NIKE, Inc. 팀에 함께하세요
NIKE, Inc.는 세계 최고의 운동선수들의 복장을 책임지는 것 그 이상의 역할을 합니다. 나이키는 자신의 잠재력을 탐색하고 경계를 없애며 가능성의 영역을 확장할 수 있는 곳입니다. 나이키는 성장하고, 생각하고, 꿈꾸고, 창조할 수 있는 인재를 찾습니다. 나이키의 문화는 다양성을 포용하고 상상력을 장려하며 더욱 발전해갑니다. 우리 브랜드는 성취자, 리더, 선구자를 찾고 있습니다. NIKE, Inc.에서는 모두가 기술과 열정으로 무장하고 끊임없이 변화하는 치열한 게임에 뛰어듭니다.
WHO YOU’LL WORK WITH
You’ll be a key member of the SecureCode team within the Application Security Consulting group, collaborating with Corporate Information Security and cross-functional teams across Nike. In this position, you will report directly to the Director of Information Security Engineering Consulting, ITC, and receive strategic guidance from the SecureCode leadership team based in the United States. Your responsibilities will include close collaboration with engineering, data, and product teams to integrate secure development practices, deliver meaningful security metrics, and effectively coordinate across the USA (PST, EST) and EMEA time zones.
WHO WE ARE LOOKING FOR
We’re looking for a Senior Application Security Engineer/Analyst with deep technical expertise in application security testing, data engineering, and metrics-driven security insights. You should be comfortable navigating ambiguity, learning on the fly, and leveraging emerging technologies—including GenAI services—to accelerate and automate security data pipelines.
The candidate needs to have strong Information Security knowledge, extremely strong written and verbal communication skills and a demonstrated ability to communicate across all areas and levels of the business. They should also be able to comprehend complex business initiatives, leveraging excellent analytical and problem-solving skills. We are seeking a motivated self-starter who is has a track record of taking ownership of information security challenges and driving them to resolution.
Bachelor’s degree in Computer Science, Information Security, or Business Information Management, or equivalent work experience.
5+ years of progressive experience in information security, application security engineering, or cybersecurity consulting.
Deep expertise in Application Security Testing (AST) tools, prefrebly including SAST, DAST, SCA, SBOM analysis, and Mobile AST.
Strong experience integrating security into CI/CD pipelines using tools like GitHub Actions and Jenkins.
Proficiency in Python scripting, API development, and working with structured, semi-structured, and unstructured data.
Hands-on experience with SQL, NoSQL, and platforms such as MongoDB and Databricks; solid understanding of ETL fundamentals and API-based data ingestion.
Familiarity with cloud-native and serverless architectures, including event-driven patterns and AWS services such as EKS, ECS, Lambda, Bedrock, DocumentDB, DynamoDB, and RDS.
Knowledge of threat modeling and secure design review methodologies.
Demonstrated ability to communicate effectively across technical and executive audiences, adjusting style and approach as needed.
Strong analytical and problem-solving skills with a track record of resolving complex challenges.
Ability to lead cross-functional collaboration, build stakeholder relationships, and drive consensus in a global, matrixed environment.
Familiarity with security standards, regulatory frameworks, and cloud security best practices.
Adaptability to evolving threats and technologies in a fast-paced cybersecurity landscape.
Security certifications such as CISSP, CSSLP, CCSP, CISM, or CRISC are preferred but not required.
WHAT YOU’LL WORK ON
If this is you, you’ll be working with the Application Security Consulting SecureCode team to perform these key tasks:
Design and implement cybersecurity metrics (KPIs/KRIs) to measure control effectiveness and program reach.
Build centralized reporting capabilities and integrate metrics into dashboards using Tableau, PowerBI, and Databricks.
Analyze large, complex datasets to identify trends, anomalies, and actionable insights.
Collaborate with global engineering and DevOps teams to integrate security tooling into CI/CD pipelines.
Prepare executive-level reports and committee summaries on security posture and risk trends.
Maintain documentation and process repositories to support compliance and continuous improvement.
Stay current with industry trends, regulatory requirements, and best practices in application security metrics and reporting.
채용 계획
01 지원
나이키 팀은 다양한 기술과 지식, 의견, 아이디어, 배경을 가진 사람들로 구성되어 있습니다. 직무 소개서와 부서, 팀을 살펴보며 내게 맞는 역할을 찾아보세요. 적합한 직무를 찾을 수 있기를 바랍니다.
02 채용 담당자와의 만남 또는 평가 진행
본사 직무에 선발되면 면접 과정을 시작하고자 채용 담당자가 연락을 드립니다. 해당 과정을 진행하는 동안 이 담당자와 주로 연락하게 됩니다. 리테일 직무의 경우 채팅과 퀴즈 등 양방향 평가가 진행되며, 완료하는 데는 약 10~20분이 소요됩니다. 어떤 직무에 지원하시든, 나이키는 여러분에 관한 모든 정보를 듣고 싶습니다. 그러니 여러분이 어떻게 세계 최고 수준의 서비스를 제공할 것인지, 여러분만의 특별함은 무엇인지 주저하지 말고 보여주시길 바랍니다.
03 면접
이 단계를 자신 있게 시작하기 위해 필요한 정보를 조사하고 나이키가 추구하는 요소를 파악해 보세요. 또 여러분과 여러분의 배경에 관해 자세히 알기 위해 고안된 질문에 답할 준비를 갖추세요.
