Senior Engineer I - AppSecurity, International Commerce
Lululemon
Vancouver, BC, Canada
Posted on Saturday, August 5, 2023
Who are we
lululemon is a yoga-inspired technical apparel company up to big things. The practice and philosophy of yoga informs our overall purpose to elevate the world through the power of practice. We are proud to be a growing global company with locations all around the world, from Vancouver to Shanghai, and places in between. We owe our success to our innovative product, our emphasis on our stores, our commitment to our people, and the incredible connections we get to make in every community we are in.
About this team
lululemon values our guests and protecting their data and their experience is of utmost importance. The passion to put the guest at the center of everything we do drives the need for strong cybersecurity for our retail stores and our online digital presence. The lululemon cybersecurity, made up of passionate professionals, continues to expand to ensure this.
A day in the life
- Performing application security reviews - Performing or managing partners to perform application penetration testing
- Security training and outreach to internal development teams
- Documenting security guidance and standards
- Security tool development
- Security metrics delivery and driving improvement
- Based out of the Seattle or Vancouver SSCs
Qualifications
- Overall 6-8 years of software engineering experience
- Experience building tools and processes to reliably identify security issues and logic flaws across large code bases
- Understanding of security challenges in service architectures or large distributed systems
- Expertise with web application security best practices
- Working experience one or more programming languages: Java, Python, JavaScript, preferred
- Experience communicating security concerns and issues to non-technical audiences
- An understanding of AWS cloud services and concepts such as S3, EC2, Lambda, and VPC
- Experience with common web application testing tools for IAST, DAST and SAST, and analysis tools
- Exposure to E-commerce / Web Content Management System platforms (Like Salesforce Commerce cloud, ATG, AEM)
- Exposure security analysis and best practice recommendation in micro service landscape.
Bonus Qualifications
- Program Management experience
- Working knowledge in Jira
- Bug Bounty program experience
- Agile software development experience
- Cloudfare experience
Must haves
- Acknowledges the presence of choice in every moment and takes personal responsibility for their life
- Possesses an entrepreneurial spirit and continuously innovates to achieve great results
- Communicates with honesty and kindness, and creates the space for others to do the
- same
- Leads with courage, knowing the possibility of greatness is bigger than the fear of failure
- Fosters connection by putting people first and building trusting relationships
- Integrates fun and joy as a way of being and working, aka doesn’t take themselves too seriously.
Immigration support is potentially available for this role.
#LI-Hybrid
#LI-Ag2