成为 NIKE, Inc. 团队的一员

NIKE, Inc. 不仅仅是为全球顶尖运动员提供装备,更是一个发掘潜力、突破边界、创造无限可能的地方。我们致力于寻找善于成长、思考、梦想和创造的人才。我们的企业文化因拥抱多元化、鼓励想象力而蓬勃发展。Nike 寻觅奋斗者、领导者和梦想者的加入。NIKE, Inc. 员工以出色的专业技能迎接挑战,满怀激情地投身于不断变化的行业发展之中。

WHO YOU’LL WORK WITH

You’ll be a key member of the SecureCode team within the Application Security Consulting group, collaborating with Corporate Information Security and cross-functional teams across Nike. In this position, you will report directly to the Director of Information Security Engineering Consulting, ITC, and receive strategic guidance from the SecureCode leadership team based in the United States. Your responsibilities will include close collaboration with engineering, data, and product teams to integrate secure development practices, deliver meaningful security metrics, and effectively coordinate across the USA (PST, EST) and EMEA time zones.

WHO WE ARE LOOKING FOR

We’re looking for a Senior Application Security Engineer/Analyst with deep technical expertise in application security testing, data engineering, and metrics-driven security insights. You should be comfortable navigating ambiguity, learning on the fly, and leveraging emerging technologies—including GenAI services—to accelerate and automate security data pipelines.

The candidate needs to have strong Information Security knowledge, extremely strong written and verbal communication skills and a demonstrated ability to communicate across all areas and levels of the business. They should also be able to comprehend complex business initiatives, leveraging excellent analytical and problem-solving skills.  We are seeking a motivated self-starter who is has a track record of taking ownership of information security challenges and driving them to resolution.

  • Bachelor’s degree in Computer Science, Information Security, or Business Information Management, or equivalent work experience.

  • 5+ years of progressive experience in information security, application security engineering, or cybersecurity consulting.

  • Deep expertise in Application Security Testing (AST) tools, prefrebly including SAST, DAST, SCA, SBOM analysis, and Mobile AST.

  • Strong experience integrating security into CI/CD pipelines using tools like GitHub Actions and Jenkins.

  • Proficiency in Python scripting, API development, and working with structured, semi-structured, and unstructured data.

  • Hands-on experience with SQL, NoSQL, and platforms such as MongoDB and Databricks; solid understanding of ETL fundamentals and API-based data ingestion.

  • Familiarity with cloud-native and serverless architectures, including event-driven patterns and AWS services such as EKS, ECS, Lambda, Bedrock, DocumentDB, DynamoDB, and RDS.

  • Knowledge of threat modeling and secure design review methodologies.

  • Demonstrated ability to communicate effectively across technical and executive audiences, adjusting style and approach as needed.

  • Strong analytical and problem-solving skills with a track record of resolving complex challenges.

  • Ability to lead cross-functional collaboration, build stakeholder relationships, and drive consensus in a global, matrixed environment.

  • Familiarity with security standards, regulatory frameworks, and cloud security best practices.

  • Adaptability to evolving threats and technologies in a fast-paced cybersecurity landscape.

  • Security certifications such as CISSP, CSSLP, CCSP, CISM, or CRISC are preferred but not required.

WHAT YOU’LL WORK ON

If this is you, you’ll be working with the Application Security Consulting SecureCode team to perform these key tasks:

  • Design and implement cybersecurity metrics (KPIs/KRIs) to measure control effectiveness and program reach.

  • Build centralized reporting capabilities and integrate metrics into dashboards using Tableau, PowerBI, and Databricks.

  • Analyze large, complex datasets to identify trends, anomalies, and actionable insights.

  • Collaborate with global engineering and DevOps teams to integrate security tooling into CI/CD pipelines.

  • Prepare executive-level reports and committee summaries on security posture and risk trends.

  • Maintain documentation and process repositories to support compliance and continuous improvement.

  • Stay current with industry trends, regulatory requirements, and best practices in application security metrics and reporting.

预期内容

我们的招聘策略

01 申请

我们的团队拥有多元化的技能组合、知识库、意见、想法和背景。 希望你能找到适合自己的职位,因此请查看职位描述、部门和团队,找到适合你的职位。

02 与招聘人员会面或进行评估

如果被选中担任公司职位,招聘人员将会联系你开启面试流程,并在整个过程中担任你的主要联系人。 如果是零售职位,你需要完成互动式评估,包括聊天和测验,用时约 10 到 20 分钟。 无论担任什么职位,我们都希望充分了解你。因此,请尽情展现你如何提供世界一流的服务以及你的独特之处。

03 面试

从容开启这一阶段,做好充分调查,了解候选人标准并根据个人情况和背景准备可能会被问到的问题。

两个人在户外微笑拥抱