budget to spend on flexible benefits, wellbeing support, an Employee Assistance Programme and 22 days annual leave with additional days off for vintage and birthday.

The salary range shown above reflects what we, in good faith, believe we would pay for this role at the time of posting. Final pay is based on a number of non‑discriminatory factors, such as previous experience, skills and internal equity.

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

Security Engineer

Senior Security Incident Responder (m/f/d)

Allianz Technology

Bucharest

Apply on the employer's site

Role description

About The Job
Join us at the ACDC (Allianz Cyber Defense Center), where we are revolutionizing cybersecurity on a global scale! We're a dynamic team of international experts, working around the clock from various locations worldwide to defend Allianz against ever-evolving cyber threats. Our mission is clear: Protect Allianz Assets, Employees and Customer Data from cyber threats while continually elevating our processes and expertise.

The Incident Response cluster within the Allianz Cyber Defense Center (ACDC) is a team of dedicated Incident Responders with the mission to limit the impact of security incidents of Allianz’s infrastructure worldwide. We are responsible for coordinating the response to Cyber Security incidents and conduct investigations within Allianz. We are also actively involved in internal strategic projects and contribute to enhancing Allianz's overall security posture.

What You Do

  • Coordinate and own security incident response activities in a heterogeneous, multi-cultural and geographically distributed environment, considering all relevant technical and non-technical stakeholders during all phases of the incident.
  • Acquire and analyze data during incident response activities from various sources and report on the findings.
  • Perform reviews of incidents and identify improvement potentials, and support in implementing improvement ideas (like updating Guidelines, Runbooks, etc.).
  • Help improve ACDC’s internal toolset by contributing with new ideas on functionality and features.

What You Bring

  • A university degree (Master's degree preferred) in Computer Science, Cyber Security, or a related field with extensive work experience in Incident Response, including experience in managing complex environments; expertise in IT Forensics, Malware Analysis, or Vulnerability Management is a plus. In-depth knowledge of fundamental attack concepts (terminology, tools, processes, etc.).
  • Comprehensive technical expertise in system architecture with broad exposure to and proficiency in key technologies relevant to IT Security, including, but not limited to, Linux and Windows operating systems, Active Directory / Entra ID, web technologies, e-mailing, networking, cryptography, as well as widely used DevOps tools and configurations
  • Proficiency in software engineering skills (Python, Golang, Shell scripting, PowerShell, CI/CD, and database management) and a strong understanding of technical and organizational aspects of information security, demonstrated through prior defensive or offensive work experience.
  • Demonstrate a high degree of problem-solving skills and innovative thinking, exceptional analytical skills with the ability to collect, organize, analyze, and disseminate significant amounts of information with a strong focus on detail and accuracy.
  • Clear and concise communication; capable of engaging with collaborators of different backgrounds, technical levels, and expertise, and working proactively. Fluent in English, both spoken and written, including proficiency in security terminology.
  • Willingness to participate in on-call shifts, as our team needs to be available 24/7
  • Relevant industry certifications such as SANS/GIAC (e.g., GCIH, GNFA, GCFA, GREM, GCFE, GIME), CompTIA Security+, CISSP, CISA, or CISM are considered a plus but are not mandatory—what truly matters is your ability to demonstrate profound knowledge and expertise in the incident response field
  • Machine learning knowledge is a strong advantage.

What We Offer

  • We offer a hybrid work model which recognizes the value of striking a balance between in-person collaboration and remote working incl. up to 25 days per year working from abroad.
  • We believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location).
  • From career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostered.
  • Flexible working, health and wellbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teach.

About Allianz Technology
With its headquarters in Munich, Germany, Allianz Technology is Allianz's global IT service provider and delivers IT solutions that drive the group's digitalization. With more than 11,000 employees in over 20 countries around the world, Allianz Technology is tasked to run, optimize, transform and innovate the infrastructure, applications and services together with Allianz companies to co-create the best customer experience.

We service the entire spectrum of digitalization – from one of the industry's largest IT infrastructure projects that spans data centres, networks and security, to application platforms ranging from workplace services to digital interaction.

In short: We deliver comprehensive end-to-end IT solutions for Allianz in the digital age. We are the backbone of Allianz.

Find us at: www.linkedin.com/company/allianz\-technology.

Commitment to Integrity, Fairness & Inclusion
Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges, is what makes us a unique employer. Together we can build an environment where everyone feels empowered and has the confidence to explore, to grow and to shape a better future for our customers and the world around us.

We at Allianz believe in a strong inclusive culture that encourages people to speak their minds, get involved and question the status quo. We are proud to be an equal opportunity employer and encourage you to bring your whole self to work, no matter where you are from, what you look like, who you love, or what you believe in. We therefore welcome applications regardless of race, ethnicity or cultural background, age, gender, nationality, religion, social class, disability, sexual orientation, or any other characteristics protected under applicable local laws and regulations.

To Recruitment Agencies
Allianz Technology has an in-house recruitment team that sources great candidates directly. Therefore, Allianz Technology does not accept unsolicited resumes from agencies or search firm recruiters.

When we do work with recruitment agencies, that engagement is formalized by a contract. Fees will only be paid when there is a contract in place. Without a contract in place, we will not accept invoices on unsolicited resumes, even if the candidate was ultimately employed by Allianz.

104726 | IT & Tech Engineering | Professional | PG11 | Allianz Technology | Full-Time | Permanent

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

Security Engineer

Cybersecurity Compliance Manager

Deloitte

Bucharest

Apply on the employer's site

Role description

Description & Requirements
Who we are looking for

  • At least 5 years of experience in information security, risk management, or regulatory compliance functions, ideally operating within a multi-country or regional environment as internal staff or an external consultant;
  • Security related certification such as CISSP, CISM or CRISC is a plus;
  • Strong working knowledge of NIS2 and its national transpositions and the ability to translate legal and regulatory text into operational requirements;
  • Working knowledge of ISO 27001, ISO 22301, NIST, Cyber Fundamentals is an advantage;
  • Experience and knowledge in Information Security Risk Management;
  • Experience conducting information security audits and risk assessments including managing external auditors and regulatory audit cycles is an advantage;
  • Practical experience with security incident response and statutory incident notification to regulatory authorities;
  • Knowledge of administrative, technical/logical and physical information security controls;
  • Very good communication and presentation skills and service quality oriented;
  • Proficiency in Microsoft Office;
  • English - advanced level, both written and spoken; additional regional language in one of the in scope countries (Polish, Romanian, Czech, Slovak, Slovenian, or Hungarian) is an advantage;
  • Comfortable with information technology, systems and data;
  • Analytical skills and thoroughness;
  • Sense of responsibility, independence and willingness to learn and implement new processes.

Your future role
We are looking for a Cybersecurity Manager to take ownership of NIS2 compliance across our in-scope entities in Central Europe (Poland, Romania, Czech Republic, Slovakia, Slovenia, Bulgaria and Hungary), working across regional and local stakeholders to embed regulatory requirements into day-to-day operational practice and ensure ongoing compliance with regulatory requirements.

This role sits within the regional CISO team, offering direct visibility into strategic security decision-making and the opportunity to meaningfully shape it. The individual in this position will have a tangible impact on regulatory standing and operational resilience across the region.

Scope of responsibilities:
1.Develop an understanding of local requirements:

  • Maintain a continuous awareness of NIS2 laws and regulations across the various countries of Central Europe and cooperate with local legal experts and consultants to understand scope and impact across the company;
  • Maintain and continuously update the roster of local roles and responsibilities of various functions across the company that are required to either act or provide input for NIS2 related matters;
  • Maintain and continuously update the catalogue of business services, hardware and software assets, and third-party suppliers across all in-scope entities, ensuring accuracy and completeness as the operational landscape evolves;
  • Support gap assessment initiatives across in-scope entities, identifying deficiencies in controls, documentation, and processes related to NIS2 and applicable national regulatory requirements.

2.Implement and NIS2 across the Central Europe region:

  • Develop and oversee structured remediation plans to address identified compliance gaps, coordinating remediation efforts across regional security functions and local stakeholders through to closure;
  • Draft, implement and maintain Standard Operating Procedures and Work Instructions to support the compliance framework and satisfy legal and regulatory obligations;
  • Ensure vendor contracts and internal documentation remain aligned with applicable legal and regulatory requirements;
  • Development and ongoing maintenance of security policies, procedures, and supporting documentation, applying version control, periodic review cycles, and management approval processes to ensure continued regulatory alignment;
  • Create and maintain a centralized control matrix related to NIS2 requirements as well as identify local, national level requirements, different from the Directive text and maintain local, country level controls, along with associated policies, procedures and work-instructions.

3.Monitor business continuity requirements:

  • Monitor and support the development, documentation and implementation of a business continuity and disaster recovery framework in alignment with NIS2 requirements, working with the relevant functions to ensure timely delivery and appropriate governance oversight;
  • Monitor periodic testing of business continuity, disaster recovery, and backup procedures including tabletop exercises, technical failover tests, and restoration verification ensuring that accountable teams conduct testing as required, findings are documented and identified gaps are tracked through to remediation.

4.Coordinate local level incident communication with regulatory bodies:

  • Serve as the primary point of contact for national authority inquiries, managing communications and coordinating the cyber incident response process across regional stakeholders and in-scope entities, gathering and disseminating relevant threat intelligence;
  • Manage the end-to-end process of cybersecurity incident notification to national authorities, ensuring all reporting obligations are fulfilled within prescribed regulatory timeframes.

5.Coordinate NIS2 activities to meet regulatory audit and self-assessment requirements:

  • Ensure periodic/event-triggered risk assessments and compliance reviews, including findings documentation, remediation tracking, and escalation to the Risk Register where required;
  • Manage the full lifecycle of mandated periodic regulatory audits, encompassing auditor procurement, scheduling and adherence to prescribed regulatory timelines, including preparation of audit evidence, facilitation of audit sessions, while maintaining an up-to-date Risk Treatment Plan and actively following up on the resolution of audit findings with local entities and regional stakeholders.

6.Monitor, report and participate in the NIS2 governance process across Central Europe:

  • Participate in the decision-making process to ensure that adequate support is allocated across the various business processes across the organization to support both the implementation of NIS2 requirements and the ongoing compliance obligations;
  • Deliver regular reporting on key risk indicators, key performance indicators, and overall compliance status to senior leadership, providing clear and actionable insight into the organization’s regulatory posture;
  • Drive continuous improvement across the compliance and cybersecurity governance framework, proactively identifying opportunities to strengthen controls, streamline processes and enhance the overall regulatory posture.

What we offer
🌱
Great perspective for your career

  • exposure from day one to various industries & a high diversity of tasks, projects and clients of well-known brands, both local and international
  • the chance to work for the Most Desired Employer in Romania, in the Financial Services Industry, six years in a row (Catalyst)
  • well-prepared care process for newcomers / peer learning and coaching program

💡
Continuous learning

  • on the job learning from some of the best experts in our country
  • free access to lifelong learning opportunities through trainings in Business Skills, Technical Knowledge, Professional Qualifications, Soft Skills, depending on your needs
  • thousands of online courses (on LinkedIn Learning, Udemy for Business, GetAbstract and others), on almost any topic you want to learn about
  • Support in obtaining certifications

🎯

Focus on your needs

  • competitive compensation
  • a budget to spend on benefits that suit you, on top of your salary! Choose from a long list, up-to-date with the current reality (private medical insurance, food vouchers, vacation tickets, private pension, high range of online store vouchers and many more)
  • monthly teleworking allowance to cover your expenses while working from home
  • 25 vacation days & 2 sick leave days /year
  • Bookster subscription & corner at the office social area
  • Employee assistance program: free legal, financial, psychological & health support
  • wellbeing monthly programs are available to you covering physical, mental and emotional areas: on-site massage, sports sessions, mindfulness and financial education workshops as well as other topics related to wellbeing
  • travel insurance for professional & personal trips

💻
Flexible working experience

  • hybrid work & flexible working hours. Teams set their team days and client office days, plan office presence together and communicate it clearly
  • exam period at University? Adapt your work schedule to accommodate your finals, while also getting the job done!

🙌

A culture of friendliness and acceptance

  • open colleagues, an environment that encourages everyone to enjoy their job and express their opinions freely and leaders whose doors are always open
  • recurring well-being programs to support your quality of life; an environment that supports everyone’s mental and physical health

🌏

Community involvement

  • 2 volunteering days/year paid by the firm, to support a cause of your choosing
  • the opportunity to volunteer for projects supported by Deloitte in partnership with non-profit organizations, with focus on education

Selection process

  • We thank all applicants in advance for submitting their resumes but please note that only those candidates selected for an interview will be contacted.

About Deloitte
We give you the means and the know-how, you bring the inspiration and the enthusiasm. Join Deloitte Romania and explore where and how far you can go, through the countless learning and professional development opportunities that our company offers and the continuous support of our friendly team!

In Romania, the services are provided by Deloitte Audit SRL, Deloitte Tax SRL, Deloitte Consultanta SRL, Deloitte Accounting SRL, Deloitte Fiscal Representative SRL, Deloitte Tehnologie SRL, Deloitte Support Services SRL, Deloitte Shared Services SRL as well as Reff & Asociații SPRL, the correspondent law firm of Deloitte in Romania, (jointly referred to as “Deloitte Romania) which are affiliates of Deloitte Central Europe Holdings Limited. Deloitte Romania is one of the leading professional services organizations in the country providing services in professional areas of audit, tax, legal, management consulting, financial advisory, risk management services, outsourcing solutions and technology consulting and other related services through over 3,400 national and specialized expatriate professionals. To learn more about how Deloitte makes an impact that matters, please visit www.deloitte.ro and connect with us on Facebook, LinkedIn, YouTube and Instagram.

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

45 more openings in this category and country

Booking Holdings Romania - Cybersecurity Incident Responder II, Enterprise SecurityBooking Holdings (NASDAQ: BKNG) · Romania

Apply on the employer's site
Booking Holdings Romania - Cybersecurity Incident Responder II, Enterprise Security — Booking Holdings (NASDAQ: BKNG) | mentors.coach