Senior Engineer, Cybersecurity

Emplacement: China Mainland

État/Province/Ville: Shanghai

Ville: Shanghai

Unité commerciale: Store Support Centre (SSC)

Description et exigences

Who we are  

lululemon is an innovative performance apparel company for yoga, running, training, and other athletic pursuits. Setting the bar in technical fabrics and functional design, we create transformational products and experiences that support people in moving, growing, connecting, and being well. We owe our success to our innovative product, emphasis on stores, commitment to our people, and the incredible connections we make in every community we're in. As a company, we focus on creating positive change to build a healthier, thriving future. In particular, that includes creating an equitable, inclusive and growth-focused environment for our people. 


About this team 

Mission and value delivery focused cybersecurity team in China is to focus to enable business growth with lululemon security guardrails ensure and cyber protection in place with effectiveness and efficiency. Team is also responsible to ensure China specific cyber requirements fulfilled. As an Engineer, you will work as part of a global team supported by our business and architecture partners to help us collaboratively develop and deliver industry leading technology solutions that drive lululemon’s business goals. 


A day in the life:  

This role will bring a high level of technical knowledge for Cybersecurity in China.
This role will be counted on as a leader in your technology space as you contribute to all areas of Application Security and Vulnerability Management in product engineer and operations (pre-production to production).
This role will work closely with a Cybersecurity manager and other technology managers, using experience and knowledge to provide engineering service and process automation, and provide a central escalation point for production concerns. You will apply that knowledge by working closely with Staff Engineers and service providers to promote platform level change. Senior Engineer takes production readiness and performance personally and help drive continuous improvement. You will be considered the technical owner of the production system(s) you work on and focus on how your product(s) are delivered and how to optimize them for efficiency, security and reliability. 
  • Partner to define China cybersecurity roadmap and plans to enable business growth and objectives.
  • Create solutions that enable business requirements during cybersecurity solution and services
  • Manage security requirements roadmap and backlog with priority by evaluating business strategies and performing regular threat analysis to keep up to date on the security landscape, including data security, cloud security, application security and DevSecOps
  • Provide guidance and support to engineering vendor and partner teams during the design, build, implementation and support procedures for enterprise-class security systems.
  • Establish Security testing during application release cycle (CI/CD) to ensure security as release quality
  • Lead vulnerability program and drive efficient patch cadence, provide vulnerability metric and patch trends
  • Assist as necessary and respond immediately to security-related incidents and provide thorough remedial solutions and analysis.
  • Main contributor for product roadmaps and reliability strategy 
  • Actively monitor key metrics, reports on trends, and make improvement recommendations 
  • Facilitate an Engineering Community of Practice for your product(s) 
  • Contribute to engineering automation, management or development of production level systems 
  • Review product roadmaps and guide intake acceptance for a set of production systems 
  • Own reliability for a defined set of production systems 
  • Own the delivery lifecycle for a defined set of production systems 

Qualifications: 
  • 3 ~5 years of experience in information security or related technology experience required experience in the retail industry or professional consulting firm is a plus.
  • Working knowledge of software development lifecycle frameworks
  • Good understanding on security tools within CI/CD, security vulnerability and patching methods
  • Understanding of public cloud technologies, shared responsibility model for cloud, and experience implementing or assessing cloud security controls is required.
  • Ability to learn, understand, and work quickly with new emerging technologies, methodologies, and solutions in the Cloud/IT technology space 
  • Advanced understanding of web technologies (HTTP, SSL, Headers, Cookies, TCP, Caching) 
  • Knowledge of CI/CD principles and best-practices.  
  • Experience working with bug tracking and task management software such as JIRA, Bugzilla, etc. 
  • Experience developing solutions for retail or eCommerce businesses and other relevant domains such as manufacturing & logistics, supply chain, or corporate shared services 
  • Ability to assume the leadership/mentorship of Engineers