锦鲤求职

迪卡侬

Information Security Officer

锦鲤会替你打开官网网申、按简历自动填表提交,你只需要在关键步骤确认。

岗位描述

工作内容
Your challenges:
Ensure the confidentiality, integrity, and availability of information systems and assets to safeguard Decathlon’s business.
Stay up-to-date with emerging security threats, regulatory requirements, industry trends, and best practices to continuously improve Decathlon’s security posture.

Your responsibilities:

GOVERNANCE
Develop and implement security policies, procedures, and standards to protect Decathlon's information systems and networks.
RISK & COMPLIANCE
Build and run the risk & compliance model to prevent threats that would be harmful to the Decathlon business model, including areas such as product Inventory & Classification, Risk Assessment, Crisis Management, Disaster Recovery Plan, and Digital Regulatory Compliance(PIPL, DSL, and CSL).
SECURITY TECH
Lead the implementation and operation of security technologies, mainly covering application security, cloud security, data security, network security, endpoint security, vulnerability management, and security monitoring.
AI SECURITY(Both AI for Security and Security for AI)
Assess security risks related to AI applications. Establish technical security standards and control mechanisms for our internal AI applications. Build AI capability for security team daily work.
SECURITY OPERATION
Contribute to the daily security operations, including security KPIs follow-up, threat monitoring, alert investigation, incident response, vulnerability remediation, detection rule optimization, security KPI follow-up, and internal technical security reviews.
SUPPLIER MANAGEMENT
Manage suppliers to guarantee high-level security service quality.
COLLABORATION
Ensure good collaboration with the local teams and the global security team on the operations and projects.

任职条件
Core Requirement:
More than 5 years of cybersecurity experience, with strong analytical, risk assessment, and communication skills.
Own strong responsibility and professionalism with good team spirit.
Strong knowledge of application security, API security, secure coding, identity and access control, threat modeling, and security architecture review.
Good understanding of AI and LLM security risks. Having experience in assessing and designing security controls for AI applications
Ability to develop internal security tools using Python, APIs, LLMs, or workflow automation.
Experience in penetration testing and vendor management, including test scoping and deliverable review.
Ability to assess vulnerabilities in their business context, validate reportable findings, recommend remediation, and drive closure.
Familiarity with NIST, MITRE ATT&CK, MITRE ATLAS, and relevant OWASP standards, as well as PIPL, DSL, and CSL requirements.

Preferred Qualification:
Experience in application security assessments.
Security incident investigation and response experience would be a strong advantage.
Experience in evaluating and optimizing security products and policies, such as WAF, NDR, EDR, CSPM, SIEM, DLP, and vulnerability management, is highly valued.
English or French communication skills, or experience working in a multinational organization, would be beneficial.

运维/技术支持方向的申请准备

先核对岗位要求与自己的经历,再准备档案、投递和面试。

阅读求职步骤与示例 →