成為 NIKE, Inc. 團隊的一員
NIKE, Inc. 不僅為世界傑出運動員提供裝備, 這是一個探索潛能、消弭疆界及超越可能的園地。 公司尋找能夠成長、思考、懷抱夢想與創造的人才, 透過擁抱多元和獎勵想像力,讓文化欣欣向榮。 品牌尋找成就者、管理者以及具有遠見的夢想家。 在 NIKE, Inc.,我們就是要讓每個人都能在面對挑戰性十足且不斷演變進化的賽局中,揮灑熱情並一展所長。
NIKE, Inc. does more than outfit the world's best athletes. It is a place to explore potential, obliterate boundaries and push out the edges of what can be. The company looks for people who can grow, think, dream and create. Its culture thrives by embracing diversity and rewarding imagination. The brand seeks achievers, leaders and visionaries. At NIKE, Inc. it's about each person bringing skills and passion to a challenging and constantly evolving game.
NIKE is a technology company. From our flagship website and five-star mobile apps to developing products, managing big data and providing leading edge engineering and systems support, our teams at NIKE Global Technology exist to revolutionize the future at the confluence of tech and sport. We invest and develop advances in technology and employ the most creative people in the world, and then give them the support to constantly innovate, iterate and serve consumers more directly and personally. Our teams are innovative, diverse, multidisciplinary and collaborative, taking technology into the future and bringing the world with it.
Who Are We Looking For
We're looking for an Information Security Analyst to join Nike's Corporate Information Security Governance, Risk, and Compliance (GRC) team, which is responsible for enterprise wide GRC ensuring Nike leadership has the information needed to make strategic risk-based decisions and maintain compliance with international regulations while enabling the achievement of Nike business objectives globally. This role will meet with business and technology teams across Nike and consult with them on their security and compliance requirements. We are looking for an individual who is passionate about GRC, someone with a good working knowledge of industry best practice frameworks, such as ISO, NIST and CoBIT.
What Will You Work On
If this is you, you'll be working with the GRC team and performing these key tasks:
Assess moderately complex platforms against Nike security and configuration standards
Evaluate and process exceptions to information security policies and standards
Participate in complex internal risk assessments, identifying information security risks through analysis of threats and vulnerabilities, and reporting on those risks to Nike business and technology owners
Perform risk assessments of critical third-party vendors and ensure the business objectives align with the type and volume of data used in maintaining a "need to know/use" mindset
Utilize your thorough understanding of ITGC's to consult with Technology units on compliance matters
Champion information security policies, standards, controls, and processes so that compliance requirements are addressed as part of "business as usual" operations
Lead Nike business units in control design and control operations related in support of compliance requirements
Perform Compliance control validation testing to determine the operating effectiveness of IT controls for scoped systems
Provide analysis and insights into data supporting the effectiveness of technical and process-based cyber security controls and establish automated data pipelines that feed data visualization tools, such as Tableau
Collaborate effectively with NIKE leaders, managers, employees, and partners to provide deliberate and thoughtful engagement throughout NIKE
Help drive execution of the Information Security training programs. Ensure the workforce stays fully informed on information security through formal trainings and oversee the development and delivery of security training and awareness campaigns
Effective, positive verbal and written communication skills and experienced creating and developing high-quality PowerPoint presentations
Who Will You Work With
You will report into the Governance, Risk and Compliance - India Technology Center Director , in support of global GRC processes and procedures, and will work cross-functionally within the Corporate Information Security (CIS) teams and across Nike. You will regularly meet with Nike business and technology teams.
What You Bring
Knowledge of information security principles and practices, general procedures and guidelines
A general understanding of technology use, trends and risks as it applies in a business context and environment
Experience reviewing third party SOC reports
Experience/working knowledge with PCI DSS (Former QSA is a benefit).
Knowledge of information security principles, frameworks, and best practices (e.g., PCI DSS, COBIT, COSO, NIST and ISO 27000)
Excellent collaboration skills - must be eager to work as part of a cohesive team and work as a partner to others within Nike, Inc. both at WHQ and globally
Experience with ServiceNow, Confluence or JIRA
招募策略
01 申請
我們的團隊由多元技能、知識庫、意見、想法和背景組成。 我們希望你找到合適的職位:查看職務說明、部門和團隊,探索適合你的角色。
02 與招募人員會面或進行評估
若獲選擔任公司職務,招募人員會與你聯絡,以展開面試流程,並在整個流程中擔任你的主要聯絡人。 若為 Retail 職務,你將完成包含對談和測驗的互動式評估,完成評估約需 10 至 20 分鐘的時間。 無論是哪個角色,我們都想瞭解你的各種面向,因此請不要避談你如何提供世界級的服務,以及你的與眾不同之處。
03 面試
在進入這個階段時,可先做好研究,瞭解我們在尋找的人才,並為深入瞭解你及相關背景而設定的問題做好準備,自信應對。
