Lead Professional Cyber Security Analyst
- Shanghai, China
Become a Part of the NIKE, Inc. Team
NIKE, Inc. does more than outfit the world's best athletes. It is a place to explore potential, obliterate boundaries and push out the edges of what can be. The company looks for people who can grow, think, dream and create. Its culture thrives by embracing diversity and rewarding imagination. The brand seeks achievers, leaders and visionaries. At NIKE, Inc. it's about each person bringing skills and passion to a challenging and constantly evolving game.
NIKE is a technology company. From our flagship website and five-star mobile apps to developing products, managing big data and providing leading edge engineering and systems support, our teams at NIKE Global Technology exist to revolutionize the future at the confluence of tech and sport. We invest and develop advances in technology and employ the most creative people in the world, and then give them the support to constantly innovate, iterate and serve consumers more directly and personally. Our teams are innovative, diverse, multidisciplinary and collaborative, taking technology into the future and bringing the world with it.
Nike does more than outfit the world's best athletes. We are a place to explore potential, obliterate boundaries, and push out the edges of what can be. We're looking for people who can grow, think, dream and create. We thrive in a culture that embraces diversity and rewards imagination. We seek achievers, leaders and visionaries. At Nike, it's about bringing what you have to a challenging a constantly evolving game.
Nike Technology brings together technology and process expertise to create value for the consumer. We deliver one-stop, integrated process and technology capabilities that enable Nike, Inc.'s businesses and brands worldwide. Our focus is on providing Lean solutions that eliminate waste, maximize consumer value, and drive profitable business growth.
As the Lead Professional Cyber Security Analyst, you will be working with the business and information technology functions in Nike Geographies to enable Nike's cyber security program, ensure Nike maintaining a security posture commensurate with the risk tolerance while meeting business objectives, and regulatory requirements. You will work to weave cyber security into all IT and business projects and functions, while enabling business operations and missions. The Lead Professional Cyber Security Analyst will leverage knowledge of best practices to be able to support applicable regulatory, policy, standards and legal requirements, while conducting and overseeing formal internal risk assessments, vendor risk assessments and self-assessments for various Information systems and processes.
The candidate shall also support internal and external compliance requirements and programs, be able to interpret technology (regulatory) requirements e.g. Cyber Security Law requirements, MLPS (Multi-Level Protection Schema), SOX control requirements, develop and/or follow appropriate processes to keep the organization in compliance and reduce legal liabilities. Drive compliance with all legal, regulatory, and corporate information security policy requirements.
The Lead Professional Cyber Security Analyst will coordinate various of global and geo Cyber Security functions, such as penetration testing, application security, cyber security engineering, and serve as the liaison of Global and Geo Cyber Security teams for Nike Information Security programs and solutions, and ensure appropriate design and implementation of Cyber security programs, solutions, processes and tools.
· Perform risk assessments in accordance with the company assessment methodology
· Oversee adherence to security policies, standards, guidelines and baselines.
· Provide remediation recommendations and/or recommend alternate solutions to resolve gaps against Policy & Standards.
· Liaise with threat intelligence and vulnerability management teams to drive remediation of security of vulnerabilities.
· Ensure policies are communicated regularly to stakeholders and customers
· Promote and monitor our corporate security awareness program.
· Identify cyber security events and incidents and follow Nike processes to report, re-mediate, and recover.
· Enable incident response processes by quickly identifying system and data owners as well as the specific fields and classification of Nike data involved.
· Actively participate in lessons learned and resultant process improvement from response activities.
· Develop and share an understanding of systems and processes employed in Nike Geographies
· Identify ways to further protect Nike data through understanding Nike processes, systems, and partnerships in both current and future states
· To make it clear, we're not looking for just anyone. We're looking for someone special, someone who has these experiences and clearly demonstrates these skills:
· Bachelor's Degree and a minimum of 10 years relevant IT experience
· CISSP, CRISC, CISM, CISA or GIAC or other relevant Information Security certifications beneficial
· At least 6-7 years of experiences in cyber security risk assessment and risk management
· At least 5 years of documenting and implementing security policies, standards, and/or controls
· At least 3-5 years of security monitoring experience and incident response activities; preferably within a professional services firm or similar environment
· Solid understanding of network security, OSI model, and information security architecture, previous work as a security engineer is a plus
· Comfortable with interfacing with other internal or external organizations regarding security policy and standards violations, security controls failure, and incident response situations
· Strong knowledge of incident response and crisis management with the ability to identify both tactical and strategic solutions using strong verbal and written communication skills
· Strong working and technical knowledge of identity and access management and data loss prevention security domains
· Understanding of network, desktop and server technologies, including experience with network intrusion methods, network containment, segregation techniques and technologies such as Intrusion Detection Systems (IDS) and Intrusion Protection Systems (IPS)
· IT Audit, internal Audit and/or risk advisory experience is a plus
· Comfortable working with ambiguity is a must
· Excellent analytical and problem solving skills
· Strong business acumen to quickly learn new business processes and understand how application
· performance requirements support the business in achieving revenue and profit goals.
· Excellent collaboration skills - must be eager to work as part of a cohesive team and work as a partner to other teams within Nike, Inc., locally and globally
· Exceptional communication skills, including the ability to gather relevant data and information, actively listen, dialogue freely, verbalize ideas effectively, negotiate tense situations successfully and manage and resolve conflict
· Proven presentation and facilitation skills
· Must excel working in team-oriented roles that rely on ability to collaborate with others
· Experience working successfully in a highly matrixed work environment
· Passion for the Nike brand and for an innovative, Just Do It work environment
NIKE, Inc. is a growth company that looks for team members to grow with it. Nike offers a generous total rewards package, casual work environment, a diverse and inclusive culture, and an electric atmosphere for professional development. No matter the location, or the role, every Nike employee shares one galvanizing mission: To bring inspiration and innovation to every athlete* in the world.
NIKE, Inc. is committed to employing a diverse workforce. Qualified applicants will receive consideration without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity, gender expression, veteran status, or disability.
Back to top